Назад
Company hidden
5 дней назад

Senior Application Security Engineer (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Building secure-by-design practices across an AI-driven software platform with an accent on SDLC integration, vulnerability management, and offensive security. Focus on threat modeling, deep-dive code reviews, penetration testing, automated SAST/DAST/SCA tooling, and reducing critical production vulnerabilities.

Location: Onsite at the headquarters in American Fork, Utah, United States. Candidates must be authorized to work in the U.S.

Company

Develops AI-driven intelligent site technology, combining mobile solar-powered units with software that improves safety, compliance, security, and operations.

What you will do

  • Integrate reproducible security practices into the software development lifecycle with Product and Engineering.
  • Develop manual and automated security processes to identify, assess, and mitigate application risks.
  • Lead threat modeling, deep-dive code reviews, offensive security exercises, and penetration testing.
  • Deploy and manage vulnerability scanning tools and drive remediation to resolution.
  • Improve secure development policies and documentation.
  • Communicate risk assessments to technical and non-technical stakeholders while mentoring junior team members.

Requirements

  • 3+ years of professional information security experience focused on modern application environments.
  • 3+ years of hands-on security experience with AWS and other cloud platforms.
  • Experience with HTML, PHP, Node, React, Nest, and Next.
  • Understanding of GitHub, Docker, JFrog, CircleCI, and ArgoCD in CI/CD environments.
  • Strong knowledge of OWASP Top 10 and SAST, DAST, and SCA tools, plus operating systems, networking protocols, and the OSI model.
  • Familiarity with CIS, NIST, ISO/IEC 27001, SOC 2, or FedRAMP, with clear cross-functional communication skills.

Nice to have

  • Degree in IT or Security.
  • Security+, OSCP, GPEN, or ITCA certification.

Culture & Benefits

  • Secure-by-design culture focused on proactive security and rapid vulnerability remediation.
  • Health, dental, and vision coverage for full-time employees.
  • Retirement benefits with a 401(k) match of up to 4%.
  • Flexible paid time off.
  • Employment is contingent on drug screening and a background check; some roles may require federal background checks and fingerprinting.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →