Назад
Company hidden
13 дней назад

Senior Security Engineer

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
c1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Cloud Security/DevSecOps): Strengthening the security posture of an open-source and SaaS orchestration platform through penetration testing, vulnerability management, infrastructure hardening, and incident response with an accent on cloud environments, Kubernetes, and software supply-chain security. Focus on discovering and remediating application and API vulnerabilities, automating SAST/DAST and dependency scanning in CI/CD, and securing GCP infrastructure and open-source integrations.

Location: Work from anywhere; fully remote

Company

hirify.global develops an open-source, declarative orchestration platform for data pipelines, IT automation, business workflows, and AI/agentic systems.

What you will do

  • Conduct hands-on penetration testing and threat modeling across web applications, APIs, control planes, and cloud environments.
  • Track vulnerabilities across codebases, dependencies, container images, and cloud infrastructure.
  • Write patches, submit pull requests, and guide product teams through remediation.
  • Audit and harden GCP infrastructure, Kubernetes clusters, and networking configurations.
  • Automate SAST, DAST, and dependency scanning in CI/CD pipelines.
  • Perform security code reviews, manage supply-chain risks, and lead incident response and continuous monitoring.

Requirements

  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined offensive and defensive security role.
  • Strong hands-on penetration testing experience across application, API, and network security.
  • Ability to read code, understand exploits, write fixes, and provide clear remediation guidance.
  • Deep familiarity with cloud security, AWS or GCP, Kubernetes, and Docker.
  • Experience with dependency and software supply-chain security, CVE management, open-source licensing, and SCA tools.
  • Fluent English and ability to work autonomously in a fully remote environment.

Nice to have

  • Experience with Trivy, GitHub Security, Dependabot, Elastic Security, Terraform, Java, TypeScript, JavaScript, PostgreSQL, Elasticsearch, Redis, Kafka, AMQP, ELK, Prometheus, Grafana, GitHub Actions, or ArgoCD.

Culture & Benefits

  • Remote-first work with the ability to work from anywhere.
  • Access to coworking spaces worldwide.
  • Medical, dental, and vision coverage.
  • Home office equipment provided.
  • Fast-paced open-source startup environment focused on pragmatism and execution speed.

Hiring process

  • Two-hour asynchronous technical scenario and practical assessment focused on threat assessment and remediation.
  • Introductory call with the hiring manager and team discussion with a future colleague.
  • Final discussion with a co-founder; the process is intended to take 2–3 weeks.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →