Назад
Company hidden
4 дня назад

Infrastructure Security Engineer

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland/Spain/Ireland +4 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Infrastructure Security Engineer (Cloud Security/Kubernetes): Building vulnerability-management, detection, and cloud-security capabilities for a travel platform with an accent on infrastructure risk prioritization, security logging, and incident response. Focus on automating security workflows, hardening AWS and Kubernetes environments, supporting SOC 2 and PCI DSS controls, and securing internal AI tooling and agentic workflows.

Location: Remote in Bulgaria, Ireland, Italy, Lithuania, Poland, Portugal, or Spain

Company

hirify.global builds a SaaS platform that helps travel organizers create trip proposals, process payments, and manage customers.

What you will do

  • Own infrastructure vulnerability management across dependencies, containers, images, and cloud infrastructure.
  • Prioritize remediation using KEV, EPSS, exposure, asset criticality, and compensating controls.
  • Automate scanner integrations, finding pipelines, normalization, ticket routing, and reporting.
  • Build security logging and detection coverage across production, cloud, and identity systems, including coordination with a managed detection and response provider.
  • Lead AWS and Kubernetes security posture management, including guardrails, hardening baselines, CSPM triage, and internet-facing asset inventory.
  • Coordinate incident response, security evidence for SOC 2 and PCI DSS, and security controls for internal AI tooling and agentic workflows.

Requirements

  • 8+ years of security engineering experience, with depth in vulnerability management, cloud security posture, detection, or incident response.
  • Experience with AWS, Kubernetes, and infrastructure as code.
  • Expertise with security logging, SIEM-class tooling, and managed detection providers.
  • Hands-on experience managing vulnerabilities across fleets, images, containers, and dependencies at scale.
  • Experience with SOC 2 and/or PCI DSS technical controls.
  • Must be based in Bulgaria, Ireland, Italy, Lithuania, Poland, Portugal, or Spain.

Nice to have

  • Experience securing payment or regulated fintech systems.
  • Detection engineering, threat modeling, or DFIR experience.
  • Exposure to GDPR incident obligations, the Cyber Resilience Act, or ISO 27001.
  • Experience in a product company scaling from mid-market to enterprise customers.

Culture & Benefits

  • Competitive salary and unlimited paid time off through the Time to Recharge policy.
  • Eligible employees can work temporarily from another approved location for up to four weeks per calendar year.
  • Two-week cross-functional onboarding program and annual team off-site.
  • Paid family leave, three paid volunteer days per year, and commuting support.
  • Latest equipment and tools within an international, travel-focused team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →