
Security Engineer
Firmus Technologies
Security Engineer
Firmus Technologies is seeking a Senior Security Engineer, Application to own application security for its AI Cloud platform and internal software. The role involves automating security gates, setting security standards, and driving remediation across services. Requires 7+ years of experience in application security and deep knowledge of OWASP, CI/CD security, and multi-tenant API security.
Security Engineer
Firmus Technologies is seeking a Senior Security Engineer, Application to own application security for its AI Cloud platform and internal software. The role involves automating security gates, setting security standards, and driving remediation across services. Requires 7+ years of experience in application security and deep knowledge of OWASP, CI/CD security, and multi-tenant API security.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Own the CI/CD security gates that every production repository passes through: SAST, DAST, SCA, secrets detection, and SBOM generation.
- Build the systems that do the repeatable work: finding triage, dependency uplift, evidence collection, and draft threat models.
- Ship the secure paved roads other teams build on: reusable libraries, service templates, and developer tooling.
- Write and review code in the services you protect, including the security-critical paths that tools miss.
- Set the application security standard and control for authentication, authorisation between services, tenant isolation at the application boundary, secret handling and logging.
- Lead threat modelling and secure design review.
- Set the security requirements for the AI assistants and agents we ship e.g. prompt injection, context poisoning.
- Govern which tools and tool servers our AI agents and software engineers may reach, and how those integrations are scoped, allow-listed, and audited.
- Own application security posture across our services: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue.
- Prioritise fixes on exploitability and exposure alongside CVSS and hold them to the Firmus vulnerability SLAs.
- Drive remediation with the teams that own the code so issues close at the source.
- Extend SOC 2 Type 2 and ISO 27001 into the software delivery path as services and sites grow.
- Coach security champions inside each team so secure design decisions get made without waiting for you.
- Provide application-security expertise during incidents and convert recurring failure modes into gates, tests, standards, or developer tooling.
- Give engineering leadership a straight read on application risk and release readiness.