Назад
Company hidden
11 часов назад

Senior Infrastructure Security Engineer (GCP/Kubernetes)

Формат работы
remote (только Europe)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Ukraine/Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Infrastructure Security Engineer (GCP/Kubernetes): Securing production infrastructure across GCP, Kubernetes, and bare-metal environments with an accent on cloud posture hardening, vulnerability remediation, and compliance controls. Focus on building agentic AI security automation, embedding controls into CI/CD and Infrastructure-as-Code, and containing infrastructure security incidents.

Location: Ukraine or Europe; hybrid work model with the option to work remotely or from the Kyiv hub.

Company

hirify.global builds software products and cybersecurity tools, including CleanMyMac, Setapp, ClearVPN, and Moonlock.

What you will do

  • Participate in adopting the Wiz CNAPP service.
  • Harden Kubernetes and GCP cloud security posture, including RBAC, admission control, network policies, and runtime threat detection.
  • Own the infrastructure vulnerability backlog and drive remediation according to severity-based SLAs with the SRE team.
  • Build and ship agentic AI security automation in code-reviewed repositories.
  • Embed security controls into CI/CD pipelines and Infrastructure-as-Code in collaboration with SRE.
  • Define, test, and coordinate security frameworks across bare-metal and GCP environments.

Requirements

  • Strong Infrastructure-as-Code and automation experience with Terraform.
  • Python or Go skills for building security tooling.
  • Production cloud security experience at scale on GCP, including least-privilege IAM, network segmentation, runtime detection, and posture hardening.
  • Production Kubernetes security experience with RBAC, OPA or Kyverno admission control, network policies, runtime detection, and image provenance.
  • Experience securing bare-metal and self-hosted Linux infrastructure, managing vulnerabilities, and handling infrastructure security incidents.
  • Upper-Intermediate English and fluent Ukrainian are required.

Nice to have

  • Experience securing agentic AI systems, including prompt injection, MCP tool poisoning, approval flows, and kill switches.
  • Experience with CNAPP or CSPM platforms such as Wiz, Sysdig, Orca, or Prisma Cloud.
  • Experience with NixOS, Cloudflare edge security controls, or ISO 27001 and SOC 2 Type II environments.
  • Security certifications such as CKS, OSCP, or GCP Professional Cloud Security.

Culture & Benefits

  • Remote or Kyiv hub work with flexible working hours.
  • Medical insurance from the first month; employees abroad may receive an annual medical insurance allowance.
  • Education opportunities, development reviews, and internal communities.
  • Personal time off, parental leave, and sabbaticals after five years.
  • Support programs for veterans, active military personnel, mobilized employees, and colleagues affected by the war.
  • Access to a Kyiv coworking office with UPS, Starlink, gym, kitchens, and recreation areas.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →