Назад
Company hidden
обновлено 3 дня назад

Staff Application Security Engineer (Web3)

168 000 - 240 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Application Security Engineer (Web3): Securing Gemini’s on-chain, exchange, and credit-card attack surfaces with an accent on secure software development lifecycle guardrails, architecture reviews, threat modeling, and penetration testing. Focus on designing AI agents for automated threat modeling and secure code generation, building scalable application security controls, and leading post-incident hardening.

Location: New York, New York; Miami, Florida; or remote within the United States. Hybrid work is available at U.S. hub offices, while employees outside hub areas may work remotely. In-person onboarding at a hirify.global office is required.

Salary: $168,000–$240,000 annual base salary in New York, excluding discretionary bonus and equity.

Company

hirify.global is a publicly traded crypto and Web3 platform providing secure financial products and services to individuals and institutions in more than 70 countries.

What you will do

  • Own and evolve secure software development lifecycle guardrails as an application security subject matter expert.
  • Lead architecture reviews, threat modeling, secure code reviews, and penetration testing for high-risk applications and services.
  • Design and build AI agents for automated threat modeling, secure code generation and review, and reduced AppSec toil.
  • Create and deliver hands-on application security training for engineering teams.
  • Participate in the application security on-call rotation and lead post-incident hardening.

Requirements

  • Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset.
  • Strong application security background and knowledge of vulnerabilities including SSRF, race conditions, and privilege escalation.
  • Deep code review experience in Scala, Java, Go, or other common languages, plus hands-on experience with Python, Go, or similar languages for building tools.
  • Experience implementing custom detection and prevention controls beyond the OWASP Top 10.
  • Experience in regulated environments such as financial services, fintech, or crypto, with the ability to assess business context and security risk.
  • Typically 7–10+ years of experience or equivalent impact in application security, product security, or similar roles.

Nice to have

  • Experience building AI application security tooling with agents or skills.
  • Experience with supply chain security, SLSA, OWASP SPVS, and CI/CD security controls.
  • Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks.
  • Experience with microservice architectures and cloud-native environments.

Culture & Benefits

  • Hybrid work at U.S. hub offices or remote work for employees outside hub areas.
  • Competitive starting pay, discretionary annual bonus, and new-hire equity grant.
  • Comprehensive health plans and 401(k) with company matching.
  • Paid parental leave and flexible time off.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →