Назад
Company hidden
2 месяца назад

Application Security Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AI) (SaaS security): Securing global SaaS applications through automated audits, threat modeling, code reviews, and vulnerability lifecycle management with an accent on cloud-native infrastructure, secure development, and AI-driven security workflows. Focus on building security-as-code tools, validating vulnerabilities with LLMs and autonomous agents, coordinating bug bounty and penetration testing programs, and responding to application-level incidents.

Location: Barcelona, Spain; hybrid work from the Barcelona office

Company

hirify.global provides a global SaaS service and maintains ISO 27001 and ISO 27701 certifications, a SOC 2 Type 2 report, a private bug bounty program, SIEM, and security awareness initiatives.

What you will do

  • Conduct continuous automated security audits of SaaS applications and identify misconfigurations against security benchmarks.
  • Advise product and engineering teams through threat modeling, AppSec reviews, and secure coding mentorship.
  • Manage the vulnerability lifecycle across application and cloud infrastructure layers, including triage, reporting, remediation tracking, and automation.
  • Integrate security checkpoints and custom security-as-code tools into CI/CD pipelines, including AI-driven workflows using LLMs and autonomous agents.
  • Direct bug bounty programs, coordinate external penetration tests and customer security assessments, and act as a technical contact for complex inquiries.
  • Lead technical response to application security incidents and conduct root-cause analysis.

Requirements

  • 3+ years of professional Application Security Operations experience in a high-growth SaaS or cloud-native environment.
  • Advanced experience securing NestJS, Vue.js, and Angular applications.
  • Hands-on experience with Snyk, Datadog ASM/AppSec, Google SecOps, and CrowdStrike.
  • Strong knowledge of AWS, Azure, Kubernetes, Docker, Terraform, web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF.
  • Programming and scripting experience with Python, Node.js, and Shell, including custom security tooling and integrations.
  • Fluent English is mandatory.

Nice to have

  • Experience with ethical hacking, CTF competitions, or bug bounty hunting.
  • Experience applying AI and LLM technologies to automated vulnerability validation or code analysis.

Culture & Benefits

  • Work alongside cybersecurity experts and collaborate with development teams, product managers, external researchers, and other third parties.
  • Contribute to initiatives designed to protect hirify.global users and customers.
  • hirify.global is an equal opportunity employer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →