Назад
Company hidden
1 день назад

Senior Application Security Engineer (Cybersecurity)

140 000 - 165 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Cybersecurity): Building and evolving an application security program across Ruby on Rails, React Native, Python, and Go applications with an accent on secure development, vulnerability management, and cloud security. Focus on integrating SAST, DAST, WAF, mobile security, and secret-scanning tools into CI/CD pipelines, hardening AWS infrastructure, and guiding threat modeling and remediation.

Location: Remote

Base salary: $140,000–$165,000 USD annually, plus eligibility for an annual bonus.

Company

hirify.global helps Americans manage and escape debt through individualized financial solutions, user-centric technology, and a compliance- and ethics-focused approach.

What you will do

  • Own and evolve the application security strategy, roadmap, and daily operations.
  • Partner with development teams working on Ruby on Rails web applications, React Native mobile applications, Python, and Go projects.
  • Provide security guidance during architecture, feature design, development, code review, and threat modeling.
  • Manage and optimize GitHub Advanced Security, Invicti, Hadrian, AppDome, and Cloudflare WAF.
  • Integrate security tooling into CI/CD pipelines and build secure development standards, playbooks, and training materials.
  • Collaborate with DevOps on AWS security, including ECS, IAM, networking, cloud configurations, and vulnerability remediation.

Requirements

  • 3–7+ years of experience in application security, product security, or related engineering roles.
  • Strong knowledge of secure coding, OWASP Top 10 vulnerabilities, and modern SDLC practices.
  • Experience with cloud-native applications, preferably in AWS.
  • Understanding of SSL certificates and cryptographic key management.
  • Hands-on experience with SAST, DAST, WAF, and/or mobile application security tools.
  • Ability to influence secure design decisions and work effectively with developers; familiarity with GitHub workflows and CI/CD pipelines.

Nice to have

  • Ruby on Rails or similar dynamic-language development experience.
  • AWS ECS/EKS, container security, secrets management, CloudFormation, or Terraform experience.
  • Experience building or maturing an application security program.
  • SOAR automation, scripting, or PCI-compliant environment experience.

Culture & Benefits

  • Collaborative environment focused on community, connection, and belonging.
  • Employer contributions toward health, dental, and vision programs for eligible full-time employees.
  • Generous PTO, paid holidays, and paid parental leave.
  • 401(k) matching program.
  • Merit advancement opportunities and career development and training.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →