Назад
Company hidden
15 часов назад

Application Security Engineer (SaaS)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Engineer (SaaS): Building and maturing an application security program for a scaling employee experience platform with an accent on secure SDLC, threat modeling, and AI-assisted security tooling. Focus on integrating security checkpoints into CI/CD pipelines, mentoring developers through a Security Champions program, and ensuring multi-tenant isolation.

Location: Onsite in Lindon, Utah

Company

hirify.global is a fast-growing SaaS company reimagining the workplace through employee recognition and rewards.

What you will do

  • Embed security checkpoints into the entire SDLC, from planning and design to release.
  • Facilitate threat modeling for new services, APIs, and integrations to ensure secure-by-design features.
  • Configure and optimize SAST, DAST, and container scanning tools, including AI-assisted tools like Snyk and Wiz.
  • Develop and maintain secure coding standards and provide pragmatic training for engineering teams.
  • Lead a Security Champions program to mentor developers and foster a security-first culture.
  • Triage and track remediation of vulnerabilities across the application stack.

Requirements

  • 6+ years of experience in application security or software engineering with a strong security focus.
  • Hands-on experience securing cloud-hosted, multi-tenant SaaS applications.
  • Deep understanding of OWASP Top 10, API security, authentication, and encryption.
  • Proficiency in modern languages such as JavaScript/TypeScript, Java, C#, Python, or Go.
  • Experience integrating security testing into automated CI/CD pipelines.
  • Must be based in or able to work from Lindon, Utah.

Nice to have

  • Experience with external pen tests or bug bounty programs.
  • Knowledge of compliance frameworks like SOC 2, ISO 27001, or PCI DSS.
  • Security certifications such as OSWE, OSCP, GWAPT, or CSSLP.

Culture & Benefits

  • Awarded as a Great Place to Work and one of the Best Places to Work by Glassdoor.
  • Fast-paced, high-growth environment backed by renowned national investors.
  • Culture focused on rewarding, supportive, and fun workplace experiences.
  • Commitment to equal opportunity and a non-discriminatory work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →