Назад
Company hidden
1 день назад

Software Security Engineer (FinTech)

110 000 - 120 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Software Security Engineer (FinTech): Building application and software security capabilities across AI-powered features, CI/CD pipelines, cloud infrastructure, and containerized services with an accent on secure coding, automated vulnerability management, and DevSecOps. Focus on reviewing code, integrating SAST/DAST/SCA tooling, hardening AI agents and LLM-backed features, and improving bot management, WAF, and API security controls.

Location: 5-day onsite role in Pittsburgh, Pennsylvania, United States

Salary: $110,000–$120,000 per year

Company

hirify.global is a Pittsburgh-based FinTech and e-commerce company developing financial products, gifting platforms, card-to-card gifting technology, and robotic fulfillment solutions.

What you will do

  • Perform code reviews, SAST/DAST testing, penetration tests, and threat modeling across application code, libraries, containers, and infrastructure as code.
  • Work with developers and DevOps engineers to remediate vulnerabilities and improve secure software delivery.
  • Integrate security tooling such as Snyk, Semgrep, and Cycode into CI/CD pipelines and automate vulnerability triage and reporting.
  • Build automation for routing and reporting findings and operate the enterprise Bug Bounty program.
  • Improve Bot Management, WAF, secrets management, and API security controls.
  • Advise on and test new application and AI functionality and develop application and AI security training.

Requirements

  • 2+ years of experience in software development, software security, or DevSecOps with security exposure; equivalent experience may replace a bachelor's degree.
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field, unless equivalent experience is provided.
  • Real coding experience and working knowledge of OWASP Top 10 and SANS CWE Top 25 secure coding principles.
  • Hands-on exposure to CI/CD pipelines such as GitHub, GitLab, Jenkins, or AWS DevOps.
  • Strong verbal and written communication skills for explaining security concepts to technical and non-technical colleagues.
  • Ability and enthusiasm to work onsite in Pittsburgh five days per week.

Nice to have

  • Experience with vulnerability scanners, Bot Management, SAST/DAST/SCA, DSOMM, or BSIMM.
  • CISSP, OSCP, GCSA, AWS Security Specialty, or CSSLP certifications.

Culture & Benefits

  • In-person mentoring and support for professional security certifications.
  • Medical, prescription, vision, and dental insurance for employees and dependents, with hirify.global paying 80% of premiums.
  • Short-term disability insurance fully paid by hirify.global, plus additional voluntary insurance options.
  • RSUs, profit share or incentive bonus, 401(k), PTO, corporate holidays, and floating holidays.
  • Tuition reimbursement, internal training, employee recognition, charitable donations, and referral bonuses.
  • Family and employee events, including a family picnic, holiday party, outings, and an internal Culture Club.

Hiring process

  • Resume review followed by first, team, culture, and final interviews.
  • Offer, background check, and start.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →