Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Enhesa is a global compliance partner helping large businesses navigate regulatory and sustainability requirements across EHS, product, chemical, and corporate sustainability compliance. It combines human expertise with AI efficiency and provides regulatory intelligence to more than half of the Fortune 500.
задачи
Secure application development lifecycles and cloud infrastructure by reviewing application code and cloud architectures across AWS, Azure, and GCP;
Integrate security controls, automated testing, and vulnerability management into CI/CD pipelines and DevSecOps workflows;
Partner with Application Engineering and Cloud Platform teams as a hands-on security advisor throughout the development lifecycle;
Provide guidance on secure design patterns;
Collaborate with Tech Leads and the Security Champions network to share secure coding practices and run awareness sessions;
Support security reviews of AI/ML systems and pipelines, assessing risks such as prompt injection, data poisoning, and model supply chain vulnerabilities;
Lead investigation, mitigation, and recovery efforts for security incidents affecting cloud infrastructure and relevant AI/ML services and inference endpoints;
Track emerging cybersecurity trends and vulnerabilities, including AI/ML risks;
Help evolve security controls to address new threats.
требования
Bachelor’s or advanced degree in computer science, artificial intelligence, mathematics, or a related field, or professional cybersecurity certifications in lieu of a formal degree;
At least 5 years of experience as a cybersecurity professional with a strong background in application security and/or cloud security;
Experience integrating security practices into CI/CD pipelines, code review processes, DevSecOps, and MLSecOps workflows;
Solid understanding of common web application vulnerabilities and the OWASP Top 10;
Solid understanding of TCP/IP, LAN/WAN networks, and their security implications;
Basic familiarity with the seven-layer OSI model;
Knowledge of security protocols including HTTPS, DNS, SMTP, FTP, and SSH;
Familiarity with firewalls, IDS, and IPS concepts;
Understanding of confidentiality, integrity, and availability principles;
Familiarity with Windows, Linux or Unix, and MacOS;
Knowledge of incident investigation and response processes;
Programming experience with Python and PowerShell;
Familiarity with API security testing and secure coding practices in web application stacks;
Knowledge of securing AWS, Azure, and GCP environments;
Familiarity with IAM, encryption in transit and at rest, and shared responsibility models;
Understanding of securing virtual machines and containerized environments;
Fluency in English;
Ability to work independently and transparently with colleagues;
Strong teamwork skills with colleagues and external partners;
Individual and team problem-solving skills;
Nice to have: Hands-on exposure to AI/ML security, LLM security, or AI-driven systems; familiarity with the OWASP LLM Top 10; exposure to AI/ML threat vectors; experience securing AI/ML workloads and managed AI services; relevant security certifications such as CISSP, CEH, CCSP, or OSCP; additional language skills.
условия
Competitive salary package;
Flexible home-working policy and work/life balance;
Collaborative, fast-paced, and driven environment;
Enhesa will sponsor and support an AI security certification such as AAISM or CompTIA SecAI+;
Equal Opportunity Employer committed to an inclusive environment.