Назад
Company hidden
1 час назад

Lead Application Security Engineer (AI)

220 000 - 300 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Релокация
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Application Security Engineer (AI): Owning application security for Ivo's web application, APIs, cloud systems, and LLM components with an accent on vulnerability research, secure code review, and threat modeling. Focus on building security tooling and SDLC controls, managing penetration testing and responsible disclosure programs, and securing identity, access, and multi-tenant customer data surfaces.

Location: On-site in San Francisco, United States. Relocation assistance and visa and green card application support may be available for successful applicants moving to San Francisco.

Salary: $220K–$300K per year

Company

hirify.global builds an AI contract intelligence platform used by companies including Uber, Meta, Canva, IBM, and Shopify.

What you will do

  • Own application security across the web application, APIs, and supporting systems.
  • Find vulnerabilities through hands-on testing, offensive experimentation, and security-sensitive code review, then partner with engineers on remediation.
  • Lead threat modeling for new features and products, including LLM and agent components.
  • Manage penetration tests and responsible disclosure programs from scoping and researcher communication through remediation.
  • Build application security tooling including SAST, DAST, SCA, secrets detection, and infrastructure-as-code scanning.
  • Embed secure-by-default practices into the SDLC and support incident response, enterprise security reviews, and compliance efforts.

Requirements

  • 4+ years of application security, product security, or offensive security experience at a SaaS company, including ownership of security for a production platform.
  • Strong hands-on web application penetration testing and code review skills.
  • Deep experience reading and writing TypeScript, Node, and Python code.
  • Strong knowledge of OWASP Top 10, OAuth, OIDC, SAML, SSO, authorization, multi-tenant isolation, and API security.
  • Practical cloud security experience with GCP and Azure, plus container and Kubernetes security, including AKS or similar.
  • Experience managing penetration tests, bug bounty programs, or responsible disclosure programs end to end.

Nice to have

  • Experience securing production AI or LLM features, including prompt injection defenses, agent guardrails, and AI-specific threat modeling.
  • Startup experience, especially building or scaling a security function at Series B or earlier.
  • OSCP, OSWE, or comparable offensive security credentials.
  • CVE credit, published research, or contributions to open-source security tooling.
  • Experience with customer-facing security products and regulated enterprise customers.

Culture & Benefits

  • High-responsibility startup environment with a strong bias toward shipping and practical collaboration with engineering.
  • Equity in a rapidly scaling company.
  • Medical, dental, and vision insurance, plus HSA, FSA, and life insurance.
  • 401(k) program, commuter benefits, unlimited PTO, and relocation and visa support where applicable.
  • Downtown San Francisco office with catered lunch, snacks, coffee, an in-building gym, and a dog-friendly environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →