Назад
Company hidden
2 дня назад

Senior Manager, Application Vulnerability Validation & Verification - USDS (Cybersecurity)

199 800 - 441 600$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager, Application Vulnerability Validation & Verification - USDS (Cybersecurity): Building and leading an application vulnerability validation function that confirms production exploitability across web, mobile, and API surfaces with an accent on AppSec leadership, automated triage, and attack-path analysis. Focus on developing scanner integrations and LLM-assisted tooling, mapping systemic blast radius, and driving secure architectural mitigations across distributed engineering organizations.

Location: San Jose, United States; fully in-person schedule up to 5 days a week

Salary: $199,800–$441,600 annually, with possible discretionary bonuses, incentives, and restricted stock units.

Company

hirify.global operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the U.S. content ecosystem.

What you will do

  • Build, lead, hire, mentor, and technically direct an Application Security engineering team.
  • Develop the automation strategy for application vulnerability validation, including scanner API integrations, custom tooling, and LLM-assisted triage.
  • Oversee deep technical verification across web, iOS, Android, and API endpoints to confirm real production exploitability.
  • Analyze attack paths, vulnerability chaining, and blast radius across a large software supply chain.
  • Partner with U.S. and global engineering teams to implement systemic security mitigations.
  • Provide actionable secure-coding and architectural guidance as a principal internal consultant.

Requirements

  • Leadership experience in Application Security, Product Security, or Software Security Engineering, typically including 5 years of domain experience and formal team management.
  • Strong software development and scripting skills in Python, Go, Java, or JavaScript.
  • Deep experience with enterprise SAST, DAST, and SCA platforms such as Checkmarx, Veracode, Burp Suite Enterprise, Snyk, or GitHub Advanced Security.
  • Strong understanding of microservices, service mesh, CI/CD pipelines, Kubernetes, Docker, and API gateways.
  • Ability to coordinate remediation across large distributed engineering organizations and communicate objective threat evidence.

Nice to have

  • Advanced security certifications such as OSWE, OSWA, GWE, CASE, or CSSLP.
  • Experience with formal threat-modeling frameworks for complex features.

Culture & Benefits

  • On-site collaboration focused on speed, alignment, real-time decision-making, team development, and integrated execution.
  • Medical, dental, and vision insurance from day one.
  • 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
  • Wellbeing benefits, 10 paid holidays, 10 paid sick days, and 17 days of paid personal time.
  • Inclusive workplace with reasonable accommodation support during recruitment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →