Назад
Company hidden
1 день назад

Senior Engineer – Cybersecurity Application Security (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Engineer – Cybersecurity Application Security (AI): Implementing and improving application security tooling, controls, and governance across secure software development workflows with an accent on API security, software supply chain protection, and CI/CD integration. Focus on securing AI-assisted development, analyzing application security risk, and building automation that improves remediation and secure-by-default adoption.

Location: Irving, TX, United States

Company

hirify.global operates in financial services and is hiring for application security engineering.

What you will do

  • Implement, administer, and continuously improve application security platforms supporting secure software development.
  • Integrate security testing and automated controls into CI/CD pipelines and engineering workflows.
  • Develop and maintain application security standards, policies, procedures, documentation, and operational guidance.
  • Analyze security findings, operational metrics, and compliance trends to identify risks and improvement opportunities.
  • Partner with engineering, architecture, platform, and cybersecurity stakeholders to advance secure-by-design and secure-by-default practices.
  • Support secure SDLC governance, vulnerability management, remediation tracking, and security automation initiatives.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • At least 5 years of application security engineering experience.
  • Experience with SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security platforms.
  • Experience securing APIs across their lifecycle, including discovery, authentication and authorization validation, schema and contract testing, abuse-case analysis, OWASP API Security Top 10 risks, and remediation guidance.
  • Experience integrating security tooling and controls into CI/CD pipelines using infrastructure as code, as well as supporting secure SDLC governance and compliance reporting.
  • Strong knowledge of application security principles, secure coding, OWASP Top 10 risks, vulnerability remediation, technical documentation, and stakeholder communication.

Nice to have

  • CSSLP, GSEC, CISSP, GWAPT, or a similar industry certification.
  • Experience in financial services, banking, or other highly regulated environments.
  • Experience governing security controls for AI-assisted development, including code-generation tools, prompt and output handling, developer guardrails, and risk monitoring.
  • Experience with security automation, scripting, workflow orchestration, and security metrics dashboards.

Culture & Benefits

  • Full-time employment.
  • Collaboration with cybersecurity, architecture, platform, and engineering stakeholders.
  • Opportunity to improve application security maturity and reduce manual operational effort through automation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →