Назад
Company hidden
7 дней назад

Senior Security Engineer (Cloud Security)

Формат работы
remote (только Malta)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Malta
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Cloud Security): Building and operating security controls across cloud infrastructure, applications, CI/CD pipelines, corporate systems, and incident response with an accent on AWS, Cloudflare, IAM, vulnerability management, and secure SDLC practices. Focus on designing and implementing controls hands-on, automating detection and response, testing real attack paths, and applying AI to security engineering and operations.

Location: Remote, with the role associated with St. Julian's, Malta

Company

hirify.global is an iGaming technology scale-up providing a complete gaming platform for rapid deployment and operational success.

What you will do

  • Architect and implement security controls across cloud infrastructure, applications, CI/CD pipelines, and the corporate environment.
  • Coach developers, engineers, and architects on secure design, threat modelling, cloud security, and secure development practices.
  • Own vulnerability management and attack surface management, prioritising exploitable risks and driving remediation to completion.
  • Build and tune SAST, DAST, and SCA controls, cloud security automation, IAM with least-privilege access, and compliance checks.
  • Own detection and response, including logging, alerting, investigation, remediation, and post-incident reviews.
  • Use offensive techniques and AI-enabled tooling for security testing, triage, code review, detection engineering, evidence collection, and automation.

Requirements

  • 5+ years of hands-on technical security engineering experience with accountability for delivering fixes.
  • Deep AWS security experience, including IAM, Organizations, SCPs, Security Hub, GuardDuty, WAF, and Cloudflare.
  • Production programming experience with Python, Go, or Bash; TypeScript is a plus.
  • Experience with Infrastructure as Code, vulnerability and attack surface management, SIEM, detection engineering, and incident response.
  • Working knowledge of offensive security, SDLC security, and integrating and tuning SAST, DAST, and SCA.
  • Practical current use of AI in security work and the ability to assess AI-driven threats, validate outputs, and secure AI systems.

Nice to have

  • PCI DSS engineering, SIEM ownership, serverless or event-driven architecture, or corporate IT security experience.
  • Experience in iGaming, fintech, or another regulated, high-value-target industry.
  • Experience securing AI or agentic systems and applying security frameworks such as NIST CSF, CIS Benchmarks, or CSA CCM.
  • Public security artifacts, certifications such as CISSP, AWS Certified Security, or CEH.

Culture & Benefits

  • Flexible remote, office-based, or mixed working models.
  • Collaborative environment combining autonomy, open technical review, transparency, and accountability.
  • Work equipment of choice and private health insurance.
  • Learning budget and company-wide and team-based get-togethers.
  • Small, focused security team with significant architectural ownership and hands-on delivery.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →