15 часов назад
InfoSec - Application & Cloud Security Engineer (L2)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
InfoSec - Application & Cloud Security Engineer (L2) (Application and Cloud Security): Supporting application and cloud security across code reviews, secure SDLC tooling, AWS account security, Kubernetes hardening, and WAF tuning with an accent on findings remediation, threat modeling, and least-privilege controls. Focus on building security automation, reducing false positives, and developing deep expertise toward an L3 specialist role.
Location: Hybrid in Bangalore, India
Company
is building infrastructure for cross-border institutional payment systems.
What you will do
- Perform manual and automated application code reviews and support secure SDLC tooling.
- Triage, reproduce, and drive remediation of findings from SAST, DAST, SCA, bug bounty, and internal reports.
- Support threat modeling for new services and features and help engineering teams remediate issues.
- Review AWS IAM policies, enforce least-privilege controls, and monitor GuardDuty, Security Hub, and Config findings.
- Harden Kubernetes clusters, including admission control, RBAC, and secrets management, and tune AWS WAF and Cloudflare rules.
- Run cloud and container vulnerability scans and build security automation with Python, Go, or Bash.
Requirements
- 2–4 years of hands-on experience in Application Security, Cloud Security, or a closely related role.
- Knowledge of OWASP Top 10, TLS/PKI, OAuth/JWT, and common cloud attack patterns.
- Hands-on experience with both application security and cloud security, including at least one of SAST, DAST, or manual review and one major cloud platform.
- Ability to write useful internal tools and scripts in Python, Go, or Bash.
- Clear communication skills and the ability to explain security findings in an actionable way.
- Willingness to participate in the InfoSec on-call rotation and develop toward an L3 specialization.
Nice to have
- Degree or equivalent experience in Computer Science, Information Security, or a related field.
- Production Kubernetes exposure and familiarity with Terraform and security enforcement in IaC.
- Bug bounty, CTF, or open-source security contributions.
- AWS Security Specialty, OSCP, CKS, or CEH certification.
Culture & Benefits
- Competitive salary and benefits package.
- Equity in a rapidly growing fintech startup.
- Defined growth path toward an L3 security specialist role.
- Collaborative environment focused on personal and professional growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 минут назад
Security Engineer (Cloud Security)
14 часов назад
Lead Security Engineer (AI/Cloud Security)
191 200 - 286 800$
15 часов назад
AI Security Engineer - Infrastructure Cloud
19 часов назад
Enterprise Software Engineer (AppOps Security Engineer) (Cybersecurity)
13 часов назад
Senior Security Engineer (AI)
10 часов назад