TL;DR
Cloud Security Engineer (Fintech): Building and scaling the information security function for a cloud-native fintech platform with an accent on cloud security, DevSecOps integration, and vulnerability management. Focus on hardening AWS infrastructure, automating security controls, and driving secure development practices in a high-compliance payment environment.
Company
hirify.global is an AI-powered payment technology provider and licensed financial institution serving PSPs and neobanks globally.
What you will do
- Harden and maintain security across multi-account AWS environments including IAM, VPC, and EKS.
- Integrate SAST, DAST, and SCA scanning tools into CI/CD pipelines.
- Manage the vulnerability lifecycle, including scanning, triage, and remediation tracking.
- Implement and maintain cloud security posture monitoring and log aggregation.
- Own secrets management and kubernetes RBAC configurations.
- Participate in threat modeling and incident response activities.
Requirements
- 3-5 years of experience in security engineering, DevSecOps, or infrastructure security.
- Strong hands-on experience with AWS services (IAM, VPC, EKS, GuardDuty).
- Proficiency in Infrastructure as Code (Terraform) and ability to automate tasks with Python/Bash.
- Deep understanding of Kubernetes security including RBAC and network policies.
- Fluent in both Russian and English languages.
- Practical knowledge of OWASP Top 10 and vulnerability management lifecycles.
Nice to have
- Experience with PCI DSS compliance in a fintech environment.
- Familiarity with network reconnaissance tools like Shodan or Nmap.
- Experience with FortiGate/Fortinet security products.
- Prior experience building security processes from scratch.
Culture & Benefits
- High autonomy working directly with the CISO to shape security architecture.
- Opportunity to influence engineering culture and tooling strategy.
- Collaborative, horizontal team structure.
- Continuous learning and professional development support.
- Flexible work arrangements to support work-life balance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →