3 дня назад
Security Tooling Engineer II (Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Tooling Engineer II (Cloud Security): Building and operating cloud-native security tooling for monitoring, vulnerability scanning, data loss prevention, and infrastructure hardening with an accent on Terraform, policy-as-code, and multi-cloud security. Focus on automating misconfiguration detection and remediation, implementing OVAL and Rego compliance checks, and producing evidence for regulatory audits.
Location: Warsaw, Poland; hybrid work with a minimum of 3 days per week in the assigned office. Occasional shifted hours may be required for cross-time-zone projects, along with participation in an on-call rotation.
Company
provides an intelligent content management platform that helps organizations collaborate, secure content, manage content lifecycles, and transform workflows with enterprise AI.
What you will do
- Deploy and maintain cloud-native security tooling across a multi-cloud environment.
- Manage infrastructure and policies with Terraform and Terragrunt, including configuration-as-code changes, peer reviews, and automated testing.
- Implement OVAL- and Rego-based cloud security configuration checks and support DLP policy workflows.
- Build monitoring, metrics, alerting, detection, and remediation automation for infrastructure and runtime misconfigurations.
- Patch and upgrade tooling, support targeted detections and ad-hoc scans, and participate in on-call response.
- Collaborate with engineering, Legal, Privacy, Compliance, and global security teams while documenting standards and playbooks.
Requirements
- BA or BS in Computer Science or a related field.
- At least 2 years of experience with cloud-native security tooling and infrastructure-as-code in a cloud environment.
- Working knowledge of configuration-as-code, policy-as-code, CI/CD, version control, reviews, and automated testing.
- Familiarity with OVAL, Rego, REST APIs, and at least one of Python, Java, Go, or Node.js.
- Awareness of FedRAMP, SOC 2, PCI, and HIPAA, with strong debugging, testing, communication, and collaboration skills.
- Strong English communication skills and flexibility for hybrid work, on-call duties, and occasional shifted hours are required.
Nice to have
- Experience with DLP policy authoring using JSON/YAML, RE2 regex, dictionaries, and context rules.
- Experience with classification, tagging, and policy enforcement to prevent sensitive data exfiltration.
- Experience with FedRAMP, SOC 2, PCI, or HIPAA compliance frameworks.
Culture & Benefits
- In-person collaboration and community are core parts of the working culture.
- Work is performed in a hybrid model from the assigned Warsaw office at least 3 days per week.
- Collaboration takes place across global teams and includes representing Poland internally and externally.
- Support is provided for professional growth, knowledge sharing, and responsible AI adoption.
Hiring process
- The recruiter provides additional details about the working model and company culture during the hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Asana
3 дня назад
Staff Detection Engineer (Cybersecurity)
40 000 - 45 000PLN
3 дня назад
Information Security Engineer (Microsoft Cloud)
4 дня назад
DevSecOps Architect (Cybersecurity)
6 дней назад
AI Agents Developer (ADX Security)
1 400 - 1 800PLN
8 дней назад
Technical Program Manager (Application Security)
9 дней назад