Назад
Company hidden
2 дня назад

Application Security Engineer - 220327

101 600 - 127 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer - 220327 (AppSec/Cloud Security): Securing Teradata's analytic applications across the software development lifecycle with an accent on automated vulnerability detection, secure coding, and AI-assisted development risks. Focus on integrating SAST, SCA, DAST, IaC, and container scanning into CI/CD, assessing cloud and software supply chain risks, and building Go-based security automation.

Location: Remote, California, USA

Salary: $101,600–$127,000–$152,500 annually

Company

hirify.global provides an enterprise data and AI platform that connects and scales analytics across on-premises, cloud, and hybrid environments.

What you will do

  • Integrate application security throughout the software development lifecycle and partner with Product Engineering, CloudOps, DevOps, and engineering teams.
  • Analyze and triage SAST, SCA, DAST, IaC, container scanning, and penetration-testing findings, providing actionable remediation guidance.
  • Review Java, C/C++, Go, Python, and JavaScript/TypeScript code for vulnerabilities and assess web applications and APIs against OWASP standards.
  • Integrate and tune AppSec tooling in CI/CD pipelines and replace manual security processes with automation written in Go.
  • Assess AI-assisted development and agentic systems for prompt injection, excessive permissions, unsafe tool use, and insecure output handling.
  • Investigate software supply chain risks, Infrastructure as Code configurations, cloud environments, and compliance requirements related to PCI-DSS and FedRAMP.

Requirements

  • Experience identifying and addressing application security issues by reading code in at least one of Java, C/C++, Go, Python, or JavaScript/TypeScript.
  • Experience with SAST, SCA, DAST, IaC, container scanning, CI/CD security integrations, or security automation in Go.
  • Knowledge of application security principles, vulnerability classes, root causes, mitigations, secure coding, and software supply chain risks.
  • Ability to communicate security findings to technical and non-technical audiences, mentor engineers, and deliver secure-development training.
  • Knowledge of OWASP standards, including the OWASP Top Ten, ASVS, AISVS, and AI security standards for LLMs, agentic applications, or non-human identities.
  • BS or MS degree in Electrical Engineering, Computer Science, Information Technology, or a related field; an advanced degree is highly preferred.

Culture & Benefits

  • Flexible work model supporting decisions about how, when, and where to work.
  • People-first and inclusive working environment.
  • Health care, life and disability insurance, retirement savings including a 401(k), and time-off programs.
  • Eligibility for an annual incentive plan based on company performance and individual performance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →