Назад
Company hidden
обновлено 6 дней назад

Application Security Lead

Тип работы
fulltime
Грейд
lead
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Lead (DevSecOps): Leading application and infrastructure security for a global ground transportation platform with an accent on secure SDLC integration, threat modeling, automated AppSec tooling, and mobile and API security. Focus on building a mature DevSecOps program, orchestrating penetration testing, securing AWS/GCP environments and CI/CD pipelines, and driving compliance with PCI-DSS, ISO27001, and GDPR.

Company

hirify.global provides a global ground transportation platform connecting mobility providers with business customers and optimizing booking, riding, invoicing, and analytics.

What you will do

  • Lead application security and integrate security practices across the full software development lifecycle.
  • Conduct threat modeling and architecture reviews for high-risk authentication, PII, and payment features.
  • Integrate SAST, SCA, and DAST tooling into CI/CD pipelines and establish secure repository and secrets-management controls.
  • Drive mobile security for iOS and Android applications, API security, cloud security posture across AWS and GCP, WAF, bot management, and environment segmentation.
  • Coordinate red-team exercises, external penetration tests, vulnerability disclosure and bug bounty programs, and application security incident response.
  • Develop the DevSecOps strategy, security metrics, Security Champions program, disaster recovery planning, and compliance initiatives.

Requirements

  • 5+ years of experience focused on application security, product security, and collaboration with developers.
  • Hands-on experience with application security tooling across CI/CD pipelines, mobile application security for iOS and Android, and API security management.
  • Strong understanding of AWS and GCP architectures, secret management, and security posture tools.
  • Deep knowledge of OWASP SAMM, NIST, STRIDE threat modeling, PCI-DSS, and GDPR.
  • Exceptional communication skills for bridging engineering, C-level executives, and security teams.

Culture & Benefits

  • Inclusive and respectful environment focused on equal opportunity and employee empowerment.
  • Support for accommodations during the recruitment process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →