Security Engineer, Application
Firmus Technologies4 hours ago
Sydney, AustraliaSenior
Responsibilities
- Own application security for Firmus AI Cloud and internal software, including public APIs, backend services, tenant isolation, and AI assistants and agents.
- Own production CI/CD security gates for SAST, DAST, SCA, secrets detection, and SBOM generation.
- Build automation for finding triage, dependency uplift, evidence collection, threat modeling, and regression testing.
- Develop reusable security libraries, service templates, and developer tooling, and write or review security-critical production code.
- Define standards and controls for authentication, service authorization, tenant isolation, secret handling, logging, AI-agent integrations, and tool access.
- Lead threat modeling, secure design reviews, vulnerability prioritization, remediation, and application security posture management.
- Extend SOC 2 Type 2 and ISO 27001 controls into software delivery and provide application-security expertise during incidents.
- Coach security champions, advise engineering leadership on application risk and release readiness, and join customer conversations when needed.
Requirements
- Bachelor's degree in computer science or a related technical field.
- 7+ years in application security, product security, or software engineering with a security focus.
- Experience securing a public cloud or multi-tenant platform with a public API.
- Deep practical knowledge of the OWASP Top 10 and OWASP API Security Top 10, including threat modeling REST and gRPC multi-tenant APIs using STRIDE or an equivalent method.
- Experience improving the security posture of software built by other engineering teams through standards, tooling, reviews, or secure-by-default patterns.
- Production experience owning and tuning CI/CD security gates including SAST, DAST, SCA, secrets detection, and SBOM generation.
- Production-quality coding experience in at least one of Python, Go, or TypeScript.
- Experience replacing manual security work with automation.
- Hands-on experience securing LLM-backed or agentic features, including prompt injection, tool misuse, agent identity, delegated credentials, cross-tenant data leakage, and generated code controls.
- Deep practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and software secrets.
- Experience working under SOC 2 Type 2 or ISO 27001 and producing evidence that controls ran.
- Willingness to participate in application and API security incident response and travel overseas occasionally.
- Clear and effective written and verbal communication in English.
- Bonus qualifications include securing AI agents or sandboxed code execution, running a vulnerability disclosure program, and holding application-security certifications such as CSSLP or OSWE.
Benefits
- Role is based in Singapore or Australia.
- Occasional overseas travel may be required.
Tech Stack
Categories
About Firmus Technologies
Firmus Technologies builds energy‑efficient AI infrastructure, developing liquid‑cooled “AI Factory” data centers and operating a large‑scale GPU cloud for model training. The company sells capacity and services to developers, enterprises, education, and government customers, with a focus on energy and cost efficiency across Asia‑Pacific. Founded in 2019 in Australia, Firmus is privately held and headquartered in St Leonards, Tasmania.