Назад
Company hidden
обновлено 3 дня назад

Senior Application Security Engineer

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France/UK/US +3 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Java/Python/Go, Cloud Security): Securing internet-facing financial software and APIs through hands-on code analysis, vulnerability remediation, and Secure SDLC improvements with an accent on secure code review, threat modeling, and developer enablement. Focus on reproducing vulnerabilities, assessing exploitability and reachability, tuning SAST/DAST/SCA tooling, and building preventative controls across AWS and Kubernetes environments.

Location: Remote, United States

Company

hirify.global develops digital and biometric identity authentication, fraud prevention, and mobile deposit solutions for organizations worldwide.

What you will do

  • Perform hands-on security analysis and secure code reviews across applications, services, APIs, and supporting components.
  • Work directly in Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide remediation.
  • Own vulnerability remediation from discovery and prioritization through retesting, validation, and closure.
  • Mature Secure SDLC gates, threat modeling, security requirements, and preventative controls in CI/CD workflows.
  • Operate and tune SAST, DAST, and SCA tooling, including dependency and supply-chain security processes.
  • Partner with Engineering on cloud-native application security across AWS, Kubernetes/EKS, containers, and Linux environments.

Requirements

  • 7+ years of experience in Application Security, Product Security, security-focused software engineering, or a related discipline.
  • Senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong coding and secure code review experience in Java, Python, and Go.
  • Experience with SAST, DAST, SCA, software dependency security, OWASP Top 10, and OWASP API Security risks.
  • Experience with STRIDE, PASTA, or similar threat-modeling methodologies.
  • Experience securing cloud-native applications in AWS and Kubernetes/EKS, with strong communication skills for working with developers and engineering leadership.

Nice to have

  • Application or API penetration-testing experience.
  • Financial services, fintech, identity, fraud, regulated SaaS, or PCI-DSS experience.
  • Experience building a Security Champions program or AppSec automation.
  • OSCP, GWEB, CSSLP, or a similar technical security certification.

Culture & Benefits

  • Virtual-first work model with remote work from a home office and access to company offices.
  • Ownership of the Application Security function with executive visibility and direct collaboration with IT, Security, and Engineering leadership.
  • Healthcare options, retirement or pension contributions, stock plan participation, life and disability coverage, and paid time off.
  • Learning resources, tuition reimbursement, hackathons, and a home office setup allowance.
  • Opportunity to secure internet-facing financial software with complex API integrations and US/EU regulatory considerations.

Hiring process

  • The hiring process includes an in-person meeting.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →