Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Toloka creates data that powers leading GenAI models and innovations. The company combines experts, a global crowd, and a technology platform to teach AI models to reason and evaluate their efficacy and safety.
задачи
Own vulnerability management and operate the vulnerability-management platform;
Ensure container images are scanned and patched on a defined cadence;
Maintain supply-chain scanning tooling and severity-classification configuration;
Define and enforce remediation SLAs;
Own cloud security across AWS, GCP, and Azure;
Harden cloud environments, logging, and service-account governance;
Own Kubernetes and service-mesh security;
Operate the service mesh and maintain policy-as-code rollout;
Audit and secure infrastructure in newly added environments;
Review build pipelines and infrastructure and remediate findings;
Contribute to security architecture and design reviews;
Review new integrations and internal systems, including AI agents running in production, for security risks;
Support VDI and browser-isolation initiatives;
Use coding agents for infrastructure-as-code, container configuration, and cloud-policy reviews;
Verify agent findings against source configuration before taking action;
Establish ownership of the vulnerability-management process;
Configure supply-chain scanning, automated image scanning and patching, and initial policy-as-code rules;
Complete policy-as-code rollout in at least one environment;
Begin infrastructure audits in newly added environments;
Close cloud logging and service-account gaps;
Establish and enforce a documented multi-cloud hardening baseline;
Production experience hardening cloud infrastructure;
Experience with IAM, logging, service accounts, and network security on at least one major cloud provider;
Experience with Kubernetes and container security;
Experience with service mesh such as Cilium or Istio;
Experience with policy-as-code such as Kyverno or OPA;
Experience with vulnerability management;
Experience with SCA/SAST tooling and SLA-driven remediation;
Experience using agentic tools for infrastructure-as-code review or investigation;
Ability to verify coding-agent output;
Ability to define scope and priorities without detailed direction;
Clear written and verbal communication skills;
Ability to run design reviews and communicate risk to engineers and leadership;
Nice to have: multi-tenant or multi-identity-domain security, supply-chain security tooling such as SBOM, Socket, or JFrog, secure-SDLC or AppSec, Terraform/IaC at scale, relevant certifications such as AWS/GCP/Azure security specialties or CKS.
условия
B2B contract collaboration;
Flexible schedule of 40 hours per week;
Path into a project team if things go well;
Work alongside a dedicated and dynamic team of experts;
Projects with AI industry leaders and well-known household names;