Назад
Company hidden
4 часа назад

Senior Application Security Engineer

145 000 - 225 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (NIST/Cloud Security): Building and auditing application security controls for satellite mission control software and flight systems with an accent on government compliance, secure architecture, and cloud-native systems. Focus on code reviews, vulnerability management, security automation, incident response playbooks, and implementing controls for DoD standards.

Location: Hybrid role requiring candidates to be located near Denver, Long Beach, or the San Francisco Bay Area; significant work must be performed onsite.

Base salary: Long Beach $150,000–$205,000; Denver $145,000–$195,000; San Francisco Bay Area $165,000–$225,000 per year.

Company

hirify.global develops autonomous spacecraft, advanced payloads, mission software, and space-based interceptors for space security and defense operations.

What you will do

  • Create security architecture documentation and operational security guides for government authorization processes.
  • Drive vulnerability management with remediation SLAs based on finding severity.
  • Perform security code reviews across Elixir, Python, C++, and JavaScript codebases.
  • Manage security automation using SAST, SCA, and DAST tools, including CodeQL, Semgrep, and JFrog Xray.
  • Partner with engineering teams to resolve findings, implement secure coding practices, and deliver security training.
  • Develop application security incident-response playbooks and evaluate third-party security solutions.

Requirements

  • 5+ years of experience in application security, product security, or security engineering.
  • Hands-on experience implementing controls for NIST 800-171, NIST 800-53, FedRAMP, or CMMC.
  • Ability to write production-quality code in Python, Rust, Elixir, C++, or a similar language.
  • Experience with cloud security, preferably Azure, and knowledge of threat modeling, risk assessment, authentication, authorization, cryptography, Zero Trust, and defense-in-depth.
  • Experience collaborating with engineering teams to implement security controls without blocking delivery.
  • Eligible to obtain and maintain a DoD Secret or TS/SCI security clearance and meet U.S. ITAR work-authorization requirements.

Nice to have

  • Active TS/SCI clearance and experience with NIST implementation projects, DoD Impact Levels, or STIGs.
  • Experience with Elixir/Erlang/Phoenix, Azure Government Cloud, or FedRAMP-authorized environments.
  • DevSecOps or platform security experience, including GitOps, CI/CD security, infrastructure-as-code, and Kubernetes security.
  • Incident response, detection engineering, SOAR integration, or aerospace and defense industry experience.
  • Startup experience and ability to build security processes from scratch.

Culture & Benefits

  • Mission focused on securing space operations and supporting U.S. and allied defense capabilities.
  • Hybrid work environment with substantial onsite collaboration.
  • Health, dental, vision, HRA/HSA options, PTO, and paid holidays.
  • 401(k), parental leave, and equity participation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →