Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой — после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
On-site role in our Almaty office (we will relocate you from anywhere).
Higgsfield AI is a generative AI company developing AI-powered video creation and next-generation creative tools for millions of users and enterprise brands.
задачи
Pentest new web features, APIs, and admin surfaces before release;
Identify the attack surface of each new feature;
Hunt authorization flaws across multi-tenant APIs and retest fixes;
Join design and code reviews early to identify flaws before implementation;
Turn recurring findings into paved-road standards and automated checks;
Provide working reproductions to code owners and follow fixes through.
требования
Proven track record of finding real vulnerabilities in real systems through application security work, bug bounty, or research;
Ability to read modern codebases, trace bugs to root cause, and discuss fixes with engineers;
Threat-modeling instinct for identifying weaknesses in designs and architectures before implementation;
Cloud and container fundamentals sufficient to follow bugs into their infrastructure;
High agency;
Working English;
Nice to have: LLM/agent security research, public research or CVEs, OSWE/CWEE or equivalent hands-on certificates.
условия
Competitive base salary in USD;
Equity through participation in the company’s stock option program;