Назад
Company hidden
обновлено 17 часов назад

Security Engineering III (AI)

146 000 - 204 500$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineering III (AI): Building and operating product security infrastructure, automation, and controls across modern software delivery pipelines with an accent on application security, DevSecOps, and software supply chain protection. Focus on integrating SAST, DAST, SCA, and vulnerability management platforms, conducting threat modeling and design reviews, and applying AI/ML to improve vulnerability triage and remediation.

Location: Seattle, Washington, United States

Salary: $146,000–$204,500 total cash range, with potential pay up to $233,500 based on sustained performance.

Company

hirify.global is a global travel technology company operating consumer travel brands, a B2B travel network, and travel advertising services.

What you will do

  • Embed security requirements and controls throughout the software development lifecycle, from design through deployment.
  • Integrate, maintain, and improve security tooling and automation across CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and supply chain protections.
  • Configure and tune vulnerability management platforms, reduce false positives, and improve developer remediation workflows.
  • Partner with product, engineering, platform, privacy, compliance, infrastructure, and security stakeholders to identify and remediate application security risks.
  • Conduct threat modeling, security code reviews, and system design reviews covering APIs, data models, and low-level designs.
  • Integrate AI/ML-enabled security solutions and apply AI/ML concepts to improve security outcomes.

Requirements

  • Bachelor’s degree in Computer Science or a related technical field, or equivalent professional experience.
  • 5+ years of relevant experience in application security, product security, DevSecOps, or security engineering.
  • Experience securing cloud-native services, modern CI/CD pipelines, and software delivery across multiple services or domains.
  • Practical knowledge of SBOMs, signing or attestation, secure build pipelines, SAST, DAST, and SCA.
  • Experience operating and tuning tools such as Qualys, Wiz, GHAS, or Ox Security and integrating them with CI/CD, ticketing, and developer workflows.
  • Programming experience with Java or Python for security automation.

Nice to have

  • Experience applying AI/ML and agentic AI to vulnerability triage, prioritization, classification, enrichment, or remediation.
  • Understanding of AI/ML security risks, the OWASP LLM Top 10, and basic penetration testing.
  • Experience enabling developers through secure development guidance, standards, and playbooks.
  • Strong communication skills and experience reducing vulnerability backlogs and improving remediation SLAs.

Culture & Benefits

  • Inclusive environment focused on traveler-first products, ownership, operational excellence, and collaboration.
  • Medical, dental, and vision coverage for employees and families.
  • Paid time off, Employee Assistance Program, wellness and travel reimbursement.
  • Travel discounts and IATAN membership.
  • Accessibility support is available throughout the recruiting process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →