Назад
Company hidden
8 дней назад

Infrastructure Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Infrastructure Security Engineer (Cloud Security/AI): Building vulnerability management, detection, cloud security posture, and incident response capabilities for a travel technology platform with an accent on AWS, Kubernetes, security logging, and risk-based remediation. Focus on automating security finding workflows, securing internal AI agents and tooling, and producing technical evidence for SOC 2 and PCI DSS controls.

Location: Amsterdam, hybrid

Company

hirify.global builds a travel technology platform that helps tour organizers create trip proposals, process payments, and manage travelers and travel businesses.

What you will do

  • Own infrastructure vulnerability management across dependencies, containers, images, and cloud infrastructure.
  • Prioritize remediation using KEV, EPSS, exposure, asset criticality, and compensating controls.
  • Automate scanner integrations, finding pipelines, normalization, ticket routing, and security reporting.
  • Build security logging and detection coverage across production, cloud, and identity systems, including coordination with a managed detection and response provider.
  • Lead cloud and infrastructure security posture management across AWS and Kubernetes, including guardrails, hardening, CSPM triage, and internet-facing asset inventory.
  • Coordinate incident response, tabletop exercises, corrective actions, and technical evidence for SOC 2, PCI DSS, and customer security reviews.

Requirements

  • 8+ years of security engineering experience with substantial depth in vulnerability management, cloud security posture, detection, or incident response.
  • Experience with AWS, Kubernetes, and infrastructure as code.
  • Expertise with security logging and SIEM-class tooling and experience working with a managed detection provider.
  • Hands-on experience managing infrastructure vulnerabilities at scale across fleets, images, containers, and dependencies.
  • Experience with SOC 2 and/or PCI DSS technical controls.

Nice to have

  • Experience securing payments or regulated fintech systems.
  • Detection engineering, threat modeling, or DFIR experience.
  • Exposure to GDPR Articles 33/34, the Cyber Resilience Act, or ISO 27001.
  • Experience scaling a product company from mid-market to enterprise customers.

Culture & Benefits

  • Hybrid work in Amsterdam with an eligible Work From Anywhere perk of up to four weeks per calendar year from another approved location.
  • Competitive salary, unlimited paid time off through the Time to Recharge policy, and extensive paid family leave.
  • Two-week cross-functional onboarding program and annual team off-site.
  • Cycle-to-work scheme or commuting reimbursement, team lunches, and after-work social events.
  • Three paid volunteer days per year plus modern equipment and tools.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →