Назад
Company hidden
обновлено 6 дней назад

Principal Application Security Engineer (Cybersecurity)

163 625 - 211 750$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Application Security Engineer (Cybersecurity): Providing senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across a hybrid engineering ecosystem with an accent on Kubernetes, API security, and DevSecOps integration. Focus on defining secure-by-default architecture patterns, driving vulnerability management strategies, and securing AI implementations within a high-stakes financial infrastructure environment.

Location: Chicago, Illinois, United States; four days in office. Candidates must be legally authorized to work in the United States without current or future employer sponsorship.

Salary: $163,625–$211,750 base salary annually, with potential annual incentive compensation and long-term equity participation.

Company

hirify.global provides financial market infrastructure, tradable products, and trading, clearing, and investment solutions.

What you will do

  • Lead secure architecture reviews and threat modeling for microservices, APIs, Kubernetes workloads, and major system changes.
  • Define application and API security standards covering authentication, authorization, input validation, and common vulnerability classes.
  • Set security direction for Kubernetes clusters, containers, RBAC, namespace isolation, network policies, secrets, and platform guardrails.
  • Integrate SAST, SCA, secret scanning, container scanning, and IaC scanning into scalable CI/CD workflows.
  • Own risk-based software vulnerability management, remediation priorities, service levels, metrics, and incident follow-through.
  • Establish secure adoption patterns, governance, permissions, and data boundaries for AI-enabled development and security capabilities.

Requirements

  • 12+ years of experience in application security, product security, or software engineering, including architecture and security leadership in complex production environments.
  • Production software development experience and the ability to read, write, and review code in a modern backend language such as C++, Go, Java, C#, Python, or Node.
  • Strong knowledge of Kubernetes security primitives, container build practices, and hybrid public-cloud and on-premises Kubernetes environments.
  • Hands-on experience integrating DevSecOps security tooling into CI/CD pipelines.
  • Exceptional communication, influence, and technical leadership skills across engineering, platform, and security stakeholders.
  • U.S. work authorization without employer visa sponsorship is required.

Nice to have

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • CSSLP, CKS, OSCP, AWS Security Specialty, or Azure Security Specialty certification.

Culture & Benefits

  • Four days per week in the Chicago office to support team connection and collaboration.
  • Medical, prescription drug, dental, vision, life, and AD&D coverage.
  • 401(k) or pension company match and retirement savings plan.
  • Spending accounts, employee stock purchase plan, paid time off, and additional voluntary benefits.
  • Leadership programs, career development initiatives, and internal mobility opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →