Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
First Connect Insurance Services is a digital marketplace that gives independent insurance agents access to leading US carriers and a range of insurance policies. It provides consumer-grade software to help agents grow their businesses.
задачи
Secure and harden the AWS environment, including identity and access, network boundaries, encryption, and key management
Build security into infrastructure definition and deployment, including Terraform modules and guardrails, Kubernetes and ECS workloads, container images, secrets management, and policy-as-code
Help select, deploy, and fine-tune cloud security platforms, including CNAPP/CSPM, workload protection, logging, and detection tools
Ensure telemetry has appropriate sources, coverage, and alerts, and support investigations
Embed SAST, SCA, secrets, IaC, and container scanning into delivery pipelines, reduce noise, and partner with developers on remediation
Automate security work by turning findings into tickets, checks into gates, and evidence collection into an automated process
Help the company adopt AI safely by reviewing tools and connectors, mapping data flows, and controlling prompt injection, data exposure, and over-permissioned integrations
Work with R&D on security for AI capabilities shipped to agents, from threat modeling to controls and monitoring
Review, advise on, and help set up fully automated AI code deployment and product development
Act as the technical reference point for cloud security across R&D and DevOps, review designs, and provide guidance
требования
6+ Years across cloud/infrastructure engineering and information security, including substantial hands-on cloud security experience
Production experience securing AWS environments, including IAM and organization-level controls, networking, encryption, and logging; able to explain security trade-offs
Solid production experience with Terraform and Kubernetes and/or ECS
Experience implementing security tooling from scratch, including selection, rollout, and tuning
Comfortable with ownership and ambiguity
Write code in Python, TypeScript/Node, Go, or similar; work with APIs and build solutions that run in CI/CD without supervision
Influence teams through reasoning and working solutions, drive technical direction, and make decisions with Security and R&D leadership
Communicate clearly in writing and speech with technical and non-technical stakeholders
Professional English and Polish (both C1)
Based in Poland and available for occasional afternoon meetings (CET) with colleagues in other time zones
Будет плюсом: pipeline-based application security scanning, dependency and secrets hygiene, common web and API vulnerability classes, prioritization of vulnerabilities, daily use of modern AI tools, understanding of AI risks including prompt injection, data leakage, excessive agency, and third-party AI data flows
условия
Локация: Польша
Remote work and flexible working hours
Non-service days
Private medical care, including dental care, physiotherapy, and psychological support, with full coverage for the entire family
Group life insurance
MultiSport, 75% covered via the cafeteria platform
English language learning budget
Cafeteria platform with a monthly budget
Glasses reimbursement every 3 years
Team-building events, including an annual Offsite and Christmas Parties, plus a workation week