arrow_back खोज पर वापस
S

Security Engineer, Application

Security Engineer, Application - Greenhouse

साझा करें:
placeSydney, Australia home_workऑन-साइट labelPlatform Engineering publicएकत्रित नौकरी · DE

event13 सित॰ 2026 को प्रकाशित · verifiedहमने पुष्टि की जब नौकरी एकत्रित की गई थी

क्या यह आपका व्यवसाय है?

नौकरी के बारे में

Firmus Technologies Firmus Technologies is a global

leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.

Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining

cutting-edge

technology with a steadfast commitment to sustainability.

At Firmus, we are unique in our approach. We design, build, and

operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.

Firmus AI Cloud Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI

compute

at scale to customers.

It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.

ROLE SUMMARY

Firmus Technologies is seeking a Senior Security Engineer, Application for our Engineering and Technology team. You own application security for Firmus AI Cloud and the internal software that runs it. Automation is how you scale that ownership.

Customers provision GPU compute through

API and console,

software engineers

build against it, and our operators run the platform through the same control plane. You own the security of that software: the public APIs, the services behind them, how tenants stay separated inside the application, and the

AI

assistants and agents we ship on top.

KEY

RESPONSIBILITIES

Automation and secure delivery

Own the CI/CD security gates that every production repository passes through: SAST, DAST, SCA, secrets detection, and SBOM generation.

Build the systems that do the repeatable work: finding triage, dependency uplift, evidence collection, and draft threat models.

Ship the

secure

paved roads other teams build on: reusable libraries, service templates, and developer tooling.

Write and review code in the services you protect, including the security-critical paths that tools miss.

Security architecture and standards

Set the application security standard

and control

for authentication, authorisation between services, tenant isolation at the application boundary, secret

handling

and logging.

Lead threat modelling and secure design review. Define what an attacker can do and what

must

be true before it ships.

Set the security requirements for the AI assistants and agents we ship e.g. prompt injection, context poisoning.

Govern which tools and tool servers our

AI

agents and

software engineers

may reach, and how those integrations are scoped, allow-listed, and audited.

Assurance and vulnerability management

Own application security posture across our services: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue.

Prioritise fixes on exploitability and exposure alongside CVSS and hold them to the Firmus vulnerability SLAs.

Drive remediation with the teams that own the code so issues close at the source.

Extend SOC 2 Type 2 and ISO 27001 into the software delivery path as services and sites grow. Evidence that a control ran should be a query, not a spreadsheet exercise.

Enablement and escalation

Coach security champions inside each team so secure design decisions get made without waiting for you.

Provide application-security

expertise

during incidents and convert recurring failure modes into gates, tests, standards, or developer tooling.

Give engineering leadership a straight read on application risk and release readiness. Join customer conversations when the question is application security.

SKILLS AND EXPERIENCE

Bachelor's degree in computer science or a related technical field.

7+ years in application security, product security, or software engineering with a security focus.

Experience securing a public cloud or multi-tenant platform with a public API.

Deep, practical knowledge of the OWASP Top 10 and the OWASP API Security Top 10. Has threat modelled multi-tenant APIs in production: identity, authorisation between services, tenant isolation, and the ways a client abuses a published contract

using

STRIDE or an equivalent method, both for

REST and

gRPC.

Has improved the security posture of software built by other engineering teams through standards, tooling, review, or secure-by-default patterns.

Has

owned CI/CD security gates in production (SAST, DAST, SCA, secrets detection, SBOM) and

tuned them to deliver actionable findings with low false-positive rates that engineers trusted and acted upon.

Writes production-quality code in at least one of Python, Go, or TypeScript.

Has replaced manual security work with automation: finding triage, dependency uplift, evidence collection, or regression tests that run without someone watching them.

Hands-on with LLM-backed or agentic features: prompt injection, tool misuse, agent identity and delegated credentials, cross-tenant data leakage, and controls on generated code reaching production. Familiar with OWASP guidance for LLM and agentic applications.

Deep practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and secrets in software.

Has worked under SOC 2 Type 2 or ISO 27001 and

मुफ़्त में पढ़ना जारी रखें

पूरी नौकरी देखने और आवेदन करने के लिए एक मुफ़्त खाता बनाएं।

  • badgeपोर्टफोलियो कंपनियों को दिखाई देता है
  • notificationsईमेल द्वारा नया जॉब अलर्ट
  • favoriteहमेशा मुफ़्त, कोई शर्त नहीं