02 ago
|
Movate
|
Colombia
We empower developers with best-in-class tools to build secure, high-quality software at scale. Our mission is to create a world where software is always secure and developers can innovate without fear. Trusted by thousands of organizations, including Fortune 500 companies, we are pioneers in software supply chain management, open-source security, and DevSecOps.
Role Overview: As an AI Red Team Staff Software Engineer, you will help shape a high-impact security engineering capability at the intersection of frontier AI, offensive application security, and software supply chain defense. You will use advanced AI models, techniques, and security tooling to discover, validate, and help remediate meaningful risks across our products, codebases, infrastructure, and dependencies.
Key Responsibilities
- Risk Identification: Identify and prioritize meaningful security risks across first-party code, services, infrastructure, build pipelines, and software supply chain components.
- Vulnerability Validation: Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
- Cross-Functional Collaboration: Collaborate with Security Research and Product teams to translate novel findings, malicious component discoveries, and emerging attack patterns into research-ready outputs, product improvements, detection opportunities, and customer-facing intelligence.
- Remediation & Mitigation: Work closely with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
- AI-SDLC Evangelism: Champion modern AI-SDLC practices by translating recurring vulnerability classes, insecure coding patterns, and effective remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks.
- Fix Implementation: Create clear remediation guidance,
engineering-ready fix proposals, and pull requests where appropriate.
Minimum Qualifications
- Experience: 8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
- Security Expertise: Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
- Code Proficiency: Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
- Tooling & Methods: Hands-on experience with application security testing methods and tools, such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
- AI & Automation: Practical experience using AI-assisted engineering, security analysis, or automation techniques to improve software quality outcomes.
- Communication: Ability to translate security findings into clear remediation guidance, engineering-ready recommendations, and practical risk-based priorities. Strong collaboration skills working across AppSec, Engineering, Product, or Security Research teams.
- Education: Bachelor’s degree in Computer Science, Engineering, or a related field—or equivalent practical experience.
- DevOps Culture: Solid understanding of cloud-native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices.
- Leadership: Passion for raising the security bar through technical leadership, mentoring, secure engineering practices, and continuous improvement.
- Advanced English (B2+) Desirable Certifications:
- SANS: GSEC, GCIH, GCLD, GCID, GMON Opportunity to directly shape company culture and employee experience. A collaborative and inclusive work environment. Growth opportunities within a dynamic organization.
📌 Senior Full Stack Engineer (Colombia)
🏢 Movate
📍 Colombia