10 сен

security engineer in AI development

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Toloka creates data that powers leading GenAI models and innovations. The company combines experts, a global crowd, and a technology platform to teach AI models to reason and evaluate their efficacy and safety.

задачи

  • Own vulnerability management and operate the vulnerability-management platform;
  • Ensure container images are scanned and patched on a defined cadence;
  • Maintain supply-chain scanning tooling and severity-classification configuration;
  • Define and enforce remediation SLAs;
  • Own cloud security across AWS, GCP, and Azure;
  • Harden cloud environments, logging, and service-account governance;
  • Own Kubernetes and service-mesh security;
  • Operate the service mesh and maintain policy-as-code rollout;
  • Audit and secure infrastructure in newly added environments;
  • Review build pipelines and infrastructure and remediate findings;
  • Contribute to security architecture and design reviews;
  • Review new integrations and internal systems, including AI agents running in production, for security risks;
  • Support VDI and browser-isolation initiatives;
  • Use coding agents for infrastructure-as-code, container configuration, and cloud-policy reviews;
  • Verify agent findings against source configuration before taking action;
  • Establish ownership of the vulnerability-management process;
  • Configure supply-chain scanning, automated image scanning and patching, and initial policy-as-code rules;
  • Complete policy-as-code rollout in at least one environment;
  • Begin infrastructure audits in newly added environments;
  • Close cloud logging and service-account gaps;
  • Establish and enforce a documented multi-cloud hardening baseline;
  • Independently deliver security-architecture design reviews.

требования

  • Production experience hardening cloud infrastructure;
  • Experience with IAM, logging, service accounts, and network security on at least one major cloud provider;
  • Experience with Kubernetes and container security;
  • Experience with service mesh such as Cilium or Istio;
  • Experience with policy-as-code such as Kyverno or OPA;
  • Experience with vulnerability management;
  • Experience with SCA/SAST tooling and SLA-driven remediation;
  • Experience using agentic tools for infrastructure-as-code review or investigation;
  • Ability to verify coding-agent output;
  • Ability to define scope and priorities without detailed direction;
  • Clear written and verbal communication skills;
  • Ability to run design reviews and communicate risk to engineers and leadership;
  • Nice to have: multi-tenant or multi-identity-domain security, supply-chain security tooling such as SBOM, Socket, or JFrog, secure-SDLC or AppSec, Terraform/IaC at scale, relevant certifications such as AWS/GCP/Azure security specialties or CKS.

условия

  • B2B contract collaboration;
  • Flexible schedule of 40 hours per week;
  • Path into a project team if things go well;
  • Work alongside a dedicated and dynamic team of experts;
  • Projects with AI industry leaders and well-known household names;
  • Friendly community.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.