28 сен

application & infrastructure security engineer

ориентир по рынку
вакансия зп не указана
в среднем 323 895 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

Рекламный баннер: ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
ИНН: 9704271170

описание

We are looking for a seasoned Security Engineer to own and elevate the security posture of our platform end to end — from the Cloudflare edge and AWS infrastructure down to the API layer, frontend, and backend application code. This is a high-impact, high-ownership role embedded within engineering. You will work closely with product, DevOps, and development teams to identify threats before they become incidents, respond decisively when they do, and build the systems, policies, and culture that keep our users and platform safe.

задачи

  • Own and drive the end-to-end security posture of web, API, and infrastructure surfaces
  • Identify, assess, and remediate vulnerabilities across frontend, backend services, and cloud infrastructure
  • Design and enforce security controls at the Cloudflare edge, including WAF policies, bot mitigation rules, Turnstile integrations, and rate-limiting strategies
  • Harden AWS environments in line with least-privilege and zero-trust principles
  • Lead threat-modelling sessions for new product features and identify security gaps before production
  • Monitor, investigate, and respond to security incidents, including Cloudflare firewall events, WAF alerts, and SIEM-detected anomalies
  • Conduct penetration testing and vulnerability assessments; prioritize findings by business impact
  • Define and enforce HTTP security header policies across all domains
  • Build and maintain a DDoS response playbook; lead mitigation during volumetric and application-layer attacks
  • Partner with engineering teams to embed secure coding practices and participate in security-sensitive code reviews
  • Manage the responsible disclosure and bug bounty programme; triage external researcher reports
  • Produce security reports, risk registers, and executive briefings; track remediation SLAs
  • Monitor emerging attack vectors, CVEs, and threat landscape changes relevant to online gaming and fintech platforms

требования

  • 10+ Years of hands-on experience in application, infrastructure, and web security
  • Deep expertise in OWASP Top 10 vulnerabilities, including SQLi, XSS, CSRF, IDOR, RCE, SSRF, and clickjacking
  • Proven experience detecting, mitigating, and analyzing DDoS attacks
  • Strong command of Cloudflare WAF rules, Bot Management, Turnstile, Rate Limiting, Transform Rules, and Firewall Events analysis
  • Hands-on AWS security experience with IAM policies, Security Groups, VPC design, API Gateway throttling, WAFv2, Shield, GuardDuty, and CloudTrail
  • Deep understanding of API security, including OAuth2, JWT, OTP abuse, rate limiting, and endpoint hardening
  • Experience securing frontend applications against XSS, CSP bypass, clickjacking, and third-party script risks
  • Backend security expertise in input validation, secure coding, secrets management, and SQL injection prevention
  • Proficiency with Burp Suite, OWASP ZAP, Nmap, Metasploit, and Nikto
  • Experience conducting and managing vulnerability assessments, threat modelling, and security audits
  • Solid understanding of TLS/SSL, HTTP security headers, and certificate management
  • Experience with SIEM platforms, log aggregation, alert tuning, and incident response
  • Knowledge of bot mitigation strategies, including JA3/JA4 fingerprinting, bot scoring, and heuristic versus ML detection
  • Familiarity with ISO 27001, SOC 2, PCI-DSS, or GDPR
  • Strong written and verbal communication skills; able to produce security reports and brief non-technical stakeholders
  • Hands-on experience integrating SAST, DAST, SCA, and secrets scanning into CI/CD pipelines as automated gates
  • Будет плюсом: Cloudflare Zero Trust, Access, and Tunnel; threat intelligence platforms (VirusTotal, Shodan, AlienVault OTX); bug bounty experience or CVE disclosures; Python, Bash, or Go scripting; securing Electron desktop applications and mobile API surfaces; blockchain/crypto platform security; Docker and Kubernetes RBAC, image scanning tools (Trivy, Snyk); OSCP, CEH, CISSP, AWS Security Specialty, or equivalent certifications; chaos engineering or red team/blue team exercises; gaming or fintech regulatory environments

условия

  • Локация: Европейский союз

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Спроси Хайрика про вакансию

Сверит с твоим резюме, подскажет вилку и вопросы на собесе.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.