TL;DR
Lead Application Security Engineer (DevSecOps): Improving the security of software products and driving best practices across the development lifecycle with an accent on security reviews, hardening recommendations, and Security by Design. Focus on assessing web and binary application security, designing secure features, and addressing risks to protect users.
Location: Fully remote, worldwide
Company
hirify.global is a global remote-first company focused on delivering high-volume, low-cost Linux infrastructure and security products.
What you will do
- Perform security reviews of the company's external services.
- Design and implement recommendations for security hardening.
- Participate as a security engineer in all steps of the SDLC.
- Design and review new features to implement the Security by Design principle.
- Call attention to risks and drive actions to address them to protect users.
Requirements
- Good technical knowledge and deep understanding of security, including web applications security (backend and frontend), penetration testing, and modern security mechanisms.
- At least 3 years of experience in assessing the security of Web applications and Binary applications.
- Deep understanding of modern web technologies (OAuth, JWT, CORS, CSP, SOP, SameSite, etc.) and architectures.
- Experience coding/scripting in one or more general-purpose languages.
- Deep understanding of Linux architecture and security stack.
- English: B2 required
Nice to have
- Experience in exploiting vulnerabilities found in code.
- Experience with code audits and code audit automation.
- Experience in architecting, developing, or maintaining secure cloud solutions.
- Experience in reviewing Docker/Kubernetes architectures.
- Successful CTF or Bug Bounty participation.
- Relevant certificates (OSCP, AWAE, CREST, GPEN).
Culture & Benefits
- Focus on professional development with interesting and challenging projects.
- Fully remote work with flexible working hours, allowing you to work from any location worldwide.
- Paid 24 days of vacation, 10 national holidays, and unlimited sick leaves.
- Compensation for private medical insurance.
- Co-working and gym/sports reimbursement.
- Budget for education and opportunity for reward for innovative ideas.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →