Назад
Company hidden
обновлено 2 месяца назад

Senior Application Security Engineer (Software Supply Chain)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Ireland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Software Supply Chain): Securing a multi-tenant SaaS platform and its software supply-chain control plane with an accent on application security, cloud-native systems, threat modeling, and artifact integrity. Focus on reviewing APIs and distributed architectures, building security automation, investigating vulnerabilities, and improving secure engineering practices across an embedded engineering tribe.

Location: Must be based in Ireland or the United Kingdom; regular travel may be required for team meetings, planning, customer work, and events. Belfast headquarters is used for working sessions, planning, all-hands, and team events.

Company

hirify.global operates a fully managed, multi-tenant SaaS platform for securing, governing, and distributing software artifacts across more than 30 ecosystems and formats.

What you will do

  • Embed within an engineering tribe and participate in planning, design reviews, code reviews, incident learning, and delivery discussions.
  • Threat-model product and platform changes across APIs, workers, data stores, queues, object storage, identity, policy, and tenant boundaries.
  • Review production code and architecture for authentication, authorization, data access, secrets handling, artifact integrity, signing, auditability, and abuse cases.
  • Build security tooling, paved roads, libraries, checks, and automation for engineering teams.
  • Operate security controls including SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning, dependency analysis, and runtime signals.
  • Investigate and remediate vulnerabilities, support security incidents and red/blue exercises, and contribute to SOC 2, ISO 27001, and EU CRA control work.

Requirements

  • Approximately 5+ years of hands-on application security experience, or equivalent software engineering and security experience.
  • Strong software engineering skills with a focus on Python; familiarity with TypeScript, Go, or Rust is advantageous.
  • Deep knowledge of web and API security, including OWASP Top 10, business logic flaws, authentication and authorization, token handling, REST, GraphQL, and multi-tenant access control.
  • Practical threat-modeling and vulnerability research experience across applications, APIs, cloud-native systems, and distributed services.
  • Strong AWS and cloud-native security experience, including IAM, KMS, S3, containers, Terraform, CI/CD, secrets handling, logging, and tenant isolation.
  • Must be based in Ireland or the United Kingdom and have the right to work independently without requiring sponsorship.

Nice to have

  • Experience securing artifact, package, or container registries, CI/CD systems, DevOps platforms, developer tooling, or software supply-chain products.
  • Experience with sandboxing, workload isolation, policy engines, OPA/Rego, eBPF, or secure runtime environments.
  • Contributions to open-source security or software supply-chain projects.
  • Familiarity with Datadog, AWS Security Hub, Okta, GitHub Advanced Security, Snyk, Semgrep, Trivy, or Wiz.
  • Security certifications such as OSCP, CSSLP, GPEN, GWAPT, GCSA, or CISSP.

Culture & Benefits

  • Engineering-first, builder-oriented security culture with high standards, practical thinking, and strong ownership.
  • Flexible working policies and a remote-first collaboration environment supported by Slack, Google Docs, and Linear.
  • Comprehensive health, dental, and vision insurance.
  • Generous annual leave and flexible, family-friendly wellbeing policies.
  • Professional development budget for equipment, training, books, conferences, travel, and certifications.
  • Belfast office facilities for working sessions, planning, meetups, and team activities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →