Назад
Company hidden
14 часов назад

Senior Application Security Engineer (IoT)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (IoT): Building and scaling product security systems, tooling, and automated workflows across cloud, mobile, embedded, and connected-device domains with an accent on secure-by-design practices, security automation, and AI-powered pipelines. Focus on threat modeling device-cloud-mobile trust boundaries, integrating SAST/SCA/DAST and secrets scanning into CI/CD, and coordinating penetration testing for IoT and firmware.

Location: Glasgow, United Kingdom

Company

hirify.global develops consumer listening products spanning embedded firmware, mobile applications, web platforms, cloud services, and connected-device partner ecosystems.

What you will do

  • Integrate and operationalize SAST, SCA, secrets scanning, DAST, and SBOM tooling across engineering workflows.
  • Partner with engineering teams to embed secure-by-design and secure-by-default practices into development.
  • Build and extend AI-powered security workflows that automate security guidelines, threat-modeling groundwork, and CI/CD review activities.
  • Lead threat modeling across cloud, mobile, and embedded domains, including device-cloud-mobile trust boundaries.
  • Establish repeatable security testing practices and coordinate third-party penetration testing across cloud, mobile, web, connected devices, IoT, and firmware.
  • Support vulnerability intake, triage, coordinated disclosure, and PSIRT readiness.

Requirements

  • 4+ years of experience in software engineering, application security, or product security.
  • Experience working directly with engineering teams in modern software development environments.
  • Hands-on experience implementing and operationalizing application security tooling such as SAST, SCA, DAST, or secrets scanning.
  • Experience integrating security practices and tooling into CI/CD pipelines.
  • Experience using AI tools to automate security practices and previously manual activities.
  • Experience scoping or coordinating penetration testing engagements and working with the results.

Nice to have

  • Experience assessing IoT products, connected devices, embedded systems, or firmware.

Culture & Benefits

  • Work with a technically diverse consumer product ecosystem spanning firmware, mobile, web, cloud, and connected devices.
  • Collaborate directly with engineering teams on secure-by-design and secure-by-default practices.
  • Use modern security tooling, automation, AI, and industry security frameworks.
  • Join an inclusive environment that values varied backgrounds, skills, and working styles.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →