Назад
Company hidden
обновлено 4 дня назад

Senior Application Security Engineer (Crypto)

140 000 - 200 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Crypto): Securing crypto custody, trading, and payments products through design reviews, threat modeling, code review, penetration testing, and AppSec tooling with an accent on AI agents and AI-enhanced SAST/DAST pipelines. Focus on building secure design and code review systems, automating repeatable security work, and preventing vulnerabilities across cloud-native and microservice environments.

Location: New York, New York; Miami, Florida; or remote within the United States. Hybrid work is available at US hub offices, while employees outside hub areas may work remotely. In-person onboarding at a hirify.global office is required.

Salary: $140,000–$200,000 annual base salary in New York, California, and Washington, excluding bonus and equity.

Company

hirify.global is a publicly traded crypto and Web3 platform providing secure crypto products and services to individuals and institutions in more than 70 countries.

What you will do

  • Lead secure design reviews, threat modeling, secure code reviews, and penetration testing for high-risk custody, trading, and payments products.
  • Design and build Application Security tooling, including AI agents for secure design and code review.
  • Build AI-enhanced SAST and DAST pipelines and automation that reduces recurring security work.
  • Partner with engineering teams to remediate vulnerabilities and improve secure coding practices over time.
  • Influence engineering, product, and business teams to embed security judgment into product development.

Requirements

  • 5+ years of experience in application security or a similar role.
  • Experience with design reviews, threat modeling, secure code reviews, or penetration testing using an attacker mindset.
  • Experience building or significantly contributing to security tooling and automation.
  • Strong knowledge of application security best practices and common vulnerabilities such as SSRF, race conditions, and privilege escalation.
  • Development or scripting experience with Python, Scala, C++, or JavaScript, including the ability to read and write code.
  • Strong communication and cross-functional collaboration skills, with the ability to influence without authority.

Nice to have

  • Experience building AI application security tooling with agents or skills.
  • Experience with supply chain security, SLSA, OWASP SPVS, and CI/CD security controls.
  • Background in regulated financial services, fintech, crypto, or equivalent environments.
  • Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks.
  • Experience with microservice architectures and cloud-native environments.

Culture & Benefits

  • Discretionary annual bonus and long-term incentive through a new hire equity grant.
  • Comprehensive health plans and a 401(k) with company matching.
  • Paid parental leave and flexible time off.
  • Hybrid collaboration at US hub offices with remote work options for employees who do not live near a hub.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →