Назад
Company hidden
1 день назад

Product Security Engineer (AI)

170 000 - 200 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (AI): Building and operating an agentic application security program for a fintech platform handling financial and tax data with an accent on SAST, DAST, SCA, LLM-based triage, and automated security reviews. Focus on driving vulnerabilities from discovery through verified remediation, eliminating vulnerability classes through secure defaults and framework-level fixes, and automating threat modeling.

Location: San Francisco, hybrid

Salary: $170,000–$200,000 per year plus equity

Company

hirify.global provides an integrated platform for self-employed professionals covering business incorporation, accounting, bookkeeping, tax services, and community access.

What you will do

  • Build and operate an agentic application security program integrating SAST, DAST, and SCA into CI/CD.
  • Develop LLM-based triage and automated security reviews for pull requests.
  • Drive vulnerability remediation from triage and ownership assignment through SLA tracking and verified fixes.
  • Ship secure defaults, paved-path libraries, and framework-level changes that eliminate vulnerability classes.
  • Lead threat modeling and security reviews for new features and platform changes, progressively automating the practice.
  • Improve pipeline signal quality through new rules, prompts, and workflow iteration.

Requirements

  • 4+ years of security engineering experience with substantial application security depth.
  • Hands-on experience with SAST, DAST, SCA, and CI/CD integration, using tools such as Semgrep, CodeQL, Bandit, OWASP ZAP, or Burp Suite.
  • Experience using or building LLM- and AI-agent-based security automation, including writing and evaluating prompts and workflows.
  • Software engineering ability to make precise production code changes; the stack includes Python, Django, and AWS.
  • Experience driving vulnerability remediation through teams without direct management responsibility.
  • Product-oriented communication focused on actionable security feedback and verified vulnerability fixes.

Culture & Benefits

  • In-office and remote flexibility within the hybrid work model.
  • Fresh lunch on in-office days and $150 monthly commuter support.
  • $200 quarterly health and wellness reimbursement.
  • Flexible PTO, 14 company holidays, and 16 weeks of fully paid parental leave.
  • 100% employee medical, dental, and vision coverage, with 75% dependent coverage.
  • 401(k), equity package, quarterly virtual events, and an annual in-person summit.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →