Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Action1 provides an autonomous endpoint management platform trusted by Fortune 500 companies. Its cloud-native platform delivers operating system and third-party patching, peer-to-peer patch distribution, and real-time vulnerability assessment to reduce IT labor, prevent ransomware and security risks, and protect the digital employee experience.
задачи
Support PSIRT and vulnerability handling activities;
Validate, triage, track, and coordinate security reports;
Provide practical remediation guidance to engineering teams;
Help validate security fixes and reduce product security risks;
Review code, APIs, and architecture to identify security issues early;
Conduct threat modeling and security design reviews;
Improve security automation in engineering workflows;
Support SAST, SCA, secrets scanning, and other security controls;
Maintain SBOMs, dependency visibility, and remediation follow-up;
Support security assessments, vulnerability assessments, and penetration testing;
3+ Years of experience in product security, application security, DevSecOps, or a related cybersecurity field;
Strong software engineering background and ability to work effectively with engineering teams;
Understanding of application, API, infrastructure, and software supply chain security risks;
Experience applying cloud security concepts and practices;
Understanding of IAM, network security, logging, monitoring, and secure cloud architecture patterns;
Familiarity with vulnerability management, incident response, security assessments, and secure SDLC practices;
Experience with threat modeling and security design reviews;
Strong communication skills, including professional communication with external researchers and vendors;
Ability to work independently and as part of a team in a fast-moving environment;
Nice to have: Genuine interest in cybersecurity and motivation to grow as a product security expert, hands-on experience with AWS security controls, best practices, and architecture patterns, hands-on experience with C++ or JavaScript, experience with security testing and automation using scripting, APIs, CI/CD pipelines, or specialized tools, experience with threat modeling for SaaS, API, cloud, or on-prem product components, experience with SBOM generation, dependency visibility, or software supply chain security.
условия
Opportunity to work on a real security product used by IT and security teams;
High ownership and direct impact on product security practices;
Close collaboration with engineering, product, and security teams;
Fast-growing software company with low bureaucracy and practical decision-making;
Opportunity to improve security processes, automation, and engineering workflows;
Supportive team that values clear thinking, ownership, and continuous learning.