TL;DR
Software Engineer II (Security): Strengthen Kibana's security posture and build robust platform security features with an accent on web application security, vulnerability management, and AI-powered security tools. Focus on designing and implementing security controls, managing vulnerabilities, and enhancing security operations through automation and AI.
Location: Remote, open to candidates in Spain, Greece, Portugal
Company
hirify.global is a Search AI company providing cloud-based solutions for search, security, and observability used by over 50% of the Fortune 500.
What you will do
- Lead security hardening efforts across Kibana's codebase and infrastructure, including content security policy implementation and enforcement
- Build AI-powered tools and workflows to enhance security operations such as automated vulnerability detection and predictive threat analysis
- Manage third-party dependency security through audits, vulnerability assessments, and upgrades
- Collaborate with security researchers and respond to vulnerability reports promptly
- Design and implement security controls for authentication, authorization, and auditing
- Contribute to threat modeling and security architecture decisions for new features
Requirements
- At least 3 years of web development experience with a focus on secure development practices
- Strong knowledge of web application security principles including OWASP Top 10 and defense-in-depth strategies
- Experience with security vulnerability management and coordinated disclosure
- Proficiency in JavaScript, TypeScript, and Node.js
- Ability to work effectively in a distributed worldwide team
- Hands-on experience with content security policies, CORS, and browser security controls
Culture & Benefits
- Competitive pay based on work performed
- Health coverage for employees and families in many locations
- Flexible schedules and locations for many roles
- Generous vacation days
- Matching donations and volunteer time
- Minimum 16 weeks parental leave
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →