YGO
5 сен

security engineer in AI tourism

ориентир по рынку
вакансия зп не указана
в среднем 320 875 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

YGO.ai is a VC-funded AI tourism platform serving major travel enterprises. It provides an AI search and recommendation engine, a SaaS content enrichment API, and a cloud platform with enterprise integrations, SSO, data ingestion, an MCP server, and multiple LLM providers.

задачи

  • Own hands-on security engineering and build the security function as the company grows;
  • Review source code and architecture across APIs, backend services, and internal tooling;
  • Perform targeted penetration testing and work with engineers on root causes and practical fixes;
  • Manage vulnerabilities and commissioned external penetration tests;
  • Build alerting, intrusion detection, incident processes, and the on-call path;
  • Harden cloud and platform security across access control, network boundaries, secrets, containers, and deployment pipelines;
  • Embed security through the SDLC, including CI/CD, repositories, and dependencies;
  • Secure APIs through authentication, authorization, tenant isolation, token lifecycle management, abuse prevention, enterprise SSO, and audit trails;
  • Secure AI systems against prompt injection and risks involving tools, agents, MCP, retrieval, and data ingestion;
  • Manage data-residency requirements;
  • Secure employee identity and company systems, including SSO, MFA, privileged access, onboarding, offboarding, access reviews, MDM, endpoint security, and SaaS access;
  • Conduct threat modelling and secure design reviews across pods;
  • Set security priorities and the roadmap based on actual risk;
  • Decide what to build, buy, automate, or defer;
  • Grow the security team and hire into it;
  • Represent security to enterprise clients;
  • Lead the SOC 2 programme on Drata.

требования

  • 5+ Years of hands-on security work across more than one discipline;
  • Strong application security expertise, including web application and API attacks, code review, and targeted penetration testing;
  • Strong understanding of authentication and authorization, including OAuth, OIDC, sessions, token handling, access control, and API breach failure modes;
  • Cloud security fundamentals covering identity, network, workload, and pipeline security;
  • Defensive security experience investigating real incidents and building or improving detection and alerting;
  • Experience with threat modelling and secure architecture for cloud, container, and API systems;
  • Engineering background and comfort working in a codebase;
  • Ability to prioritize based on risk, business impact, and available resources in resource-constrained environments;
  • Willingness to build a security team;
  • Working proficiency with Claude Code, with specific examples;
  • Good judgement about security pace in a company that ships daily;
  • Experience with SOC 2, ISO 27001, or demanding enterprise security reviews;
  • Excellent spoken and written English;
  • Availability for European or African time zones within ±3 hours of CET;
  • Nice to have: Prior Go experience, prior leadership experience, AI and LLM security, early security hire experience, experience leading or mentoring security engineers, Go, self-built security tooling or automation, MDM, endpoint protection and identity provider administration, compliance automation tooling, security certifications, GDPR depth, travel or GDS exposure, German.

условия

  • Full-time, 40 hours per week.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.