Назад
Company hidden
4 часа назад

Security Engineer, Application & AI

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer, Application & AI (Application Security/Agentic AI): Building application-layer security controls, tooling, and data protection for agentic AI products used by regulated institutions with an accent on secure development, agent authorization, third-party integrations, and sensitive data handling. Focus on designing threat models, guardrails, and automated security checks that protect production AI workflows and scale across the engineering organization.

Location: San Francisco Bay Area, United States; hybrid work arrangement.

Company

hirify.global builds AI-native operating systems for large, regulated institutions, powered by agentic workflows and the proprietary Atlas platform.

What you will do

  • Own application and product security across secure development practices, authentication, authorization, secrets management, input handling, and secure-by-default standards.
  • Integrate security into code review, CI/CD pipelines, and pre-deployment checks, and conduct threat modeling for product features and releases.
  • Define application-layer security models for AI agents, including tool scoping, permission boundaries, trust boundaries, output validation, and user-context handling.
  • Secure third-party integrations and APIs by designing credential management, response validation, and agent capability controls.
  • Define data protection standards and build safeguards such as access controls, output filtering, and audit logging for PHI, PII, and government records.
  • Build security tooling, automated checks, reusable guardrails, threat models, architecture reviews, and deployment documentation in collaboration with product, ML, and platform teams.

Requirements

  • 5+ years of application security or product security experience with hands-on work on production systems at scale.
  • Strong knowledge of OWASP Top 10, AuthN/AuthZ, secure SDLC, secrets management, secure integration patterns, and cryptography basics.
  • Experience protecting sensitive data through access controls, audit logging, and prevention of exposure through integrations and AI-generated outputs.
  • Ability to work with engineers on agentic AI security, attack surfaces, trust boundaries, and converting threat models into shipped controls.
  • Experience working with delivery teams and security requirements for regulated industries.
  • Ability to use AI-native workflows for code, security reviews, automation, and internal tooling.

Nice to have

  • Experience with agent security, LLM application security, or authorization and guardrail systems for agentic pipelines.
  • Familiarity with FedRAMP, HIPAA, SOC 2, or ISO 27001.
  • Proficiency in Python, Go, or TypeScript for security tooling and automation.
  • Experience with SAST/DAST tooling or automated security checks in developer workflows at scale.

Culture & Benefits

  • Competitive salary plus equity.
  • Daily lunches and commuter benefits.
  • 401(k) plan.
  • Medical, dental, and vision coverage.
  • Unlimited PTO.
  • Work on production AI systems for government, healthcare, insurance, and financial services.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →