Назад
Company hidden
6 дней назад

Application Security Engineer II (AI)

Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer II (AI): Securing AWS-based, AI-powered systems including LLM integrations, agentic workflows, MCP connectors, and model supply chains with an accent on threat modeling, secure architecture, and automated security testing. Focus on designing security tooling, addressing prompt-injection risks, strengthening CI/CD controls, and responding to application-level incidents.

Compensation includes base salary, potential bonus or incentive compensation, equity, and comprehensive benefits; the amount depends on experience, qualifications, skills, and geographic location.

Company

hirify.global develops AI-powered systems and an AWS-based platform focused on protecting applications and customers from security threats.

What you will do

  • Lead threat modeling and security architecture reviews for AI-powered features, including LLM integrations, agentic workflows, and MCP connectors.
  • Architect and maintain security tooling and integrations that embed secure development practices into CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early.
  • Investigate application-level behavior during security incidents and improve response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define security posture metrics and build dashboards or reports covering security coverage and vulnerability trends.

Requirements

  • 5+ years of experience in application security engineering, preferably in AWS or comparable cloud-native environments.
  • Experience securing AI/ML-powered systems or the ability to quickly develop expertise in prompt injection, model supply-chain, and agentic-workflow risks.
  • Strong production programming skills in Python, Go, Java, or JavaScript/TypeScript.
  • Expertise in web application security, OWASP Top 10, authentication and authorization, cryptography, secure API design, microservices, containers, and cloud-native architectures.
  • Hands-on experience with threat modeling and security architecture reviews.
  • Strong cross-functional collaboration and written communication skills.

Nice to have

  • Experience in fast-paced or startup environments.
  • Experience with Veracode, Checkmarx, SonarQube, Wiz, Semgrep, or Burp Suite.
  • Experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to SOC 2 or ISO 27001 compliance, bug bounty programs, or vulnerability disclosure processes.

Culture & Benefits

  • Individual contributor role reporting to the Director of Security Engineering.
  • Opportunity to collaborate with engineering, DevOps, and product teams across the organization.
  • Potential equity, annual bonus or incentive compensation, and comprehensive benefits.
  • Video interviews, identity validation, and pre-employment checks are part of the secure hiring process.
  • Applications are typically reviewed within two weeks.

Hiring process

  • Recruiting teams may use AI-assisted tools to prepare interview questions; these tools do not make hiring decisions or automatically screen candidates.
  • Video interviews and applicant identity validation may occur at various stages.
  • Successful candidates undergo pre-employment checks before receiving a final offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →