Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Toloka creates data that powers leading GenAI models and innovations. It combines experts, a global crowd, and a technology platform to teach AI models to reason and evaluate their efficacy and safety.
задачи
Own vulnerability management and maintain the vulnerability-management platform;
Ensure container images are scanned and patched on a defined cadence;
Maintain supply-chain scanning tooling and severity-classification configuration;
Define and enforce remediation SLAs;
Own cloud security across AWS, GCP, and Azure;
Harden cloud environments, logging, and service-account governance;
Own Kubernetes and service-mesh security;
Operate the service mesh and maintain policy-as-code rollout;
Audit and secure infrastructure in newly added environments;
Review build pipelines and infrastructure and remediate findings;
Contribute to security architecture and design reviews;
Review new integrations and internal systems, including AI agents running in production, for security risks;
Support workforce and endpoint security initiatives;
Contribute to VDI and browser-isolation initiatives;
Use coding agents to review infrastructure-as-code, container configuration, and cloud policy;
Verify agent findings against source configuration before acting on them;
Establish ownership of the vulnerability-management process;
Configure supply-chain scanning, automated image scanning and patching, and policy-as-code rules;
Complete policy-as-code rollout in at least one environment;
Begin infrastructure audits in newly added environments;
Close cloud logging and service-account gaps;
Establish and enforce a documented multi-cloud hardening baseline;
Production experience hardening cloud infrastructure;
Experience with IAM, logging, service accounts, and network security on at least one major cloud provider;
Experience with Kubernetes and container security;
Experience with service mesh such as Cilium or Istio;
Experience with policy-as-code such as Kyverno or OPA;
Vulnerability-management experience;
Experience with SCA/SAST tooling and SLA-driven remediation;
Experience using agentic tools for infrastructure-as-code review or investigation work;
Ability to verify coding-agent output;
Ability to define scope and priorities without detailed direction;
Clear written and verbal communication skills;
Ability to run design reviews and communicate risk to engineers and leadership;
Nice to have: multi-tenant or multi-identity-domain security, supply-chain security tooling such as SBOM, Socket, or JFrog, secure-SDLC or AppSec experience, Terraform/IaC at scale, relevant certifications such as AWS/GCP/Azure security specialties or CKS.
условия
Contract (B2B) collaboration, with a path into a project team if things go well;
Flexible, fully remote schedule;
40 Hours per week;
Work at the leading edge of AI development alongside a dedicated and dynamic team of experts;
Projects with customers that are AI industry leaders and well-known household names;