Назад
Company hidden
3 часа назад

Senior Security Engineer, Product Security

146 000 - 185 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, Product Security (AI/LLM Security): Building production security services and testing AI- and LLM-backed features for a regulated consumer-finance platform with an accent on application security, backend engineering, and threat modeling. Focus on designing adversarial attacks, validating vulnerabilities across APIs and web applications, securing AWS infrastructure, and defining launch criteria for agentic systems.

Location: Remote, United States

Salary: $146,000–$185,000 per year

Company

hirify.global is a technology company providing financing and software products for sustainable home solutions, including solar, energy-efficient HVAC, roofing, and related services.

What you will do

  • Adversarially test AI- and LLM-backed applications and agents for prompt injection, jailbreaks, tool abuse, and data exfiltration.
  • Build and operate production security services and internal tooling using TypeScript, Node.js, .NET, or Python.
  • Review product requirements, technical designs, and pull requests to identify vulnerabilities, trust-boundary issues, and insecure data flows.
  • Perform manual security testing of web applications and APIs, validate exploitability, retest fixes, and support bug bounty and penetration-testing programs.
  • Operate and improve AppSec tooling, including SAST and dependency scanning, vulnerability triage, routing, SSO, and access management.
  • Secure the supporting infrastructure and enable engineering teams through training, documentation, and practical security guidance.

Requirements

  • Senior-level backend engineering experience with production services, asynchronous patterns, HTTP APIs, and streaming transports.
  • Ability to read and assess code across multiple languages and technology stacks.
  • Strong understanding of identity, authorization, OAuth, token handling, sessions, request signing, SSRF, and DNS rebinding.
  • Practical experience securing REST and GraphQL APIs, OpenAPI contracts, input validation, rate limiting, gateway authentication, webhooks, and service-to-service verification.
  • Hands-on AWS and infrastructure-as-code experience, including IAM, secrets management, containers, network egress, and compute lifecycle management.
  • Practical experience attacking an LLM-backed application or agent and communicating findings clearly to engineering, product, executive, and legal audiences.

Nice to have

  • Experience owning AppSec tooling, tuning SAST or SCA, reducing false positives, and routing findings.
  • Structured vendor evaluations, security policy or AI standards work, or security training experience.
  • Depth in cryptography and key management.
  • Detection engineering, incident response, or threat hunting experience.
  • Understanding of SaaS product development, roadmaps, prioritization, and delivery constraints.

Culture & Benefits

  • Remote work within the United States.
  • Collaboration with product and engineering teams to make shipped software secure by default.
  • Work on security for regulated consumer-finance products and emerging LLM and agentic capabilities.
  • Opportunity to contribute across product security, vulnerability management, security analytics, investigations, and incident response.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →