Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
We are looking for a seasoned Security Engineer to own and elevate the security posture of our platform end to end — from the Cloudflare edge and AWS infrastructure down to the API layer, frontend, and backend application code. This is a high-impact, high-ownership role embedded within engineering. You will work closely with product, DevOps, and development teams to identify threats before they become incidents, respond decisively when they do, and build the systems, policies, and culture that keep our users and platform safe.
задачи
Own and drive the end-to-end security posture of web, API, and infrastructure surfaces
Identify, assess, and remediate vulnerabilities across frontend, backend services, and cloud infrastructure
Design and enforce security controls at the Cloudflare edge, including WAF policies, bot mitigation rules, Turnstile integrations, and rate-limiting strategies
Harden AWS environments in line with least-privilege and zero-trust principles
Lead threat-modelling sessions for new product features and identify security gaps before production
Monitor, investigate, and respond to security incidents, including Cloudflare firewall events, WAF alerts, and SIEM-detected anomalies
Conduct penetration testing and vulnerability assessments; prioritize findings by business impact
Define and enforce HTTP security header policies across all domains
Build and maintain a DDoS response playbook; lead mitigation during volumetric and application-layer attacks
Partner with engineering teams to embed secure coding practices and participate in security-sensitive code reviews
Manage the responsible disclosure and bug bounty programme; triage external researcher reports
Produce security reports, risk registers, and executive briefings; track remediation SLAs
Monitor emerging attack vectors, CVEs, and threat landscape changes relevant to online gaming and fintech platforms
требования
10+ Years of hands-on experience in application, infrastructure, and web security
Deep expertise in OWASP Top 10 vulnerabilities, including SQLi, XSS, CSRF, IDOR, RCE, SSRF, and clickjacking
Proven experience detecting, mitigating, and analyzing DDoS attacks
Strong command of Cloudflare WAF rules, Bot Management, Turnstile, Rate Limiting, Transform Rules, and Firewall Events analysis
Hands-on AWS security experience with IAM policies, Security Groups, VPC design, API Gateway throttling, WAFv2, Shield, GuardDuty, and CloudTrail
Deep understanding of API security, including OAuth2, JWT, OTP abuse, rate limiting, and endpoint hardening
Experience securing frontend applications against XSS, CSP bypass, clickjacking, and third-party script risks
Backend security expertise in input validation, secure coding, secrets management, and SQL injection prevention
Proficiency with Burp Suite, OWASP ZAP, Nmap, Metasploit, and Nikto
Experience conducting and managing vulnerability assessments, threat modelling, and security audits
Solid understanding of TLS/SSL, HTTP security headers, and certificate management
Experience with SIEM platforms, log aggregation, alert tuning, and incident response
Knowledge of bot mitigation strategies, including JA3/JA4 fingerprinting, bot scoring, and heuristic versus ML detection
Familiarity with ISO 27001, SOC 2, PCI-DSS, or GDPR
Strong written and verbal communication skills; able to produce security reports and brief non-technical stakeholders
Hands-on experience integrating SAST, DAST, SCA, and secrets scanning into CI/CD pipelines as automated gates
Будет плюсом: Cloudflare Zero Trust, Access, and Tunnel; threat intelligence platforms (VirusTotal, Shodan, AlienVault OTX); bug bounty experience or CVE disclosures; Python, Bash, or Go scripting; securing Electron desktop applications and mobile API surfaces; blockchain/crypto platform security; Docker and Kubernetes RBAC, image scanning tools (Trivy, Snyk); OSCP, CEH, CISSP, AWS Security Specialty, or equivalent certifications; chaos engineering or red team/blue team exercises; gaming or fintech regulatory environments