Назад
Company hidden
4 дня назад

Senior Application Security Engineer (AI)

120 000 - 220 500$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Building secure-by-default patterns, paved-road tooling, and automation for web, mobile, and API ecosystems with an accent on application security tooling, threat modeling, code review, and cloud-native security. Focus on tuning SAST, SCA, DAST, and secrets scanning for actionable results, securing AI and agent features, and designing out vulnerabilities across engineering pipelines.

Location: Remote employment available in all US states except Arkansas, Mississippi, Montana, North Dakota, South Dakota, Vermont, West Virginia, and Wyoming.

Salary: $120,000–$220,500 annually, depending on location, knowledge, skills, and experience. Performance-based incentives or bonuses may also apply.

Company

hirify.global is a retail company building application security capabilities for its web, mobile, and API ecosystem.

What you will do

  • Build secure-by-default patterns and paved-road tooling for engineering pipelines and frameworks.
  • Own and tune SAST, SCA, secrets-scanning, and DAST tooling to improve signal quality and route findings into existing engineering workflows.
  • Automate security work that does not require human judgment while preserving manual review for higher-risk issues.
  • Partner with product engineering, DevOps, penetration testing, attack surface management, and platform security teams.
  • Mentor engineers and security champions while raising application security standards across the organization.

Requirements

  • 4+ years of experience in application security, secure software development, or a closely related field, plus a relevant degree or equivalent experience.
  • Experience shipping security tooling, automation, or reusable secure-development patterns.
  • Expert-level threat modeling, security design review, manual code review, and knowledge of application and API vulnerability classes.
  • Ability to read and write code in languages such as Java, Kotlin, C#, or Python.
  • Hands-on use of AI for security work, with judgment about when to trust and verify its output.
  • Knowledge of LLM and agent risks, including prompt injection, unsafe tool and permission use, data leakage, and cloud-native security across AWS, GCP, Azure, and Kubernetes.

Nice to have

  • Experience with GitHub Advanced Security, JFrog Artifactory, or similar tools.
  • Offensive security, vulnerability disclosure, bug bounty, or production software engineering experience.
  • Certifications such as CSSLP, CISSP, OSWA, OSWE, GWAPT, or GMOB.

Culture & Benefits

  • Medical, vision, dental, life, and disability insurance options.
  • Retirement benefits including 401(k).
  • Paid time away, PTO accruals, and holidays.
  • Merchandise discount and employee assistance resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →