Назад
Company hidden
обновлено 7 дней назад

Application Security Architect (AI)

158 050 - 193 325$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Architect (AI): Establishing and leading the application security function for a cloud-based smart home and IoT platform with an accent on secure SDLC, threat modeling, and AI-assisted tooling integration. Focus on designing resilient security architectures, managing vulnerabilities across complex codebases, and collaborating with engineering teams to embed security best practices from development to production.

Location: Tysons, Virginia, United States; employees work from the office 4 days a week

Base salary: $158,050–$193,325 USD per year

Company

hirify.global operates a cloud-based platform for smart security and the Internet of Things, including AI, video analytics, machine learning, and energy analytics products.

What you will do

  • Own and shape the application security function across mobile apps, cloud services, on-premise systems, IoT devices, and AI-powered features.
  • Manage vulnerabilities from SAST, DAST, IAST, SCA, bug bounty programs, and penetration tests using risk-based prioritization.
  • Lead threat modeling, security-focused design reviews, targeted code and application reviews, and secure architecture guidance.
  • Integrate security practices, automation, and developer-friendly remediation workflows into CI/CD pipelines and the secure SDLC.
  • Advise on cloud application security, IoT platform security, AI and LLM security, incident response, compliance, and security policy.
  • Deliver secure coding guidance, workshops, and training while partnering with engineering, architecture, product, red-team, penetration-testing, and compliance teams.

Requirements

  • 10+ years of experience in application security, software engineering, or related technical security roles; 8+ years may be accepted for exceptionally strong candidates.
  • Bachelor’s degree in computer science, computer engineering, electrical engineering, or a related field, or equivalent experience.
  • Programming experience in at least one language such as Python, JavaScript, or C#, with the ability to navigate large codebases.
  • Knowledge of application security across cloud and on-premise environments, including Kubernetes and related cloud services.
  • Hands-on experience with SAST, DAST, SCA, IAST, WAF, OWASP security principles, CI/CD, and DevSecOps.
  • New applicants must not require employment authorization sponsorship or other immigration-related support.

Nice to have

  • Experience with GitHub Advanced Security, including code scanning, secret scanning, and dependency insights.
  • Familiarity with AI and LLM security, including model hardening, prompt and input validation, data protection, and the OWASP Top 10 for LLMs.

Culture & Benefits

  • Collaborative environment with close partnership across engineering, architecture, product, and executive teams.
  • In-person work culture with meaningful responsibility and opportunities to influence technology and security practices.
  • Medical plans, HSA with company contribution, 401(k) with employer match, paid holidays, wellness time, and vacation increasing with tenure.
  • Paid maternity and bonding leave, company-paid disability and life insurance, FSAs, well-being resources, and casual dress.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →