17 авг

security engineer for hosting infrastructure

ориентир по рынку
вакансия зп не указана
в среднем 346 799 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

Рекламный баннер: ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
ИНН: 9704271170

описание

UltaHost provides hosting products and production infrastructure, including VPS, dedicated servers, shared hosting, WordPress, cloud, email, game hosting, customer portals, control panels, and internal hosting platforms.

задачи

  • Take ownership of the security of hosting products and production infrastructure;
  • Review the security of VPS, VDS, dedicated servers, shared hosting, WordPress, cloud, Mac hosting, email hosting, game hosting, customer portals, control panels, APIs, and internal hosting platforms;
  • Assess authentication, authorization, session security, tenant isolation, secrets handling, privileged operations, and data-exposure risks;
  • Perform threat modeling, architecture reviews, security testing, API security reviews, and release risk assessments;
  • Define security requirements and release checks for new products, major features, and sensitive platform changes;
  • Work with Product, Engineering, DevOps, and QA teams until vulnerabilities are remediated, retested, and closed;
  • Define secure baselines for Linux servers, hypervisors, control panels, network devices, firewalls, storage systems, and management interfaces;
  • Review SSH configurations, exposed ports and services, routing, DNS, firewall rules, segmentation, management access, and privilege boundaries;
  • Secure environments involving Proxmox, KVM, VMware, Ceph, containers, VPS nodes, dedicated infrastructure, and data-center connectivity;
  • Investigate brute-force attacks, malware, suspicious processes, privilege escalation, lateral movement, data exfiltration, and abnormal traffic;
  • Own technical DDoS/DoS response, including traffic analysis, mitigation, provider escalation, evidence collection, and post-incident reviews;
  • Run vulnerability scanning, configuration audits, patch-risk assessments, and targeted penetration testing;
  • Prioritize vulnerabilities according to actual customer and infrastructure risk;
  • Assign remediation owners and deadlines and verify that fixes are effective;
  • Lead product and infrastructure security incidents;
  • Support internal security incidents involving servers, networks, or applications;
  • Help achieve earlier detection of critical vulnerabilities before release or exploitation;
  • Help achieve faster containment of product, server, network, and DDoS incidents;
  • Reduce exposed high-risk services, unsafe configurations, and overdue vulnerabilities;
  • Establish secure baseline coverage across Linux, virtualization, network, and hosting products;
  • Strengthen product-security reviews and remediation verification;
  • Prevent recurring security weaknesses;
  • Collaborate with Internal Security & Security Operations Engineer, Product, Engineering, DevOps, Network, QA, Support, Abuse, and executive management.

требования

  • 5+ Years of hands-on experience in hosting security, infrastructure security, Linux security, network security, product security, cloud security, or a closely related role;
  • Advanced Linux administration skills;
  • Real-world experience with VPS, dedicated servers, shared hosting, control panels, hypervisors, storage, or large multi-tenant environments;
  • Experience with Proxmox, KVM, VMware, Ceph, containers, or equivalent virtualization and cluster technologies;
  • Strong knowledge of TCP/IP, DNS, routing, firewalls, VPNs, segmentation, and traffic analysis;
  • Hands-on experience detecting and mitigating DDoS attacks;
  • Strong understanding of OWASP Top 10, API security, authentication, authorization, session security, tenant isolation, secrets management, and secure release practices;
  • Experience with vulnerability scanners, penetration-testing tools, SAST/DAST, dependency scanning, configuration reviews, tcpdump, Wireshark, and log analysis;
  • Ability to investigate compromised servers, malware, brute-force attacks, web attacks, privilege escalation, and abnormal network behavior;
  • This is not a general penetration-testing position; experience must include securing and investigating real production hosting infrastructure, not only vulnerability testing and penetration-test reports;
  • Nice to have: Direct experience in a web hosting company, cloud provider, ISP, CDN, data center, infrastructure vendor, or MSSP; OSCP, OSWA, CCNP Security, GIAC, Security+, CISSP, cloud-security certifications, or equivalent practical expertise.

условия

  • Office role in Tbilisi, Georgia.

Хостинг-провайдер: общий хостинг, VPS и выделенные серверы.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Спроси Хайрика про вакансию

Сверит с твоим резюме, подскажет вилку и вопросы на собесе.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.