Назад
Company hidden
19 часов назад

Senior Security Engineer (AI Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Application and AI Security): Leading application security reviews across the SDLC and reducing security risk for web, API, cloud, and AI/ML systems with an accent on threat modeling, secure code review, vulnerability remediation, and vendor coordination. Focus on assessing prompt injection, data leakage, model abuse, and supply-chain risks while improving security operations, detection, incident response, and infrastructure hardening.

Location: Hybrid in Livermore, California, USA, during standard business hours, with periodic coordination across time zones and occasional after-hours incident support.

Company

hirify.global designs, manufactures, and distributes productivity tools for construction, geopositioning, and agriculture, focusing on workflow automation and connected data.

What you will do

  • Lead application security reviews across the software development lifecycle, including threat modeling, secure design reviews, and secure code reviews.
  • Assess web applications, APIs, cloud services, and AI/ML or LLM-based systems for security risks.
  • Triage vulnerabilities from SAST, DAST, SCA, and penetration testing, and drive remediation with engineering teams.
  • Manage the day-to-day technical relationship with an offshore security vendor, including scoping work, reviewing deliverables, and tracking risks and commitments.
  • Support security operations through detection monitoring, alert investigation, incident response, vulnerability management, and infrastructure or endpoint hardening.
  • Improve security practices, runbooks, detection quality, and AI security standards and guardrails.

Requirements

  • 6+ years of experience in security engineering with hands-on application security experience.
  • Practical experience with security operations, including monitoring, detection, or incident response.
  • Experience maintaining an offshore or third-party vendor relationship across time zones.
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • Knowledge of OWASP, secure SDLC practices, common vulnerability classes, cloud security, CI/CD, and containerized environments.
  • Strong written and verbal communication skills, with the ability to work across engineering, operations, and external partners.

Nice to have

  • Exposure to AI/ML or LLM security concepts.
  • Relevant certifications such as OSCP, GWAPT, CSSLP, CISSP, or a cloud security certification.
  • Scripting and automation skills, such as Python.

Culture & Benefits

  • Hybrid work in a standard office and remote environment.
  • Occasional travel may be required.
  • Periodic cross-time-zone coordination supports the offshore security vendor.
  • Work involves collaboration with engineering, operations, and external security partners.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →