Назад
Company hidden
2 часа назад

Cybersecurity Application Security Engineer (AI/LLM)

90 000 - 125 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Application Security Engineer (AI/LLM): Protecting applications, services, and AI-driven components through secure code review, security testing, automation, and secure SDLC practices with an accent on application security, CI/CD integration, and AI/LLM threat modeling. Focus on identifying prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities while building automated security tooling and communicating risks to engineering and management.

Location: Centennial, Colorado; hybrid work with in-office presence three days per week for associates living within 30 miles of an office location. US citizenship and existing authorization to work in the United States are required.

Salary: $90,000–$125,000 annually, depending on experience.

Company

hirify.global is a diversified services company operating across student lending, payments processing, renewable energy, and K–12 and higher education.

What you will do

  • Perform manual source code reviews and SAST/DAST security scanning.
  • Integrate security tooling and automated checks into CI/CD pipelines.
  • Develop automated source code review processes and custom security tooling.
  • Expand the Security Champions program and help product teams implement secure SDLC practices.
  • Assess application, web, mobile, container, secrets, and AI-related vulnerabilities.
  • Prepare detailed vulnerability reports and communicate risk and urgency to business, management, and engineering stakeholders.

Requirements

  • 2–4 years of hands-on application security experience.
  • Strong manual code review experience in at least one major language, such as Java, JavaScript/TypeScript, C#, or PHP.
  • Experience with SAST, SCA, DAST, web and mobile penetration testing, container scanners, and secrets-detection tools.
  • Experience integrating security tooling and automated checks into CI/CD pipelines, with scripting skills in Python, Bash, or Node.
  • Threat-modeling expertise using STRIDE, attack trees, or misuse cases for traditional and AI/LLM-integrated systems.
  • Knowledge of web/API security, secure SDLC practices, OWASP Top 10, and AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities.

Nice to have

  • Experience building internal developer tooling or conducting secure code reviews.
  • Experience with AI/LLM-integrated applications, model security, or prompt safety.
  • Mobile security, reverse engineering, or platform-specific secure coding experience.
  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or an ML security certification.
  • Experience mentoring junior developers or engineers in secure design and coding practices.

Culture & Benefits

  • Hybrid work environment supporting flexibility and regular in-office collaboration.
  • Medical, dental, vision, HSA, and FSA benefits.
  • Earned time off, life and disability insurance, and an employee assistance program.
  • 401(k), student loan repayment, employee stock purchase program, and tuition reimbursement.
  • Performance-based incentive pay and wellness program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →