13 дней назад
Senior Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Cloud Security/DevSecOps): Strengthening the security posture of an open-source and SaaS orchestration platform through penetration testing, vulnerability management, infrastructure hardening, and incident response with an accent on cloud environments, Kubernetes, and software supply-chain security. Focus on discovering and remediating application and API vulnerabilities, automating SAST/DAST and dependency scanning in CI/CD, and securing GCP infrastructure and open-source integrations.
Location: Work from anywhere; fully remote
Company
develops an open-source, declarative orchestration platform for data pipelines, IT automation, business workflows, and AI/agentic systems.
What you will do
- Conduct hands-on penetration testing and threat modeling across web applications, APIs, control planes, and cloud environments.
- Track vulnerabilities across codebases, dependencies, container images, and cloud infrastructure.
- Write patches, submit pull requests, and guide product teams through remediation.
- Audit and harden GCP infrastructure, Kubernetes clusters, and networking configurations.
- Automate SAST, DAST, and dependency scanning in CI/CD pipelines.
- Perform security code reviews, manage supply-chain risks, and lead incident response and continuous monitoring.
Requirements
- 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined offensive and defensive security role.
- Strong hands-on penetration testing experience across application, API, and network security.
- Ability to read code, understand exploits, write fixes, and provide clear remediation guidance.
- Deep familiarity with cloud security, AWS or GCP, Kubernetes, and Docker.
- Experience with dependency and software supply-chain security, CVE management, open-source licensing, and SCA tools.
- Fluent English and ability to work autonomously in a fully remote environment.
Nice to have
- Experience with Trivy, GitHub Security, Dependabot, Elastic Security, Terraform, Java, TypeScript, JavaScript, PostgreSQL, Elasticsearch, Redis, Kafka, AMQP, ELK, Prometheus, Grafana, GitHub Actions, or ArgoCD.
Culture & Benefits
- Remote-first work with the ability to work from anywhere.
- Access to coworking spaces worldwide.
- Medical, dental, and vision coverage.
- Home office equipment provided.
- Fast-paced open-source startup environment focused on pragmatism and execution speed.
Hiring process
- Two-hour asynchronous technical scenario and practical assessment focused on threat assessment and remediation.
- Introductory call with the hiring manager and team discussion with a future colleague.
- Final discussion with a co-founder; the process is intended to take 2–3 weeks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Platform Security Engineer / DevSecOps
ДОМ.РФ
2 дня назад
DevSecOps в команду безопасной разработки систем (Kubernetes)
Karta.io
3 часа назад
Lead Platform Engineer (DevSecOps)
13 дней назад
Senior DevSecOps Engineer (Infrastructure & Cloud Security)
13 дней назад
DevOps Security Engineer
3 дня назад
Lead/Senior Security Engineer (Incident Response)
136 500 - 214 500$