Назад
Company hidden
2 дня назад

Senior Application Security Engineer (Cybersecurity)

220 000 - 350 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Application Security Engineer (Cybersecurity): Partner with web, backend, and data science teams to embed security best practices in the SDLC, with an accent on AI/ML-specific security concerns and API/web security. Focus on conducting threat modeling, integrating SAST/SCA/DAST tools into CI/CD, reviewing code for vulnerabilities, and enabling secure development practices.

Location: Remote within the US (excluding U.S. territories). Core hours 9AM-2PM PT. Occasional travel may be requested but not required. Employees in San Francisco Bay Area or Providence, RI may commute to offices as desired.

Salary: $220,000 to $350,000

Company

Context-based insurance solutions company backed by State Farm, building innovative digital products with Silicon Valley talent.

What you will do

  • Partner with product portfolios on security management, emphasizing AI/ML security and cross-functional data science collaboration
  • Perform security design reviews, threat modeling on APIs/web features/service integrations, and integrate SAST/SCA/DAST into CI/CD
  • Review source code and deployment configs for vulnerabilities, triage/fix findings with developers
  • Draft AppSec guidance, contribute to security awareness, and develop automation integrations like ASVS scanning
  • Participate in incident response, remediation, SaaS/OSS reviews, and application security integrations

Requirements

  • Bachelor’s degree or equivalent
  • 6-8 years in application security or full-stack dev with security expertise
  • Strong secure coding in JavaScript/TypeScript, Node.js, web standards
  • OWASP Top 10, API security, SSRF, code scanning tools (CodeQL, Semgrep, SonarQube, Snyk)
  • Comfortable debugging complex codebases, offensive security concepts (pentesting, bug bounties)
  • Clear communicator to guide engineers

Nice to have

  • GraphQL security experience
  • Security champions programs or secure SDLC rollouts
  • Open-source security tooling contributions
  • Infrastructure-as-code and container security familiarity

Culture & Benefits

  • Comprehensive health/dental/vision/life insurance, 401(k) with match, Headspace, wellness allowance
  • $2K one-time home office setup, MacBook Pro provided
  • 4 weeks PTO first year, 12 weeks paid parental leave
  • $5K annual professional development budget, LinkedIn Learning, BetterUp coaching
  • Remote-first with core PT hours for collaboration

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →