Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой — после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Sumsub is an AI-powered trust infrastructure for compliance operations at scale. It connects identity and business verification, fraud prevention, transaction monitoring, and risk workflows to help teams reduce manual work and enter new markets.
задачи
Design and operate scanning pipelines across infrastructure and containers using Nessus, Trivy, or equivalent tools, managing CVE correlation, asset ownership mapping, and remediation SLAs;
Oversee fleet inventory, policy coverage, and configuration drift using osquery or FleetDM-class solutions;
Develop correlation logic linking vulnerabilities to business criticality and exploitability using CVSS/EPSS;
Automate lifecycle operations including onboarding, asset reconciliation, and exception workflows;
Build APIs, dashboards, and ChatOps/Slack integrations for independent use of security controls by platform and engineering teams;
Define machine-checkable security standards and ensure audit-ready compliance evidence is produced automatically;
Partner with SOC, Infrastructure, and Platform teams to validate controls in production while protecting developer experience;
Take full engineering ownership of Vulnerability Management and Fleet Security capabilities.
требования
Hands-on experience running program-level infrastructure scanning with Nessus, Qualys, Tenable, or similar tools;
Experience with container image security using Trivy or similar tools;
Proven experience with fleet inventory systems such as osquery or FleetDM;
Experience with cloud platforms, preferably AWS;
Experience with containerized and Kubernetes environments;
Strong scripting ability in Python, Go, or Bash;
Solid experience building custom APIs, dashboards, or system integrations;
Deep understanding of CVEs, CVSS/EPSS scoring, and remediation workflows;
Practical judgment in applying theoretical risk frameworks to production environments;
Think like a Platform Engineer building tools for internal customers and prioritizing developer experience and automated prevention;
Nice to have: experience integrating security gates into modern CI/CD pipelines such as GitLab CI and GitHub Actions, exposure to Kubernetes admission control and Policy-as-Code frameworks such as Kyverno and OPA, experience automating compliance evidence collection for PCI DSS, SOC 2, or ISO 27001, proven track record of evolving a security function from manual reviews toward platform ownership.
условия
Remote-first, trust-based culture;
No mandatory office days or attendance trackers; offices or coworking spaces are available in some locations;
Flexible working hours without a fixed 9-to-5 schedule;
Birthday holiday;
10 Personal days each year;
Seven sick days without paperwork;
Extra time off for Christmas and New Year;
Fair and transparent pay benchmarked to the market;
Role-specific learning opportunities and covered events;
Financial bonuses for marriage and welcoming a new baby;
Fully covered team offsites several times a year;
Tools and hardware required for work;
Compensation varies by work location and applicable local market conditions;
A single universal salary range is not included; location-specific compensation will be shared in writing early in the recruitment process.