Firmus Technologies

Senior Security Engineer, Application

Firmus Technologies

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
7+ yrs
Salary
Openings
1
Posted
2 weeks ago
Work mode
In office
Education
Bachelor's degree in Computer Science or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Firmus Technologies

Established in 2019 in Australia, Firmus Technologies is a global front-runner in developing and managing efficient AI infrastructures throughout the Asia Pacific region. We specialize in creating a new category of digital infrastructure called the AI Factory, which integrates advanced multi-generational liquid cooling, energy management, AI software orchestration, and construction technologies to optimize energy use and cost-effectiveness globally.

Our flagship product, the Firmus AI Cloud, is a large-scale GPU cloud platform designed to offer energy-efficient AI compute capabilities at scale. It supports various clients including developers, businesses, educational institutions, and governments, enabling them to train and deploy AI models while maximizing efficiency and reducing costs.

As a partner with NVIDIA Cloud and Engineering in Asia Pacific, we provide unique opportunities for professional growth in the AI sector. Our organization is founder-led with rapid decision-making processes, minimal bureaucracy, and direct involvement in shaping the company’s growth trajectory across a wide-scale national roadmap. Our AI Factories are designed not just for business success but also to actively support local energy grids, strengthening the communities where we operate.

Role Summary

We are looking for a Senior Security Engineer focused on Application Security to join our Engineering and Technology team. This role entails full ownership of the security posture for Firmus AI Cloud software and related internal applications. You will secure public APIs, internal services, tenant isolation mechanisms, and AI assistant features through automation and hands-on involvement in both architecture and coding.

Key Responsibilities

  • Manage CI/CD pipeline security validations, including static and dynamic analysis (SAST, DAST), software composition analysis (SCA), secrets detection, and software bill of materials (SBOM) generation.
  • Develop automated systems for security tasks such as vulnerability triage, dependency upgrades, evidence gathering, and threat modeling.
  • Create and maintain secure infrastructure components like reusable libraries, service templates, and developer tools to facilitate secure software development.
  • Write and audit secure code paths not covered by automated tools within the services you protect.
  • Define and enforce application security standards for authentication, inter-service authorization, tenant isolation, secret management, and logging practices.
  • Lead threat modeling and security design reviews based on attacker capabilities and risk thresholds before software releases.
  • Specify security controls for AI assistants and agents, tackling issues like prompt injection and context poisoning.
  • Oversee the integration policies for tools and services accessible by AI agents and engineering teams, ensuring appropriate scopes, allow lists, and auditing procedures.
  • Maintain a clear view of the application security status across all services, identifying coverage gaps, ownership of risks, and compliance with internal vulnerability remediation service-level agreements.
  • Coordinate remediation efforts directly with code-owning teams to resolve vulnerabilities as close to the source as possible.
  • Support compliance with SOC 2 Type 2 and ISO 27001 standards within software delivery workflows and automate evidence collection rather than relying on manual methods.
  • Mentor security champions across teams to embed secure design principles independently.
  • Provide expert support during security incidents focused on application risks and convert recurring issues into automated checks and standards.
  • Report application security risk and readiness transparently to engineering leadership and participate in customer discussions concerning application security concerns.

Qualifications and Experience

  • Bachelor’s degree in Computer Science or a related technical discipline.
  • At least seven years of experience in application or product security, or software engineering with a security emphasis.
  • Proven background securing public cloud or multi-tenant platforms with publicly accessible APIs.
  • Comprehensive practical understanding of OWASP Top 10 and API Security Top 10 vulnerabilities and experience applying threat modeling techniques (e.g., STRIDE) on production multi-tenant APIs including REST and gRPC.
  • Track record of enhancing software security through standards creation, tooling improvements, code reviews, and secure-by-default implementations.
  • Experience managing production CI/CD security gates successfully to generate actionable, trusted security results.
  • Proficiency in writing production-level code in at least one language among Python, Go, or TypeScript.
  • Capability in automating security workflows such as triaging findings, upgrading dependencies, collecting evidence, and regression testing without manual intervention.
  • Experience with security challenges related to LLM-backed or agentic applications, including prompt injection, tool misuse, identity delegation, cross-tenant data leakage, and implementing OWASP guidelines for such systems.
  • Deep knowledge of security technologies including OAuth, OpenID Connect (OIDC), JWT, Role- or Attribute-Based Access Control (RBAC or ABAC), application-layer cryptography, token management, and secret handling.
  • Familiarity with compliance frameworks SOC 2 Type 2 and ISO 27001 and ability to produce auditable controls evidence.
  • Preparedness to participate in incident response related to application and API security.
  • Availability for occasional international travel as needed.
  • Excellent written and verbal communication skills in English.

Additional Desirable Skills

  • Hands-on experience securing AI agents, isolated code execution environments, or automated systems triggered by AI-generated outputs.
  • Managed a vulnerability disclosure program.
  • Relevant security certifications such as CSSLP or OSWE focused on application security.

Location and Diversity

This position is available in Singapore or Australia. Firmus is dedicated to fostering a diverse and inclusive working environment and welcomes applicants from all backgrounds who are enthusiastic about advancing sustainable AI infrastructure through innovative engineering.

Join Us!

Contribute to transforming the AI industry by participating in sustainable practices and best-in-class technology at Firmus Technologies. Apply today to impact future AI infrastructure materially.

Minimum education

Bachelor's Degree

How they work

Communication Accountability Digital Literacy
🤖
Online · instant AI help
Broxer