11 дней назад
Senior DevSecOps Engineer (Infrastructure & Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior DevSecOps Engineer (Infrastructure & Cloud Security) (AWS/Azure, Terraform, Kubernetes): Designing and operating security architecture, access controls, telemetry, vulnerability management, and API protection across regulated financial-services infrastructure with an accent on cloud security, identity governance, and compliance automation. Focus on securing hybrid multi-cloud environments, building policy-as-code and detection capabilities, and implementing ISO 27001, SOC 2, and DORA controls for crypto-asset infrastructure.
Location: Remote — work from anywhere in the world
Company
operates brokerage and crypto-related financial-services products for clients in different countries.
What you will do
- Define and enforce security architecture across AWS and Azure, including landing zones, network segmentation, encryption, policies, logging, and monitoring.
- Own perimeter and edge security, including WAF, DDoS protection, VPN, zero-trust access, DNS, certificates, and exposure management.
- Run vulnerability management, security reviews, threat modeling, incident response, and remediation tracking with the infrastructure team.
- Design enterprise access controls across AWS IAM, Azure RBAC, Kubernetes, databases, networks, and SaaS, including SSO, phishing-resistant MFA, PAM, and break-glass procedures.
- Build security telemetry, detection, response, and automated evidence collection for SIEM, EDR, cloud, Kubernetes, network, and application environments.
- Own API security and technical controls for ISO 27001, SOC 2, and DORA, including third-party cloud and ICT security reviews.
Requirements
- 6+ years of hands-on infrastructure, cloud, or security engineering experience, including 3+ years with security as the primary responsibility.
- Experience in a regulated financial-services environment such as brokerage, trading, payments, banking, or crypto services.
- Production security experience with complex AWS and Azure estates, including IAM, RBAC, networking, private connectivity, KMS, Key Vault, logging, detection, landing zones, and policy enforcement.
- Deep practical knowledge of Active Directory, Group Policy, Conditional Access, hybrid identity, enterprise IAM, PAM, and access-rights governance.
- Experience with SIEM, EDR, incident response, Terraform or equivalent IaC, CI/CD security gates, Kubernetes and container security, and policy-as-code.
- Confident scripting in Python, Bash, and PowerShell, plus hands-on experience securing crypto-asset infrastructure such as wallets, exchanges, payment rails, HSM, or MPC systems.
Nice to have
- Experience with ISO/IEC 27001:2022 Annex A, SOC 2 Type II, DORA testing programs, and ICT third-party registers.
- Experience with REST, WebSocket, FIX, and streaming market-data API security.
Culture & Benefits
- Official employment from the first day.
- Bonuses and an annual employee review covering salary review or bonus and performance feedback.
- Opportunities to work on multiple projects and products with different technologies.
- Participation in industry conferences, forums, and corporate events.
- Remote work from anywhere in the world.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →