Назад
Company hidden
24 часа назад

Director, Application Security Engineering (AI)

142 500 - 190 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Director, Application Security Engineering (AI): Strengthening application and agent security across web, mobile, data, and AI-enabled workflows with an accent on secure SDLC practices, developer-friendly guardrails, and risk-based remediation. Focus on operating security tooling, conducting threat modeling, securing CI/CD pipelines, and addressing AI-specific trust, data exposure, prompt, and tool-invocation risks.

Location: Hybrid role with three days per week in the office. Preference is given to candidates near a TKO office in New York City, Stamford, Orlando, Austin, or Las Vegas.

Salary: $142,500–$190,000 annually.

Company

hirify.global is a sports and entertainment company operating UFC, WWE, PBR, IMG, and On Location.

What you will do

  • Own and evolve application security practices across the secure software development lifecycle.
  • Configure, tune, and operate SAST, SCA, secret scanning, code scanning, repository protections, and CI/CD security controls.
  • Conduct threat modeling and security design reviews for systems, integrations, APIs, and high-risk workflows.
  • Review vulnerabilities, validate findings, prioritize risk-based remediation, and improve reporting.
  • Develop standards, playbooks, reference architectures, documentation, and developer enablement programs.
  • Assess and improve security for AI-assisted development, AI applications, and agentic systems.

Requirements

  • 5+ years of hands-on experience in application security, product security, DevSecOps, or related software security roles.
  • Experience working directly with engineering teams in fast-moving delivery environments.
  • Hands-on experience with SAST, SCA, GitHub, GitHub Advanced Security, SonarQube, Dependabot, or comparable tooling.
  • Strong understanding of application and API security, authentication and authorization, secrets, dependencies, injection, deserialization, and data protection.
  • Experience with SSDLC, shift-left security, threat modeling, vulnerability management, CI/CD, containers, IaC, and Git-based workflows.
  • Ability to provide clear remediation guidance and technical documentation for technical and non-technical audiences.

Nice to have

  • Experience securing AI agents, LLM applications, copilots, or agentic workflows.
  • Experience with DAST, API security testing, penetration testing, red-team support, or adversarial testing.
  • Knowledge of policy-as-code, IaC scanning, container security, SBOMs, provenance, attestation, and secrets management.
  • Familiarity with AWS or GCP application-layer security and cloud-native architectures.
  • Experience with security metrics, dashboards, regulated environments, or mentoring engineers.

Culture & Benefits

  • Hands-on partnership with software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams.
  • Focus on practical, scalable security controls that improve delivery without unnecessary disruption.
  • Health care, retirement benefits, vacation, paid time off, and additional company offerings.
  • Growth and professional development opportunities, with base compensation and potential short- and long-term incentives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →