Application Security Engineer
higgsfieldai · Almaty, Kazakhstan
Open. First seen 9 September 2026.
Description
Why work at Higgsfield AI? Higgsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands. We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.
About the role
Break new features before they ship: agentic systems, MCP servers, code-generating agents, user-deployed apps, generative models for image, video, and voice, and enterprise features (SSO, org and team management, roles). It's new ground, and you'll help define how we secure it. You go first.
What you'll do
Pentest new features and products pre-release: web, APIs, admin surfaces. Work out the attack surface of each new feature yourself. Hunt authorization flaws across our multi-tenant APIs and retest fixes. Join design and code reviews early, so flaws die before they're built. Turn recurring findings into guardrails — paved-road standards and automated checks — so a bug class dies once instead of resurfacing every release. Bring a working repro to the team that owns the code and see the fix through.
Requirements
A track record of finding real vulnerabilities in real systems — appsec work, bug bounty, or research. The ability to read modern codebases, trace a bug to root cause, and discuss the fix with the engineers who wrote it. A threat-modeling instinct for spotting the weak spots in a design or architecture before a line is written. Enough cloud and container fundamentals to follow a bug into the infrastructure it runs on. High agency. Working English.
Nice to have
LLM/agent security research, public research or CVEs, OSWE/CWEE or equivalent hands-on certificates.
What we offer
Competitive base salary in USD Equity: participation in the company’s stock option program, giving you the opportunity to share in the company’s long-term growth. On-site role in our Almaty office (we will relocate you from anywhere). WHY WORK AT HIGGSFIELD AI?
Higgsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands. We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.
ABOUT THE ROLE
Break new features before they ship: agentic systems, MCP servers, code-generating agents, user-deployed apps, generative models for image, video, and voice, and enterprise features (SSO, org and team management, roles). It's new ground, and you'll help define how we secure it. You go first.
What you'll do
- Pentest new features and products pre-release: web, APIs, admin surfaces.
- Work out the attack surface of each new feature yourself.
- Hunt authorization flaws across our multi-tenant APIs and retest fixes.
- Join design and code reviews early, so flaws die before they're built.
- Turn recurring findings into guardrails — paved-road standards and automated checks — so a bug class dies once instead of resurfacing every release.
- Bring a working repro to the team that owns the code and see the fix through.
Requirements
- A track record of finding real vulnerabilities in real systems — appsec work, bug bounty, or research.
- The ability to read modern codebases, trace a bug to root cause, and discuss the fix with the engineers who wrote it.
- A threat-modeling instinct for spotting the weak spots in a design or architecture before a line is written.
- Enough cloud and container fundamentals to follow a bug into the infrastructure it runs on.
- High agency.
- Working English.
Nice to have
- LLM/agent security research, public research or CVEs, OSWE/CWEE or equivalent hands-on certificates.
WHAT WE OFFER
- Competitive base salary in USD
- Equity: participation in the company’s stock option program, giving you the opportunity to share in the company’s long-term growth.
- On-site role in our Almaty office (we will relocate you from anywhere).
Salary context
5 other open postings titled Application Security Engineer state a salary: median USD 106,300 to USD 146,000 a year.
Similar jobs
- Application Security Engineer at contentsquare
- Application Security Engineer at Virtru
- Application Security Engineer at Fin
- Application Security Engineer at Fin
- Application Security Engineer at Accenture Federal Services
- Application Security Engineer at lovable
Is this your posting and you want it taken down? Email info@careerholo.com.