Назад
14 часов назад

Product Security Engineer (Application Security)

120 000 - 180 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Product Security Engineer (Application Security): Securing applications by identifying design and implementation flaws and collaborating with product engineers to remediate defects with an accent on threat modeling, code review, and tool automation. Focus on hunting for security defects across the SDLC, hardening internal systems, and utilizing AI to enhance security workflows.

Location: Must be based in the USA

Salary: $120,000 - $180,000 per year

Company

Global leader in cybersecurity providing an AI-native platform designed to stop breaches and protect modern organizations.

What you will do

  • Act as a security expert for engineering teams to influence product design and capabilities.
  • Develop and maintain threat models using STRIDE to minimize the attack surface.
  • Perform source code reviews in Go, Python, and Java to identify security risks and defects.
  • Execute application penetration testing throughout the Secure Development LifeCycle.
  • Build integrated tools and automation to streamline AppSec processes for the team and partners.
  • Manage responses to the bug bounty program and conduct proactive vulnerability hunting.

Requirements

  • Understanding of software delivery in Agile and DevOps environments.
  • Experience with threat modeling, specifically the STRIDE framework.
  • Ability to conduct security code reviews for applications built with Go, Python, or Java.
  • Knowledge of secure configuration for cloud-native and containerized apps in AWS, Azure, or GCP.
  • Experience with AppSec tools such as SAST, DAST, CSPM, DSPM, and ASPM suites.
  • Must be based in the USA

Nice to have

  • Experience developing automation for application security tasks.
  • Knowledge of Docker and Kubernetes (k8s).
  • Contributions to security enhancements in open source projects.
  • Experience with threat intelligence driven testing and adversarial emulation.
  • Ability to demonstrate security implications of AI-assisted development.

Culture & Benefits

  • Market leader in compensation and equity awards.
  • Comprehensive physical and mental wellness programs.
  • Competitive vacation and holidays for recharge.
  • Paid parental and adoption leaves.
  • Professional development opportunities for all employees.
  • Vibrant office culture with world-class amenities and employee networks.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →