Назад
Company hidden
5 дней назад

Principal Cyber Security Engineer (AI)

249 000 - 348 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Cyber Security Engineer (AI): Building enterprise-scale security platforms, cloud controls, and SDLC integrations for a global travel technology platform with an accent on AWS security, zero-trust infrastructure, service mesh protection, and AI system security. Focus on implementing LLM, RAG, and agentic AI safeguards, operationalizing CSPM/DSPM programs, and embedding automated controls into high-velocity engineering workflows.

Location: San Jose, California, United States

Salary: $249,000–$348,500 annual total cash; the range may increase up to $398,500 based on sustained performance.

Company

hirify.global is a global travel technology company connecting travelers, partners, and advertisers through consumer brands, B2B travel services, and travel advertising.

What you will do

  • Design, build, and operate reusable security platforms, shared services, reference architectures, and automated policy-as-code controls.
  • Implement cloud-native security across AWS and multi-cloud environments, including IAM, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, and KMS.
  • Secure service mesh and distributed microservices with mTLS, workload identity, traffic policies, network segmentation, and zero-trust controls.
  • Embed threat modeling, SAST, DAST, SCA, CSPM, DSPM, and runtime security into CI/CD and engineering workflows.
  • Implement security architecture for LLM applications, RAG pipelines, and agentic AI systems, including controls for prompt injection, model abuse, data exfiltration, and agent trust boundaries.
  • Partner with engineering, platform architecture, AI, and technology leadership teams to deliver measurable security outcomes and influence strategy through execution.

Requirements

  • 15+ years of hands-on cybersecurity experience building and operating enterprise-scale security systems.
  • Practitioner-level AWS expertise and experience operating cloud security controls in high-velocity release environments.
  • Production experience with SDLC security architecture, CI/CD integration, developer tooling, SAST/DAST/SCA, and runtime security.
  • Hands-on service mesh experience with mTLS, workload identity, traffic policy, and zero-trust enforcement using Istio, Envoy, Linkerd, or equivalent.
  • Experience implementing security controls for LLM, RAG, and agentic AI systems, plus operational CSPM and DSPM programs.
  • Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience; strong technical communication and cross-functional influence skills.

Nice to have

  • Experience in large-scale multi-cloud e-commerce or travel technology environments.
  • Experience securing production agentic AI and LLM applications, including red-teaming and abuse-scenario validation.
  • Experience building security-as-a-platform services, self-service tooling, security libraries, or SDKs.
  • People leadership or technical lead experience and certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer.
  • Applied experience with PCI-DSS, SOC 2, GDPR, and ISO 27001.

Culture & Benefits

  • Senior individual contributor role with director-level scope; people management is optional for suitable candidates.
  • Collaborative environment focused on traveler-first products, ownership, excellence, and practical security outcomes.
  • Medical, dental, and vision coverage, paid time off, and an Employee Assistance Program.
  • Wellness and travel reimbursement, travel discounts, and IATAN membership.
  • Inclusive and accessible recruiting experience with accommodation support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →