Назад
Company hidden
24 часа назад

Senior Product Security Engineer (AI Security)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (AI Security): Embedding security into the product development lifecycle through architecture reviews, threat modeling, application testing, and vulnerability remediation with an accent on APIs, cloud-native applications, and AI-enabled services. Focus on testing prompt injection and data leakage risks, building CI/CD security automation, and developing secure engineering standards with product and engineering teams.

Location: Miami, United States; workplace: on-site

Company

hirify.global is scaling a product security function within its broader security organization.

What you will do

  • Perform security design and architecture reviews, threat modeling, and application security reviews across the SDLC.
  • Conduct manual penetration testing of web, API, thick-client, and mobile applications, as well as secure code reviews.
  • Partner with engineering teams to prioritize vulnerabilities, verify remediation, and improve remediation timelines.
  • Develop secure coding practices, product security standards, engineering guardrails, reusable security patterns, and reference architectures.
  • Assess AI-enabled products and LLM integrations for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Automate security testing in CI/CD and integrate security tooling into developer workflows.

Requirements

  • 5+ years of experience in Product Security or Application Security.
  • Experience securing web applications, APIs, microservices, and cloud-native applications.
  • Experience with threat modeling and penetration testing.
  • Strong knowledge of OWASP Top 10, OWASP API Top 10, authentication and authorization, OAuth/OIDC, and Secure SDLC.
  • Experience with SAST, DAST, SCA, and container security, plus direct partnership with engineering teams.
  • Strong written and verbal communication skills.

Nice to have

  • Experience securing AI and LLM applications.
  • Experience with Kubernetes, containers, cloud security, GitHub Actions, or CI/CD security.
  • Experience with Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security.
  • OSCP, GWAPT, GWEB, CSSLP, or CISSP certification.

Culture & Benefits

  • Engineering-first product security work focused on enabling developer velocity.
  • Cross-functional collaboration with Product, Engineering, Infrastructure, Cloud Security, and Compliance.
  • Opportunity to mature hirify.global's AI Security program and expand automated security testing.
  • Customer security questionnaire and Sales Engineering support as part of the role.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →