Назад
Company hidden
11 дней назад

Security Engineer (AWS)

Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AWS) (Cloud Security): Protecting a PCI DSS-certified hospitality platform through vulnerability remediation, SIEM detection engineering, and hands-on incident response with an accent on AWS security, application security, and secure delivery pipelines. Focus on hardening multi-account cloud infrastructure, investigating and containing incidents, building automated remediation workflows, and producing evidence for PCI DSS, GDPR, and SOC 2 obligations.

Location: Remote - Canada

Company

hirify.global provides a unified hospitality platform used by properties in 150 countries, integrating hotel operations and commercial tools with hundreds of partners.

What you will do

  • Find and remediate vulnerabilities across application repositories, Terraform, dependencies, secrets, containers, and delivery pipelines.
  • Build and tune detections in Datadog Cloud SIEM, reduce false positives, and map detection coverage to MITRE ATT&CK.
  • Investigate, contain, and document cloud security incidents, including root-cause analysis and remediation tracking.
  • Harden AWS environments using IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, VPC controls, and comprehensive logging.
  • Secure CI/CD and Kubernetes environments with GitHub Advanced Security, code scanning, Dependabot, secret scanning, CrowdStrike scanning, and admission policies.
  • Automate triage, enrichment, remediation, and security documentation through workflows, scripts, runbooks, and standards.

Requirements

  • Bachelor’s degree with 4 years of relevant experience, or at least 6 years of practical experience in security engineering, detection engineering, or incident response.
  • Ability to read unfamiliar application repositories, understand vulnerabilities, write code, and ship fixes through pull requests.
  • Deep AWS security experience covering IAM, least privilege, GuardDuty, CloudTrail, KMS, VPC controls, containers, and serverless workloads.
  • Hands-on SIEM detection engineering and cloud incident response experience, including investigation, containment, evidence handling, and post-incident documentation.
  • Knowledge of OWASP Top 10, dependency and secrets risks, SAST, DAST, SCA, IaC scanning, and CI/CD security integration.
  • Strong written communication in English is required.

Nice to have

  • Production experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security.
  • Experience supporting PCI DSS Level 1 or SOC 2 audits as an engineer.
  • Kubernetes and ArgoCD security experience, or automation and policy-as-code using Python and Terraform.

Culture & Benefits

  • Remote-first, remote-always work environment with a globally distributed security team.
  • PTO in accordance with local labor requirements and monthly Wellness Fridays.
  • Fully paid parental leave and a home office stipend based on country of residency.
  • Professional development through hirify.global University, manager training, upskilling, and knowledge transfer.
  • Opportunity to work on security for a PCI DSS-certified platform processing bookings across 150 countries.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →