Назад
Company hidden
3 дня назад

Senior Application Security Engineer (AI)

Формат работы
remote
Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Securing the Temporal development pipeline, product, and customer execution environment across multiple clouds with an accent on threat modeling, secure development, Kubernetes security, and multi-tenant architecture. Focus on identifying vulnerabilities across the product surface, hardening workloads and control planes, preventing cross-tenant data leakage, and translating emerging AI security standards into internal policy.

Location: Remote-first; roles may be remote in-country or within a region, with occasional travel for onboarding and team gatherings.

Company

hirify.global develops a platform for durable, distributed application execution across multiple clouds.

What you will do

  • Integrate security principles into product design and architecture in partnership with product and engineering teams.
  • Conduct threat modeling and risk assessments across the full product surface.
  • Manage code security and third-party library supply chain security within the secure development pipeline.
  • Translate emerging guidance, including OWASP Top 10 for LLMs and MCP security specifications, into actionable internal policy.
  • Triage bug bounty findings and responsibly disclosed vulnerabilities.
  • Participate in the on-call rotation.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
  • 5+ years of experience in application security, product security, or a related role.
  • Experience partnering with engineering teams throughout planning and development.
  • Knowledge of encryption, authentication, secure communication protocols, application architecture, and vulnerability identification across multiple programming languages.
  • Experience with SAST, DAST, penetration testing frameworks, Kubernetes security posture management, workload hardening, RBAC design, and admission control.
  • Experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention; expertise in at least one programming language and familiarity with Python and Go.

Nice to have

  • Distributed computing and related vulnerability experience.
  • Experience running a Security Champions program.
  • Open source automation or automation project experience.
  • Additional security expertise, security conference talks, or published research.

Culture & Benefits

  • Remote-first work model with occasional travel for onboarding and team gatherings.
  • Competitive benefits and equity.
  • Flexible time off.
  • Support for learning, wellness, and a home office.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →