Назад
Company hidden
обновлено 36 минут назад

AppSec Engineer (AI)

Тип работы
fulltime
Грейд
middle
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
AppSec Engineer (AI): Securing a large web platform through application security reviews, vulnerability remediation, scanning pipelines, bug bounty operations, and AI-driven automation with an accent on secure SDLC, vulnerability disclosure, and developer collaboration. Focus on building AI agents for triage and remediation, integrating SAST/DAST/SCA tools, and designing security architecture for AI-produced code and workflows.

Location: Not specified

Company

hirify.global develops a platform used to build websites, applications, and online businesses, with security integrated into product development.

What you will do

  • Partner with R&D teams to identify, triage, and remediate application-level vulnerabilities.
  • Review code, architecture, new features, integrations, and third-party dependencies.
  • Run and tune SAST, DAST, and SCA tools across the codebase and CI/CD pipelines.
  • Lead the Bug Bounty and vulnerability disclosure program, including scoping, triage, severity assessment, payouts, researcher communication, and SLA handling.
  • Build AI agents, automation workflows, scripts, and integrations that reduce manual triage and accelerate remediation.
  • Design security mechanisms for AI-produced code and workflows and evaluate automation platforms such as n8n and Zapier.

Requirements

  • 2–4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
  • Understanding of common web and application vulnerabilities, including the OWASP Top 10.
  • Experience with application security testing, SAST, DAST, SCA, and CI/CD security configuration.
  • Hands-on experience using AI tools and building AI agents for practical workflows.
  • Basic coding and scripting skills in Python, Bash, JavaScript, or a similar language.
  • Strong communication skills and the ability to work with developers and cross-functional teams.

Nice to have

  • Experience running or participating in Bug Bounty or responsible disclosure programs.
  • Experience with Patchstack, Bugcrowd, Wordfence, or similar vulnerability disclosure and WAF/plugin security platforms.
  • Familiarity with n8n, Zapier, or custom AI agents for security automation.
  • Cloud security fundamentals across AWS, Azure, or GCP.

Culture & Benefits

  • Work closely with R&D to integrate security into products from the beginning of the development lifecycle.
  • Ownership of security initiatives, including the Bug Bounty program.
  • Use AI coding tools such as Claude Code and Cursor to improve security workflows.
  • Focus on automation, practical developer guidance, and reducing repetitive security work.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →