Назад
Company hidden
20 часов Π½Π°Π·Π°Π΄

Staff Product Security Engineer (AI Security)

154Β 000 - 205Β 000$
Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
hybrid
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Staff Product Security Engineer (AI Security): Leading product security reviews, threat modeling, vulnerability management, and security automation across SaaS products and cloud-native platforms with an accent on application, API, cloud, Kubernetes, and AI security. Focus on securing GenAI applications, LLMs, AI agents, and MCP integrations, building scalable SSDLC controls, and driving systemic remediation across engineering teams.

Location: McLean, Virginia; hybrid with 3 days per week onsite. Candidates in the Tysons Corner vicinity are prioritized.

Annual base salary: $154,000–$205,000.

Company

hirify.global provides the hirify.global Experience Cloud SaaS platform for managing customer, employee, patient, resident, and candidate experiences.

What you will do

  • Lead security reviews, threat modeling, and secure architecture assessments for complex products, services, features, and engineering initiatives.
  • Embed secure-by-default practices and automated security controls throughout the software development lifecycle.
  • Analyze, prioritize, investigate, and remediate complex product vulnerabilities and systemic security risks.
  • Design and optimize SAST, SCA, secrets detection, DAST, container, cloud, ASPM, and AI-assisted security capabilities.
  • Review GenAI and AI-enabled products, including LLMs, AI agents, MCP integrations, tool invocation, and emerging AI architectures.
  • Lead cross-functional initiatives, influence technical decisions, represent Product Security in architecture and customer security discussions, and mentor security engineers.

Requirements

  • 8+ years of experience in application security, product security, security engineering, or a related field.
  • Hands-on experience with application security, SSDLC, threat modeling, security architecture reviews, vulnerability management, and secure coding practices.
  • Experience securing APIs, microservices, Kubernetes, containers, cloud-native services, and public cloud environments, preferably AWS.
  • Experience with SAST, SCA, secrets detection, DAST, and ASPM platforms, plus knowledge of OWASP and common application security risks.
  • Ability to independently investigate complex security issues, develop practical remediation strategies, and influence engineering teams without direct authority.
  • Professional working proficiency in written and spoken English is required.

Nice to have

  • Experience securing AI/ML systems, GenAI applications, LLMs, AI agents, or MCP-based architectures.
  • Experience with security automation, CI/CD integrations, cloud and container security technologies.
  • Familiarity with NIST, SOC 2, ISO 27001, PCI DSS, or similar frameworks.
  • Customer security review or security escalation experience.
  • CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent certification.

Culture & Benefits

  • Hybrid work with regular onsite collaboration.
  • Medical, dental, and vision coverage.
  • 401(k), disability, life, and AD&D insurance.
  • Statutory leaves, paid parental leave, and paid holidays.
  • Equal opportunity workplace committed to diversity and inclusion.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’