application security engineer in AI-driven platforms

HireHi

United States

Remote

USD 120,000 - 180,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Solvd Inc. ищет опытного специалиста по безопасности приложений в США.

Ваша задача — определить и валидировать контроль безопасности на всех стадиях доставки, выполнять архитектурные обзоры и threat modelling, проверять аутентификацию/авторизацию и безопасность API, а также руководить управлением секретами и контролью уязвимостей. Кандидат должен обладать опытом работы с GDPR, шифрованием и подготовкой документации по приемке безопасности.

Qualifications

  • Опыт 5+ лет в области обеспечения безопасности приложений, безопасности инженерии или схожей роли.
  • Опыт проведения threat modelling и архитектурных обзоров безопасности для сложных платформ.
  • Знания паттернов аутентификации и авторизации: OAuth/OIDC/RBAC/privileged access management.
  • Навыки проверки безопасности API и интеграций с внешними сервисами.
  • Опыт управления секретами, обработкой учетных данных и жизненным циклом токенов.
  • Опыт поддержки или координации сканирования уязвимостей и пентестов.
  • Знание стандартов шифрования и безопасной обработки данных в хранении и передаче.
  • Знакомство с GDPR и требованиями privacy-by-design.
  • Умение подготовить понятные рекомендации по исправлению и документацию по приемке безопасности для команд разработки и поставки.
  • Желательно: опыт обеспечения безопасности CMS или медиа-платформ (AEM, Amplience), опыт работы с высоконагруженными платформами, SIEM и планы реагирования на инциденты, процессы оценки поставщиков, сертификации CISSP/OSCP/CEH и участия в фазы полного жизненного цикла продуктов.

Responsibilities

  • Определять и валидировать контроль безопасности приложений и платформ на всех стадиях доставки.
  • Проводить архитектурные обзоры и threat modelling на стадии дизайна и развивающейся платформы.
  • Рассматривать аутентификацию, авторизацию и управляемый доступ на всех компонентах CMS, API и интегрированных сервисов.
  • Проверять безопасность API и интеграций в мультивендорной архитектуре.
  • Контролировать управление секретами, обработку токенов и доступом.
  • Оказывать поддержку сканирования уязвимостей и тестирования на проникновение; координировать находки и исправления.
  • Подтверждать методы шифрования и безопасную обработку данных при хранении и передаче.
  • Рассматривать требования к логированию, мониторингу и реагированию на инциденты.
  • Участвовать в GDPR и privacy-engineering на протяжении доставки.
  • Проводить внешние оценки безопасности третьих сторон и поставщиков.
  • Предоставлять пути устранения и документацию по безопасности перед запуском.

Skills

Threat modelling
OAuth/OIDC
RBAC
API security
Secrets management
Vulnerability testing
Encryption standards
GDPR familiarity
Security documentation
SIEM

Tools

AEM
Amplience

Job description

Описание

Solvd Inc. is an AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. Following the acquisition of Tooploox, it provides end-to-end delivery from strategic advisory and solution design to custom AI development and enterprise-scale implementation.

Задачи
  • Define and validate application and platform security controls across all delivery phases;
  • Perform architecture and threat-model reviews at the design stage and as the platform evolves;
  • Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services;
  • Validate API and integration security across a composable, multi-vendor platform architecture;
  • Review secrets, credentials, and token-management practices across the full stack;
  • Support vulnerability scanning and penetration-testing activities by coordinating findings and remediation;
  • Validate encryption and secure data handling across storage, transit, and third-party integrations;
  • Review security logging, monitoring, and incident-response requirements;
  • Support GDPR and privacy engineering requirements throughout delivery;
  • Conduct third-party security assessments for integrated services and vendors;
  • Provide remediation guidance and produce security acceptance evidence ahead of launch.
Требования
  • 5+ Years of experience in application security, security engineering, or a closely related role;
  • Experience performing threat modelling and architecture security reviews on complex, multi-component platforms;
  • Strong knowledge of authentication and authorization patterns, including OAuth, OIDC, RBAC, and privileged access management;
  • Hands-on experience validating API security and reviewing integration patterns across third-party services;
  • Solid understanding of secrets management, credential handling, and token lifecycle best practices;
  • Experience supporting or coordinating vulnerability scanning and penetration testing programmes;
  • Knowledge of encryption standards and secure data handling practices across storage and transit;
  • Familiarity with GDPR and privacy-by-design engineering requirements;
  • Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams;
  • Nice to have: experience securing composable CMS or media platform architectures such as AEM or Amplience, experience with high-traffic public-facing platforms, security logging and monitoring tooling including SIEM and incident response playbooks, third-party vendor security assessment processes, CISSP/OSCP/CEH or equivalent certification, experience working within a phased full-lifecycle delivery programme alongside engineering and architecture teams.
Условия

No conditions specified.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer for AI-Driven Platforms
Application Security Engineer for AI-Driven Platforms

HireHi • United States

Remote
USD 120,000 - 180,000
data engineer in risk and compliance
data engineer in risk and compliance

HireHi • United States

Remote
USD 120,000 - 180,000
full stack developer in insurance
full stack developer in insurance

HireHi • United States

Remote
USD 110,000 - 180,000
full stack developer in AI platforms
full stack developer in AI platforms

HireHi • United States

Remote
USD 100,000 - 140,000
qa engineer (auto)
qa engineer (auto)

HireHi • United States

On-site
USD 90,000 - 130,000
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
devsecops engineer
devsecops engineer

HireHi • United States

On-site
USD 140,000 - 180,000
Application Security Engineer
Application Security Engineer

Prediktive • New York (NY)

Remote
USD 130,000 - 190,000
Application Security Engineer - Senior
Application Security Engineer - Senior

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
node.js developer for AI Agents
node.js developer for AI Agents

HireHi • United States

Remote
USD 31,000 - 54,000