Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
PandaDoc provides an all-in-one document workflow automation platform that helps growing organizations create, manage, and sign digital documents, including proposals, quotes, and contracts.
задачи
Review, test, and monitor applications to identify security weaknesses;
Manage vulnerabilities from discovery through remediation with engineering teams;
Respond to infrastructure security alerts and perform hardening, including reviewing roles and permissions across services and APIs;
Participate in incident response and root cause analysis;
Analyze and monitor relevant security threats and prevention measures based on industry trends and standards;
Partner with product, development, and infrastructure teams to embed security requirements into development processes;
Integrate and operate automated security testing across the development lifecycle, including SAST, DAST, SCA, secrets detection, container, and supply chain security;
Develop security automation and tooling to scale security across engineering;
Drive threat modeling and secure-by-design practices across services;
Assess the overall security posture, identify risks, and provide recommendations to strengthen it;
Assist in addressing emerging AI security threats as PandaDoc deploys AI in its product and for internal use.
требования
3+ Years of experience with application security tools such as SAST/SCA, DAST, WAF, CI/CD security, and penetration testing;
2+ Years of cloud security experience implementing security controls and best practices in AWS, GCP, or Microsoft Azure;
Strong background in web application security, including OWASP Top 10, CWE Top 25, attack vectors, and mitigations;
Good understanding of access control and identity management principles, including SAML 2.0, OAuth, OIDC, and JWT;
Practical skills building security automation and tooling with Python, Bash, or equivalent languages;
Experience implementing DevSecOps practices across the SDLC;
Familiarity with containerized, Kubernetes-based environments and their security;
Solid interpersonal, written, and verbal communication skills;
Upper-Intermediate English level (B2+).
условия
Monthly base salary of 21,000 PLN to 24,750 PLN;
Comprehensive healthcare coverage through LuxMed for employees and their families;
UNUM life insurance for employees and their families;
Multisport Card for fitness and wellness activities;
Onboarding benefit allowance for necessary work equipment and setup;
6 Self-care days beyond standard Polish vacation entitlements;
Wellness, learning, and development budgets;
Employees may be able to purchase company stock or receive annual bonuses.