2 часа назад
Senior Cyber Security Engineer / DevSecOps (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Cyber Security Engineer / DevSecOps (Fintech): Embedding offensive and defensive security engineering into product, infrastructure, and development workflows with an accent on security architecture, penetration testing, threat modeling, and vulnerability management. Focus on designing cloud and infrastructure controls, coordinating incident response, improving security monitoring, and mentoring security team members.
Location: Cairo Office, hybrid
Company
is a fintech product company democratizing access to investing through a mobile investing platform and the Rumble investment recommendations service across the MENA region.
What you will do
- Embed security architecture and practices into product and engineering workflows, including S-SDLC, security acceptance criteria, and threat modeling.
- Perform pre- and post-deployment penetration tests and plan web, mobile, cloud, infrastructure, and red-team security assessments.
- Define, implement, and monitor infrastructure security measures across production and staging environments.
- Conduct vulnerability research, manage vulnerabilities, assess security tools, and contribute to the security roadmap and backlog.
- Improve security logging and monitoring, coordinate company-wide incident response through remediation, and support the bug-bounty program.
- Guide, train, and mentor security and engineering team members on security checks and best practices.
Requirements
- Bachelor's degree in Computer Science, Software Engineering, or a related field, or equivalent work experience.
- At least 5 years of application and/or infrastructure penetration testing experience beyond running automated tools.
- Strong experience with security code reviews and a solid understanding of software development, testing methodologies, version control, networks, and network security.
- Knowledge of cloud platforms such as AWS, Azure, or GCP, plus Docker and Kubernetes containerization technologies.
- Hands-on experience implementing security policies and managing SIEM solutions; knowledge of EDR, IDS, CSPM, and CWPP.
- Strong communication skills for explaining technical concepts to technical and non-technical stakeholders.
Nice to have
- Python experience.
- Experience with serverless or Lambda technologies.
- Fortinet experience.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →