Назад
Company hidden
15 часов назад

InfoSec - Application & Cloud Security Engineer (L2)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
InfoSec - Application & Cloud Security Engineer (L2) (Application and Cloud Security): Supporting application and cloud security across code reviews, secure SDLC tooling, AWS account security, Kubernetes hardening, and WAF tuning with an accent on findings remediation, threat modeling, and least-privilege controls. Focus on building security automation, reducing false positives, and developing deep expertise toward an L3 specialist role.

Location: Hybrid in Bangalore, India

Company

hirify.global is building infrastructure for cross-border institutional payment systems.

What you will do

  • Perform manual and automated application code reviews and support secure SDLC tooling.
  • Triage, reproduce, and drive remediation of findings from SAST, DAST, SCA, bug bounty, and internal reports.
  • Support threat modeling for new services and features and help engineering teams remediate issues.
  • Review AWS IAM policies, enforce least-privilege controls, and monitor GuardDuty, Security Hub, and Config findings.
  • Harden Kubernetes clusters, including admission control, RBAC, and secrets management, and tune AWS WAF and Cloudflare rules.
  • Run cloud and container vulnerability scans and build security automation with Python, Go, or Bash.

Requirements

  • 2–4 years of hands-on experience in Application Security, Cloud Security, or a closely related role.
  • Knowledge of OWASP Top 10, TLS/PKI, OAuth/JWT, and common cloud attack patterns.
  • Hands-on experience with both application security and cloud security, including at least one of SAST, DAST, or manual review and one major cloud platform.
  • Ability to write useful internal tools and scripts in Python, Go, or Bash.
  • Clear communication skills and the ability to explain security findings in an actionable way.
  • Willingness to participate in the InfoSec on-call rotation and develop toward an L3 specialization.

Nice to have

  • Degree or equivalent experience in Computer Science, Information Security, or a related field.
  • Production Kubernetes exposure and familiarity with Terraform and security enforcement in IaC.
  • Bug bounty, CTF, or open-source security contributions.
  • AWS Security Specialty, OSCP, CKS, or CEH certification.

Culture & Benefits

  • Competitive salary and benefits package.
  • Equity in a rapidly growing fintech startup.
  • Defined growth path toward an L3 security specialist role.
  • Collaborative environment focused on personal and professional growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →