Назад
Company hidden
обновлено 8 дней назад

Product Security Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (AI): Conducting security reviews, threat modeling, vulnerability operations, and bug bounty triage for Cloudflare’s core software products with an accent on product security, distributed cloud environments, and AI/LLM-driven automation. Focus on validating complex vulnerabilities, routing findings to engineering owners, building automated triage tools, and driving remediation within SLAs.

Location: Hybrid in Austin, US or London, UK. Candidates progressing to the offer stage may be asked to attend an in-person interview at a hirify.global office or hub.

Company

hirify.global operates a large global network that protects and accelerates Internet applications for customers ranging from individual websites to major enterprises.

What you will do

  • Conduct security reviews and threat modeling for product features, including STRIDE-based analysis.
  • Manage product vulnerability findings from verification and ownership assignment through remediation within defined SLAs.
  • Perform technical triage and validation of external bug bounty submissions.
  • Support internal and external penetration testing and help engineering teams remediate findings.
  • Build AI-driven tools and scripts using AI/LLMs to automate code analysis, triage, and data enrichment.
  • Partner with DevOps and product teams to improve secure coding practices and security workflows.

Requirements

  • 5+ years of Product or Application Security experience in large-scale distributed cloud environments or SaaS platforms.
  • Hands-on experience building production-grade automation and using AI/LLMs to solve operational or technical challenges.
  • Experience with threat modeling, risk analysis, vulnerability lifecycle operations, and remediation tracking.
  • Ability to communicate technical security risks clearly and collaborate with software engineering teams.
  • Ability to work in a hybrid arrangement in Austin or London.

Nice to have

  • Experience with exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Experience scaling crowdsourced security programs such as HackerOne or Bugcrowd.
  • Experience optimizing agile workflows in JIRA.
  • Experience integrating hardware security features into production codebases.

Culture & Benefits

  • Equity plan participation.
  • Medical, dental, vision, flexible spending, commuter, fertility, family-forming, and mental health benefits.
  • Global travel medical insurance and financial protection programs, including disability and life insurance.
  • 401(k) retirement savings and employee stock participation plans.
  • Flexible paid time off and parental, pregnancy, medical, and bereavement leave programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →