Назад
Company hidden
1 день назад

Senior Security Application Engineer - Automation & Detection

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Mexico
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Application Engineer - Automation & Detection (Agentic Security and Cryptographic Infrastructure): Building agentic detection and response workflows, security automation, and cryptographic infrastructure for firmware signing, device identity, and attestation with an accent on MITRE ATT&CK/ATLAS, AI agent governance, PKI, HSM operations, and post-quantum cryptography. Focus on developing detections-as-code, automated triage, signing pipelines, certificate lifecycle management, and security controls across firmware and CI/CD environments.

Location: Zapopan, Mexico; full-time onsite role

Salary: USD 0–0 yearly

Company

hirify.global is a global memory technology company developing data storage products and related firmware, security, and cryptographic infrastructure.

What you will do

  • Define detection coverage standards, map threats to MITRE ATT&CK techniques, and track detection quality, MTTD, false positives, and coverage gaps.
  • Build detections-as-code, automated triage, supervised agentic response workflows, and secure AI agent identity and delegation controls.
  • Support product security and code-signing infrastructure for firmware signing, device identity, PKI, attestation, HSM operations, and cryptographic key workflows.
  • Develop signing-pipeline, certificate-management, access-provisioning, telemetry, audit-logging, and anomaly-detection automation integrated with CI/CD.
  • Embed security controls into firmware, manufacturing, and release environments, including SAST, SBOM validation, attestation signing, and supply-chain controls.
  • Lead security engineering initiatives, participate in threat modeling and purple-team exercises, mentor engineers and analysts, and contribute to security governance and roadmaps.

Requirements

  • B.S. degree in information security, cybersecurity, computer science, software engineering, or a related field.
  • Advanced English proficiency is mandatory.
  • 4–6+ years of relevant hands-on experience in security engineering or a related field.
  • Software development experience with Python, API integration, infrastructure-as-code, and CI/CD pipelines.
  • Experience with detection engineering, SIEM/SOAR platforms such as Microsoft Sentinel or Splunk, incident response, and MITRE ATT&CK coverage analysis.
  • Experience with AI agents or RAG pipelines, AI security governance, PKI, HSM operations, certificate lifecycle management, and code-signing pipelines.

Nice to have

  • Experience with Entrust nShield, Fortanix DSM, EJBCA, KeyFactor, Venafi, or comparable platforms.
  • Experience with firmware or binary signing, SBOM signing, attestation, post-quantum cryptography, ML-DSA, or LMS.
  • Knowledge of NIST FIPS 140-3, CNSA 2.0+, OCP, ISO 27001, or SOX ITGC.
  • Experience with Microsoft Defender XDR, Sentinel, Security Copilot, Logic Apps, KQL, Azure, Splunk, MCP, LangChain, or workload identity platforms.

Culture & Benefits

  • Work within a global technology organization with operations across the United States, Asia, Europe, and the Americas.
  • Collaborate across firmware engineering, manufacturing, product security, application security, and operations.
  • Participate in structured operational and governance routines, including KPI reporting, CISO reviews, and the Cryptographic Architecture Board.
  • Promote security-by-design, test-driven development, agile practices, technical mentoring, and inclusive teamwork.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →