Назад
Company hidden
обновлено 3 дня назад

Staff Application Security Engineer (DevSecOps)

172 000 - 233 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Staff Application Security Engineer (DevSecOps): Own the AppSec/DevSecOps program strategy for embedding security into the SDLC with shift-left practices, paved roads, and automation, with an accent on secure CI/CD, Kubernetes/GCP tooling, and AI/ML workflow controls. Focus on designing guardrails that reduce developer risk and cognitive load while leading security architecture, threat modeling, and incident-response readiness across multiple teams.

Location: Remote within the United States or Canada

Salary: $198,000–$233,000 USD (high cost of living areas) or $172,000–$216,000 USD (all other US locations), plus bonus eligibility and equity

Company

hirify.global provides real-time internet visibility and actionable threat intelligence for security teams and governments.

What you will do

  • Own and drive the AppSec/DevSecOps roadmap, defining how security is embedded into the SDLC through shift-left practices, paved roads, and automation instead of gates.
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads.
  • Integrate security into CI/CD pipelines (code scanning, secret detection, software composition analysis, and infrastructure policy enforcement) with engineering teams.
  • Deliver hardened service templates, secure service catalogs, and guardrails that reduce developer risk and cognitive load.
  • Set security architecture direction for AI/ML workflows, implementing controls for training/deployment/inference pipelines (access control, artifact validation, sanitization, and provenance tracking).
  • Provide technical leadership and mentorship via design reviews and threat modeling; participate in shared on-call rotation for security incident response readiness.

Requirements

  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, including leading security initiatives across multiple teams.
  • Deep expertise securing Kubernetes environments (container images, network policies, and supply chain protections such as Helm and Crossplane).
  • Strong application security tooling experience (dependency scanning, static analysis, and policy enforcement) integrated into CI/CD (e.g., GitHub Actions, ArgoCD) and ability to bridge engineering with Security Operations.
  • Strong understanding of attacker TTPs and familiarity with MITRE ATT&CK.
  • Strong cloud security experience with GCP preferred, including securing data pipelines and model hosting endpoints.
  • Proficiency with Infrastructure-as-Code (e.g., Terraform, Crossplane) and scripting/automation (e.g., Python, Bash).

Culture & Benefits

  • Equity, health/dental/vision coverage, retirement with company contribution, parental leave, and mental health & wellness benefits.
  • Flexible PTO and a professional development stipend.
  • Bonus eligibility and equity; annual bonus plan for eligible non-sales roles.
  • Remote role with onboarding in-person at HQ in Ann Arbor (Michigan).
  • Shared on-call rotation with Infrastructure and SRE teams.

Hiring process

  • Interview process includes objective assessment of skills, prior relevant experience, potential impact, and role scope.
  • Video interviews require candidates to keep cameras on.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →