Назад
Company hidden
15 часов назад

Senior Application Security Engineer (AI)

130 000 - 180 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Identifying and remediating vulnerabilities across web, mobile, internal systems, and FDA-regulated medical device software with an accent on penetration testing, threat modeling, and secure-by-design practices. Focus on reverse engineering mobile applications, developing automated security tools, and solving complex exploit chains affecting sensitive healthcare data.

Location: Chicago, Illinois, United States

Salary: $130,000–$180,000 annually for work performed from Illinois; compensation may vary for California, Colorado, and New York.

Company

hirify.global develops a precision medicine platform that connects real-world evidence with clinical insights to support treatment decisions.

What you will do

  • Execute advanced black-box and grey-box penetration tests of web applications, REST and GraphQL APIs, and internal systems.
  • Conduct mobile security assessments on iOS and Android, including reverse engineering and bypassing root detection and certificate pinning.
  • Lead security testing and threat modeling for FDA-regulated software medical device products.
  • Assess compliance and security risks related to HIPAA, GDPR, and FDA cybersecurity guidelines.
  • Write technical reports covering exploit chains and business logic flaws, with actionable remediation guidance.
  • Build custom security testing tools and scripts and communicate risks to executives and cross-functional teams while mentoring junior engineers.

Requirements

  • 5+ years of penetration testing experience, preferably in healthcare or highly regulated environments.
  • Expertise in web and API vulnerabilities, including the OWASP Top 10.
  • Experience with mobile security tools and frameworks such as Frida, Burp Suite, MobSF, and Ghidra.
  • Knowledge of DICOM, HL7, cloud security practices, and secure SDLC processes.
  • Proficiency in Python, JavaScript/TypeScript, or Go, combined with strong analytical and communication skills.

Nice to have

  • Offensive Security certifications such as OSCP, OSCE, or OSWE.
  • Mobile security certifications such as eCMAP or GMOB.
  • CEH, CSSLP, GPEN, GWAPT, or UL 2900 training.

Culture & Benefits

  • Work on security for healthcare data and software medical device products.
  • Support a secure-by-design engineering culture through training and mentoring.
  • Benefits may include incentive compensation, restricted stock units, medical benefits, and other position-dependent benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →