drjobs Senior Application Security Engineer

Senior Application Security Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

San Francisco, CA - USA

Monthly Salary drjobs

$ 150000 - 235000

Vacancy

1 Vacancy

Job Description

We are seeking a Senior Application Security Engineer to join our product security engineering team and help build a secure foundation for our products. You will play a critical role in identifying mitigating and preventing security issues across our codebase architecture and runtime environments and further strengthen the secure software development lifecycle. This role requires a strong background in application security deep technical expertise in secure coding practices and a passion for secure software development in cuttingedge technologies including Web3 AI/LLMs and decentralized platforms.

This is a hybridonsite position (onsite 3x per week) based out of our new office in the heart of San Francisco.

Responsibilities

  • Perform indepth security design and code reviews particularly in Rust and web frontends and extending to system security aspects. Identify potential vulnerabilities and design flaws.
  • Design implement use and maintain static and dynamic analysis tools and fuzz testing frameworks for continuous security validation.
  • Lead threat modeling sessions and proactively shape the secure design of complex systems.
  • Leverage knowledge of application security attack vectors and standards such as OWASP CWE and CAPEC to inform secure development.
  • Champion securebydesign practices and partner closely with engineering to embed security throughout the SDLC. Promote security best practices within DFINITY and the ICP community.
  • Contribute to incident response coordination and third party vulnerability management.
  • Contribute security expertise to systems that interact with Web3 technologies and decentralized architectures identifying unique risks in blockchainbased applications.

Requirements

  • 5 years of experience in product or application security roles.
  • Strong proficiency in Rust and familiarity with web frontends especially from a secure software development and auditing perspective.
  • Handson experience developing or integrating fuzz testing and dynamic analysis tools.
  • Deep knowledge of application security fundamentals including secure coding common vulnerabilities and attack surface minimization.
  • Demonstrated ability to identify and remediate complex security design flaws.
  • Exposure to blockchain smart contract or Web3 systems security concerns and risk models.
  • Excellent communication and collaboration skills in crossfunctional environments.

Preferred Qualifications

  • Experience contributing to open source security tools or frameworks.
  • Familiarity with blockchain protocollevel vulnerabilities or smart contract audits.
  • Familiarity with or proficiency in systems security is a strong plus such as:
    • Experience with Trusted Environments (TEEs) using AMD SEVSNP
    • Linux OS and process isolation security including syscall filtering SELinux seccomp sandboxing untrusted processes kernel vulnerabilities
    • Hypervisor and virtualization security including QEMU VM isolation guesttohost escapes sidechannel attacks container security
  • AI/LLM security expertise is a major plus including understanding adversarial attacks prompt injection model data leakage and safe deployment of deep learning models.
  • Past work in environments with highassurance security or regulated sectors is a bonus.

Base Salary Range: $150000 $235000/yr

This position can be considered across multiple levels. Total compensation at DFINITY consists of base salary generous bonus and is determined based on multiple factors including job leveling areas of expertise educational background geographic location and overall experience.

In addition to the cash components of our offers we have generous benefits including top tier medical dental and vision insurance; disability insurance; life insurance; 401(k); flexible PTO policy in addition to paid holidays.

About DFINITY and the Internet Computer:

DFINITYis a leading contributor to the Internet Computer Protocol (ICP) with a mission to bring the worlds compute onto the secure ICP network. Built on its unique thirdgeneration blockchain technology ICP enables the development and operation of a new generation of unstoppable tamperproof fully decentralized web applications. Its powerful technology can run entire AI models within smart contracts representing a major advancement for secure AI. Through seamless integration with Bitcoin Ethereum and other networks ICP facilitates multichain operations for digital assets and web3.

Join our team of over 250 talented individuals including worldrenowned cryptographers distributed systems engineers programming language experts and industry leaders who are shaping the future of the internet and web3.
DFINITY was founded in 2016 by entrepreneur and crypto theoretician Dominic Williams.

All qualified applicants will receive consideration for employment without regard to race color religion gender gender identity or expression sexual orientation national origin genetics disability age or veteran status.

Required Experience:

Senior IC

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.