Назад
Company hidden
2 дня назад

Staff/Principal Application Security Engineer

240 000 - 330 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Staff/Principal Application Security Engineer: Ensuring the security and integrity of hirify.global's software applications with an accent on conducting security reviews, code audits, and penetration testing. Focus on identifying and addressing potential security vulnerabilities, implementing best practices, and upholding secure coding standards.

Location: Hybrid (San Francisco, CA)

Salary: $240K – $330K

Company

hirify.global builds software for state and county government agencies, focusing on reinventing social services, particularly in child welfare.

What you will do

  • Conduct security assessments, including regular security reviews, code audits, penetration testing, and threat modeling.
  • Help chart a specific and pragmatic course of action to achieve a strong security posture.
  • Respond promptly to security incidents and provide detailed post-event analyses.
  • Design and implement technologies to enhance security automation during the software development lifecycle.
  • Lead efforts to design and implement secure coding standards and best practices.
  • Act as the company’s expert on application security matters, providing mentorship to development teams.

Requirements

  • Proven experience as an Application Security Engineer or in a similar role.
  • Strong technical background with experience in full-stack development, cloud computing, and scalable architecture.
  • Proficiency in one or more OOP coding languages (Ruby, Python, Java, etc).
  • Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.
  • Excellent communication skills with the ability to simply convey complex security concepts to non-technical stakeholders.
  • Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.

Nice to have

  • Prior experience with GovTech or FedRamp.

Culture & Benefits

  • Above-market compensation package (salary + equity).
  • Excellent medical, dental, vision, and life insurance (99% of premiums covered).
  • Flexible vacation time to promote a healthy work-life blend.
  • Opportunities for ongoing learning and development, including trainings/conferences and on-site speaker series.
  • Reimbursement for initial office setup and monthly work expenses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →