Назад
Company hidden
15 часов назад

Security Engineer III (Application Security)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security Engineer III (Application Security): Leading the advancement of application security posture and implementing security capabilities across the Application Protection portfolio with an accent on WAF, API security, and CI/CD guardrails. Focus on threat modeling, vulnerability assessments, and integrating AI-enabled security tools while ensuring robust data protection and compliance.

Location: Must be based in Tulsa, OK, US

Company

hirify.global is a stable and financially strong banking corporation providing comprehensive financial services and investment management.

What you will do

  • Lead the design and implementation of advanced application security architectures and secure CI/CD guardrails.
  • Conduct threat modeling and in-depth vulnerability assessments for internal applications and APIs.
  • Develop and maintain application security controls including WAF, API policies, and DAST/SAST/SCA/IaC scanning.
  • Oversee application-layer incident response, including triage, containment, and root cause analysis.
  • Define security controls for AI/LLM-enabled features, addressing risks like prompt injection and data leakage.
  • Mentor junior engineers and lead cross-functional initiatives to enhance security maturity.

Requirements

  • Must be based in or able to work from Tulsa, OK
  • Bachelor’s degree in Information Security, Computer Science, or 7+ years of relevant experience.
  • 5+ years of experience in Cyber Security or a related technical discipline.
  • Advanced expertise in application security tools like WAF, DAST, SAST, and SCA.
  • Proficiency in scripting languages such as Python, Bash, Go, or PowerShell.
  • Experience securing CI/CD pipelines and cloud-native applications in AWS, Azure, or GCP.

Nice to have

  • Master’s degree in a relevant field.
  • CISSP or equivalent professional certifications.
  • Experience with secrets management tools like HashiCorp Vault.
  • Knowledge of data analysis tools such as Splunk or Elasticsearch.

Culture & Benefits

  • Collaborative environment focused on innovation, ownership, and continuous improvement.
  • Opportunities for professional development and long-term career growth within a stable financial institution.
  • Commitment to equal opportunity employment and inclusive workplace practices.
  • Engagement in complex security challenges with cross-functional teams across the organization.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →