Назад
Company hidden
12 часов назад

Application Security Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AI) (SaaS security): Securing global SaaS applications through automated audits, threat modeling, code reviews, and vulnerability lifecycle management with an accent on cloud-native infrastructure, secure development, and AI-driven security workflows. Focus on building security-as-code tools, validating vulnerabilities with LLMs and autonomous agents, coordinating bug bounty and penetration testing programs, and responding to application-level incidents.

Location: Barcelona, Spain; hybrid work from the Barcelona office

Company

hirify.global provides a global SaaS service and maintains ISO 27001 and ISO 27701 certifications, a SOC 2 Type 2 report, a private bug bounty program, SIEM, and security awareness initiatives.

What you will do

  • Conduct continuous automated security audits of SaaS applications and identify misconfigurations against security benchmarks.
  • Advise product and engineering teams through threat modeling, AppSec reviews, and secure coding mentorship.
  • Manage the vulnerability lifecycle across application and cloud infrastructure layers, including triage, reporting, remediation tracking, and automation.
  • Integrate security checkpoints and custom security-as-code tools into CI/CD pipelines, including AI-driven workflows using LLMs and autonomous agents.
  • Direct bug bounty programs, coordinate external penetration tests and customer security assessments, and act as a technical contact for complex inquiries.
  • Lead technical response to application security incidents and conduct root-cause analysis.

Requirements

  • 3+ years of professional Application Security Operations experience in a high-growth SaaS or cloud-native environment.
  • Advanced experience securing NestJS, Vue.js, and Angular applications.
  • Hands-on experience with Snyk, Datadog ASM/AppSec, Google SecOps, and CrowdStrike.
  • Strong knowledge of AWS, Azure, Kubernetes, Docker, Terraform, web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF.
  • Programming and scripting experience with Python, Node.js, and Shell, including custom security tooling and integrations.
  • Fluent English is mandatory.

Nice to have

  • Experience with ethical hacking, CTF competitions, or bug bounty hunting.
  • Experience applying AI and LLM technologies to automated vulnerability validation or code analysis.

Culture & Benefits

  • Work alongside cybersecurity experts and collaborate with development teams, product managers, external researchers, and other third parties.
  • Contribute to initiatives designed to protect hirify.global users and customers.
  • hirify.global is an equal opportunity employer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →