Назад
Company hidden
1 час назад

Application Security Engineer

100 000 - 160 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Application Security): Embedding security throughout the software development lifecycle by conducting threat modeling, code reviews, vulnerability management, and runtime protection across a U.S.-based application portfolio with an accent on secure architecture, offensive and defensive security, and engineering enablement. Focus on operating SAST, DAST, IAST, SCA, and secret-scanning tools, leading red-team exercises, hardening cloud and Kubernetes environments, and responding to application security incidents.

Location: 100% remote within the United States

Salary: $100,000–$160,000 annually

Company

hirify.global is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.

What you will do

  • Conduct threat modeling, security architecture reviews, manual code reviews, and secure design consultations.
  • Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines.
  • Manage vulnerability workflows, including triage, prioritization, ownership, remediation SLAs, and CVE tracking.
  • Build secure libraries and frameworks, and implement authentication, authorization, session management, and cryptographic patterns.
  • Lead red-team and purple-team exercises and operate runtime protections such as WAF, RASP, bot protection, and abuse detection.
  • Partner with engineering, infrastructure, and platform teams on cloud, container, and Kubernetes security; deliver training and respond to application security incidents.

Requirements

  • 10+ years of application security or security engineering experience.
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Strong knowledge of OWASP Top 10, vulnerability classes, exploit patterns, authentication, authorization, and cryptography.
  • Hands-on code review experience across at least two major programming languages and proficiency in one language for tooling and automation.
  • Deep familiarity with SAST, DAST, SCA, CI/CD-integrated security tooling, cloud security, and modern infrastructure controls.
  • Strong communication skills and experience working with engineering teams in an Agile environment. Applicants must be U.S. Citizens, Green Card Holders, EAD Holders, or H-1B transfer candidates; new H-1B visa petitions cannot be sponsored.

Nice to have

  • OSCP, OSCE, GWAPT, CISSP, or similar industry certification.
  • Offensive security tooling, red-team operations, bug bounty, public CVE, or open-source security contribution experience.
  • Familiarity with AI/LLM application security and regulated industries with strict compliance requirements.

Culture & Benefits

  • Full-time direct W2 employment.
  • Remote work within the United States.
  • Collaboration with engineering teams to make secure software development efficient.
  • Opportunity for career growth within an established technology consulting and software development organization.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →