8 дней назад
Infrastructure Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Infrastructure Security Engineer (Cloud Security/AI): Building vulnerability management, detection, cloud security posture, and incident response capabilities for a travel technology platform with an accent on AWS, Kubernetes, security logging, and risk-based remediation. Focus on automating security finding workflows, securing internal AI agents and tooling, and producing technical evidence for SOC 2 and PCI DSS controls.
Location: Amsterdam, hybrid
Company
builds a travel technology platform that helps tour organizers create trip proposals, process payments, and manage travelers and travel businesses.
What you will do
- Own infrastructure vulnerability management across dependencies, containers, images, and cloud infrastructure.
- Prioritize remediation using KEV, EPSS, exposure, asset criticality, and compensating controls.
- Automate scanner integrations, finding pipelines, normalization, ticket routing, and security reporting.
- Build security logging and detection coverage across production, cloud, and identity systems, including coordination with a managed detection and response provider.
- Lead cloud and infrastructure security posture management across AWS and Kubernetes, including guardrails, hardening, CSPM triage, and internet-facing asset inventory.
- Coordinate incident response, tabletop exercises, corrective actions, and technical evidence for SOC 2, PCI DSS, and customer security reviews.
Requirements
- 8+ years of security engineering experience with substantial depth in vulnerability management, cloud security posture, detection, or incident response.
- Experience with AWS, Kubernetes, and infrastructure as code.
- Expertise with security logging and SIEM-class tooling and experience working with a managed detection provider.
- Hands-on experience managing infrastructure vulnerabilities at scale across fleets, images, containers, and dependencies.
- Experience with SOC 2 and/or PCI DSS technical controls.
Nice to have
- Experience securing payments or regulated fintech systems.
- Detection engineering, threat modeling, or DFIR experience.
- Exposure to GDPR Articles 33/34, the Cyber Resilience Act, or ISO 27001.
- Experience scaling a product company from mid-market to enterprise customers.
Culture & Benefits
- Hybrid work in Amsterdam with an eligible Work From Anywhere perk of up to four weeks per calendar year from another approved location.
- Competitive salary, unlimited paid time off through the Time to Recharge policy, and extensive paid family leave.
- Two-week cross-functional onboarding program and annual team off-site.
- Cycle-to-work scheme or commuting reimbursement, team lunches, and after-work social events.
- Three paid volunteer days per year plus modern equipment and tools.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →