TL;DR
Security Engineer (Product Security): Building and shipping secure products by integrating security into the software development lifecycle with an accent on threat modeling, vulnerability detection, and remediation. Focus on partnering with engineering teams to make security practical and actionable, improving secure development practices, and contributing to security tooling.
Location: Hybrid in Seattle, US
Salary: $140,000 - $165,000 a year
Company
hirify.global develops a cloud-based phone system for businesses.
What you will do
- Partner with engineering teams to review designs, identify security risks, and recommend mitigations.
- Perform threat modeling for new features and major changes.
- Identify and remediate common vulnerability classes across services and APIs.
- Conduct security testing and validation, including targeted manual testing for high-risk areas.
- Improve secure development practices by creating reusable guidance and patterns.
- Contribute to security tooling and automation.
Requirements
- 2–5 years of experience in Product Security, Application Security, or software engineering with a strong security focus.
- Strong understanding of web application and API security fundamentals and common vulnerability classes (OWASP Top 10).
- Experience performing security reviews, threat modeling, or secure architecture assessments.
- Familiarity with security testing tools and practices (SAST/DAST, dependency scanning, fuzzing, manual testing).
- Comfort reading and reviewing production code in at least one language (e.g., Python, Go, Java, JavaScript/TypeScript).
- Ability to work cross-functionally with engineering teams and drive remediation efforts.
Nice to have
- Experience with cloud-native architectures (AWS/GCP/Azure), microservices, and Kubernetes.
- Experience tuning security tools to reduce noise and improve signal.
- Familiarity with secure SDLC practices and security champions programs.
- Exposure to bug bounty / vulnerability disclosure programs.
- Experience improving internal security automation or developer workflows (including using AI-assisted tooling).
Culture & Benefits
- Work in a hybrid setup from the Seattle office.
- Help build and ship secure products by integrating security early in the software development lifecycle.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →