Назад
Company hidden
12 дней назад

Product Security Engineer (AI)

Формат работы
remote (только Sri_lanka)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
SL
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (AI): Managing vulnerability assessment and remediation across a containerized AI cloud platform with an accent on security scanning, dependency upgrades, container image security, and compliance operations. Focus on analyzing exploitability, coordinating fixes across engineering teams, validating remediation through rescanning, and supporting FedRAMP monitoring and customer security reviews.

Location: Based in Sri Lanka; remote-friendly environment

Company

hirify.global develops open-source and enterprise AI cloud platform solutions for organizations and public sector agencies, with a focus on secure, compliant, and infrastructure-flexible AI deployments.

What you will do

  • Lead vulnerability scan analysis and triage across the containerized cloud platform, assessing exploitability and contextual risk.
  • Coordinate remediation with engineering teams, route findings to component owners, and track resolution through completion.
  • Remediate vulnerabilities hands-on by upgrading dependencies, rebuilding container images, and contributing code fixes.
  • Test fixes and verify remediation through pre- and post-deployment rescanning.
  • Maintain vulnerability management tooling and automation, including container security controls and Kubernetes security policies.
  • Support FedRAMP monitoring, compliance reporting, customer security reviews, incident response, and audit documentation.

Requirements

  • 2–4 years of experience in application security, product security, or DevSecOps, plus 3+ years of software engineering experience.
  • Strong coding skills in at least two languages, such as Python, JavaScript, Go, Ruby, or Java.
  • Experience with dependency management, CI/CD, Git, code review, debugging, deployment, and testing.
  • Strong understanding of container security, vulnerability management, CVE assessment, and security scanning tools.
  • Familiarity with Kubernetes security concepts and best practices.
  • Strong written and verbal communication skills, follow-through, customer focus, and ability to manage multiple priorities in a remote-first environment.

Nice to have

  • Experience with FedRAMP, SOC 2, ISO 27001, or banking regulations.

Culture & Benefits

  • Remote-friendly culture with a flexible working environment.
  • Career growth opportunities.
  • Work with a distributed, world-class AI engineering organization.
  • Market-leading total rewards.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →