Назад
Company hidden
обновлено 11 дней назад

Director, App Security (AI)

142 500 - 190 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, App Security (AI): Strengthening application and agent security across web, mobile, data, and AI-enabled workflows with an accent on SSDLC, shift-left controls, vulnerability management, and developer-focused security tooling. Focus on threat modeling, securing CI/CD pipelines and AI systems, tuning SAST and SCA controls, and driving risk-based remediation across engineering teams.

Location: New York, NY; hybrid with 3 days per week in the office. Preference is given to candidates near TKO offices in NYC, Stamford, Orlando, Austin, or Las Vegas.

Salary: $142,500–$190,000 annually.

Company

hirify.global is a sports and entertainment company operating UFC, WWE, PBR, IMG, and On Location.

What you will do

  • Own and evolve application security practices across the secure software development lifecycle.
  • Configure and improve SAST, SCA, secret scanning, code scanning, repository protections, and CI/CD security controls.
  • Conduct threat modeling and security design reviews for applications, APIs, integrations, and high-risk workflows.
  • Review vulnerabilities, validate findings, prioritize risk-based remediation, and reduce security tooling noise.
  • Develop secure development guidance, playbooks, standards, and enablement for engineering and citizen development teams.
  • Assess security risks in AI-assisted development and agentic systems, including trust boundaries, data exposure, prompt risks, and tool invocation.

Requirements

  • 5+ years of hands-on experience in application security, product security, DevSecOps, security engineering, or a related software security role.
  • Experience working directly with engineering teams and operationalizing SAST, SCA, and related tools such as SonarQube, Dependabot, GitHub, or GitHub Advanced Security.
  • Strong knowledge of application and API security, secure coding, authentication and authorization, secrets, dependencies, injection, deserialization, and data protection.
  • Practical experience with SSDLC, shift-left security, threat modeling, security design reviews, vulnerability management, and CI/CD controls.
  • Familiarity with cloud delivery patterns, containers, infrastructure as code, and Git-based workflows.
  • Ability to communicate clear remediation guidance and technical standards to technical and non-technical audiences.

Nice to have

  • Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows.
  • Experience with DAST, API security testing, penetration testing, red-team support, or adversarial testing.
  • Knowledge of policy-as-code, IaC scanning, container security, software supply-chain security, SBOMs, provenance, attestation, and secrets management.
  • Experience with AWS or GCP application-layer security, security metrics, dashboards, or regulated environments.
  • Experience mentoring engineers and influencing security culture without direct people management responsibility.

Culture & Benefits

  • Hands-on partnership with software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams.
  • Emphasis on automation, simplification, scalable guardrails, and actionable security guidance.
  • Health care, retirement benefits, vacation, paid time off, and short- and long-term incentives where applicable.
  • Growth and development opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →