Назад
Company hidden
4 дня назад

Senior Application Security Engineer (AdTech)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AdTech): Building and scaling application security capabilities for high-scale advertising platforms with an accent on secure software development, automated security testing, and vulnerability remediation. Focus on integrating SAST, DAST, and SCA into CI/CD pipelines, conducting penetration testing and threat modeling, and securing AWS workloads.

Location: London, England, United Kingdom

Company

hirify.global is an advertising technology platform that helps brands reach audiences and enables publishers and platforms to monetize digital content through video, connected TV, display, and native advertising.

What you will do

  • Build and maintain application security and NIST CSF compliance capabilities.
  • Develop automated SAST, DAST, and SCA testing and integrate security scanning into CI/CD pipelines.
  • Administer GitHub Advanced Security, including code scanning, secret scanning, and dependency review.
  • Conduct threat modeling, architecture reviews, penetration testing, vulnerability assessments, and threat hunting.
  • Partner with engineering, platform, cloud infrastructure, product, and security teams to improve authentication, authorization, data protection, and vulnerability remediation.
  • Develop secure coding guidelines, deliver security training, and support incident handling and security program maturity improvements.

Requirements

  • At least 5 years of experience in application security, secure software development, security engineering, or a related role.
  • Strong knowledge of secure coding practices, OWASP Top 10, CWE, API security, and business logic vulnerabilities.
  • Hands-on experience with GitHub Advanced Security, SAST, DAST, SCA, and CI/CD security integrations.
  • Experience with penetration testing, security code reviews, threat modeling, and architecture reviews across web applications, APIs, or cloud infrastructure.
  • Knowledge of AWS security services including IAM, VPC, KMS, GuardDuty, and CloudTrail, along with cloud-native workload security.
  • Understanding of NIST CSF and related cybersecurity and compliance frameworks such as PCI, SOC 2, HITRUST, or ISO 27001/2.

Nice to have

  • Experience in ad-tech, programmatic advertising, or another high-scale, real-time environment.
  • Familiarity with AI/LLM-based tools for threat intelligence, alert triage, or security automation.
  • Cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA.

Culture & Benefits

  • Collaborative, positive, and compassionate working environment.
  • Focus on innovation, continuous learning, and constructive feedback.
  • People, culture, and community initiatives supporting belonging, development, and meaningful connections.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →