Назад
Company hidden
11 часов назад

Application Security Engineer (Go/TypeScript)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Go/TypeScript): Securing Opal's identity governance product through secure SDLC ownership, production security engineering, incident response, and cloud hardening with an accent on application security, authentication, authorization, and vulnerability remediation. Focus on building encryption and identity services, integrating Auth0 with SAML/OIDC/OAuth 2.0, hardening AWS and Kubernetes environments, and embedding SAST/DAST/SCA into CI/CD.

Location: San Francisco, United States; hybrid

Company

hirify.global builds identity governance and intelligent access management for enterprise environments in the AI era.

What you will do

  • Own the secure software development lifecycle, including threat modeling, design reviews, code reviews, and security standards.
  • Coordinate internal and external application penetration tests and drive findings through remediation.
  • Build and maintain SAST, DAST, and SCA tooling integrated into CI/CD pipelines.
  • Develop security-critical production code in Go and TypeScript, including encryption services, authorization enforcement, authentication flows, and shared security libraries.
  • Investigate and contain security incidents, identify root causes, and improve detection, logging, and alerting.
  • Partner with Infrastructure Engineering on AWS and Kubernetes cloud security and mentor engineers on secure coding and security architecture.

Requirements

  • 4+ years of experience in application security or software security engineering.
  • Production software development experience, not only security assessment and reporting.
  • Strong knowledge of OAuth 2.0, OIDC, SAML, session management, and token lifecycle security.
  • Experience with AWS and containerized environments, including Kubernetes and Docker.
  • Experience leading complex cross-functional security initiatives from kickoff through completion.
  • Experience conducting or participating in external penetration tests and overseeing remediation.

Nice to have

  • Familiarity with Go, TypeScript, React, PostgreSQL, Redis, and GraphQL.

Culture & Benefits

  • Work directly with engineering as an embedded security partner.
  • Take ownership of the security roadmap and application security standards.
  • Collaborate with engineers to make secure development practices practical and accessible.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →