Назад
Company hidden
1 час назад

Senior Application Security Engineer (AI)

220 000 - 235 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Securing Savvy Wealth’s product, cloud infrastructure, SaaS stack, and AI-assisted development workflows with an accent on vulnerability management, AppSec tooling, and secure-by-default engineering practices. Focus on building scanning pipelines, designing guardrails for AI-generated code, hardening SaaS and cloud configurations, and improving detection and incident response readiness.

Location: NYC office, hybrid

Salary: $220,000–$235,000 per year plus equity

Company

hirify.global is a Series B registered investment advisor building an AI-native technology platform, client portal, and business-in-a-box service for independent financial advisors.

What you will do

  • Own vulnerability management across the product, codebases, cloud infrastructure, and SaaS tools, from identification and triage through remediation.
  • Build and operate GitHub-centric AppSec tooling, including secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integrations.
  • Define code security hygiene and review standards that address AI-generated code, including authorship transparency and human review for sensitive paths.
  • Partner with the internal AI team to create guardrails for AI-assisted development, including sanctioned tools, data boundaries, dependency vetting, and secure defaults.
  • Harden SaaS, cloud, identity, and edge configurations across Google Workspace, GitHub, Rippling, Slack, AWS, GCP, and Cloudflare.
  • Develop high-signal detections and support incident response readiness in collaboration with Engineering and IT.

Requirements

  • 5+ years of hands-on security engineering experience, including significant application or product security work.
  • Strong software engineering fundamentals and the ability to read, write, and remediate code.
  • Deep experience with secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration.
  • Practical SaaS security experience, including OAuth review, third-party integrations, configuration hardening, and least-privilege access.
  • Working knowledge of AWS and/or GCP cloud security and Cloudflare edge/CDN security.
  • Strong understanding of AI-assisted development risks, risk-based prioritization, technical communication, and independent work.

Nice to have

  • Experience establishing security programs at an early- to mid-stage company.
  • Experience with SaaS security posture management, CSPM, identity threat detection, or detection engineering.
  • Experience securing LLM tooling, agentic workflows, or internal AI platforms.
  • Fintech, financial services, offensive security, pentesting, bug bounty, or red-team experience.

Culture & Benefits

  • AI-forward, written culture with close collaboration across Engineering, IT, and the internal AI team.
  • Competitive salary and equity package.
  • Unlimited PTO and paid company holidays.
  • Medical, dental, vision, 401(k), commuter, and HSA/FSA plans.
  • NYC Manhattan office with lunch and snacks provided.
  • Virtual mental health care, health concierge services, and counseling resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →