Назад
Company hidden
3 дня назад

Security Tooling Engineer II (Cloud Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Tooling Engineer II (Cloud Security): Building and operating cloud-native security tooling for monitoring, vulnerability scanning, data loss prevention, and infrastructure hardening with an accent on Terraform, policy-as-code, and multi-cloud security. Focus on automating misconfiguration detection and remediation, implementing OVAL and Rego compliance checks, and producing evidence for regulatory audits.

Location: Warsaw, Poland; hybrid work with a minimum of 3 days per week in the assigned office. Occasional shifted hours may be required for cross-time-zone projects, along with participation in an on-call rotation.

Company

hirify.global provides an intelligent content management platform that helps organizations collaborate, secure content, manage content lifecycles, and transform workflows with enterprise AI.

What you will do

  • Deploy and maintain cloud-native security tooling across a multi-cloud environment.
  • Manage infrastructure and policies with Terraform and Terragrunt, including configuration-as-code changes, peer reviews, and automated testing.
  • Implement OVAL- and Rego-based cloud security configuration checks and support DLP policy workflows.
  • Build monitoring, metrics, alerting, detection, and remediation automation for infrastructure and runtime misconfigurations.
  • Patch and upgrade tooling, support targeted detections and ad-hoc scans, and participate in on-call response.
  • Collaborate with engineering, Legal, Privacy, Compliance, and global security teams while documenting standards and playbooks.

Requirements

  • BA or BS in Computer Science or a related field.
  • At least 2 years of experience with cloud-native security tooling and infrastructure-as-code in a cloud environment.
  • Working knowledge of configuration-as-code, policy-as-code, CI/CD, version control, reviews, and automated testing.
  • Familiarity with OVAL, Rego, REST APIs, and at least one of Python, Java, Go, or Node.js.
  • Awareness of FedRAMP, SOC 2, PCI, and HIPAA, with strong debugging, testing, communication, and collaboration skills.
  • Strong English communication skills and flexibility for hybrid work, on-call duties, and occasional shifted hours are required.

Nice to have

  • Experience with DLP policy authoring using JSON/YAML, RE2 regex, dictionaries, and context rules.
  • Experience with classification, tagging, and policy enforcement to prevent sensitive data exfiltration.
  • Experience with FedRAMP, SOC 2, PCI, or HIPAA compliance frameworks.

Culture & Benefits

  • In-person collaboration and community are core parts of the working culture.
  • Work is performed in a hybrid model from the assigned Warsaw office at least 3 days per week.
  • Collaboration takes place across global teams and includes representing hirify.global Poland internally and externally.
  • Support is provided for professional growth, knowledge sharing, and responsible AI adoption.

Hiring process

  • The recruiter provides additional details about the working model and company culture during the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →