TL;DR
Staff Application Security Engineer (Cybersecurity): Leading and driving secure development practices across the engineering organization by building robust security tools and infrastructure with an accent on cloud-native security, developer experience, and automation. Focus on designing scalable security controls, performing threat modeling, and fostering a strong security culture within a high-load retail tech environment.
Location: Hybrid (must be near Birmingham, San Francisco, or Minneapolis offices)
Salary: $95,800–$180,000
Company
hirify.global is a retail tech company connecting customers to local stores through a reliable, high-quality delivery service and is a subsidiary of Target Corporation.
What you will do
- Design, implement, and scale security controls and processes across the engineering organization.
- Build and maintain security-focused developer tooling and CI/CD integrations.
- Lead threat modeling and security design reviews for complex systems.
- Establish and validate secure coding practices and application security controls.
- Mentor engineering team members and influence security culture throughout the company.
- Collaborate with cross-disciplinary teams to protect user data and maintain compliance standards like PCI DSS and SOC2.
Requirements
- Extensive software engineering experience with a focus on developer tooling or infrastructure.
- Strong proficiency in Go, Python, and JavaScript/TypeScript.
- Experience with cloud platforms, specifically Kubernetes and containerization.
- Deep knowledge of security design flaws, OWASP Top 10, and SANS CWE Top 25.
- Strong system design skills and experience with Infrastructure as Code (Terraform).
- Bachelor's degree or equivalent work experience.
Nice to have
- Professional certifications such as CISSP, OSWE, CSSLP, GWAPT, GWEB, or OSCP.
- Experience managing and troubleshooting CDN and WAF technologies.
- Familiarity with open-source software and dependency management.
Culture & Benefits
- Comprehensive medical, dental, and vision insurance coverage.
- Company 401(k) plan with potential for restricted stock units (RSUs).
- Discretionary vacation policy and paid holidays.
- Focus on professional growth, mentorship, and team belonging.
- Inclusive workplace dedicated to diversity and community giving.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →