31 июл

devsecops engineer

ориентир по рынку
вакансия зп не указана
в среднем 359 861 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

генерация резюме под вакансию

Загрузи резюме в профиль, чтобы сгенерировать временное CV под эту вакансию

сопроводительное письмо

Загрузи резюме в профиль, а нейросеть определит твою категорию. Затем ты сможешь генерировать сопроводительные письма для вакансий этой категории

описание

XBO.com is a group of regulated fintech and cryptocurrency companies. Security serves as the foundation of its business and is governed by PCI DSS Level 1, ISO 27001, SOC 2, and CCSS.

задачи

  • Act as the security–engineering liaison by translating security requirements and audit-driven requests from the CISO into scoped engineering tasks, implementing changes within the security tooling scope, routing infrastructure and code changes to DevOps and R&D, verifying outcomes, and reporting status proactively;
  • Produce technical compliance evidence, including cloud configuration exports, access reviews, network posture, scan results, change records, and CI/CD execution logs, according to the GRC Manager’s calendar and specifications;
  • Run offensive security and validation activities, including internal vulnerability scanning, reproducing and validating external penetration test findings, verifying remediation, challenging false positives with evidence, and technically coordinating ASV scans and penetration test cycles;
  • Own CI/CD security gate outcomes by triaging SAST, dependency and container scanning, and SBOM findings; defining checks and pass/fail thresholds; managing and monitoring gate changes; and packaging outputs as compliance evidence;
  • Assess cloud and edge security posture by researching the cloud and CDN/WAF stack, finding and testing drift and misconfigurations, prioritizing risks, verifying remediation, and owning WAF security rules and posture tooling;
  • Run vulnerability management end to end, including scanning, triage, prioritization, fix coordination, and closure verification;
  • Co-build the detection layer of an agentic, Kubernetes-native monitoring platform with DevOps, contribute and execute detection logic, and investigate its findings;
  • Support incident response through technical investigation, log analysis, and containment under CISO direction.

требования

  • Deep DevOps and infrastructure foundation across AWS, Kubernetes, CI/CD, infrastructure-as-code, and Linux;
  • Hands-on experience with offensive security tooling, including penetration testing tools, red team frameworks, and vulnerability scanners such as Nessus, Burp Suite, Metasploit, Nmap, or OpenVAS;
  • Ability to run scans, validate findings, and reproduce reported vulnerabilities;
  • Shell scripting and automation experience with Bash;
  • Ability to translate audit evidence requests into correctly scoped exports;
  • Sound judgment with elevated access and credentials;
  • Least-privilege discipline;
  • Nice to have: 2+ years in a security-titled role, OSCP, eJPT, PNPT or equivalent, experience producing PCI DSS, ISO 27001, or SOC 2 audit evidence, Python for security automation and tooling, Trivy, SonarQube, Dependency-Track, GuardDuty, Defender, Cloudflare security, SIEM or detection engineering with Microsoft Sentinel, interest in LLM/AI security, fintech, payments, or crypto background.

условия

  • Cyprus location;
  • Founding security hire with direct access to the CISO and influence over the security roadmap;
  • Broad scope covering offensive security, compliance evidence, cloud posture, detection, and incident response;
  • Opportunity to co-build an AI-assisted security stack’s detection layer;
  • GRC counterpart responsible for the paperwork side of compliance.

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

прозрачные зарплаты в IT

Анонимные данные по зарплатам и грейдам

Посмотреть
График динамики зарплат
Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.