Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
YGO.ai is a VC-funded AI tourism platform serving major travel enterprises. It provides an AI search and recommendation engine, a SaaS content enrichment API, and a cloud platform with enterprise integrations, SSO, data ingestion, an MCP server, and multiple LLM providers.
задачи
Own hands-on security engineering and build the security function as the company grows;
Review source code and architecture across APIs, backend services, and internal tooling;
Perform targeted penetration testing and work with engineers on root causes and practical fixes;
Manage vulnerabilities and commissioned external penetration tests;
Build alerting, intrusion detection, incident processes, and the on-call path;
Harden cloud and platform security across access control, network boundaries, secrets, containers, and deployment pipelines;
Embed security through the SDLC, including CI/CD, repositories, and dependencies;
Secure APIs through authentication, authorization, tenant isolation, token lifecycle management, abuse prevention, enterprise SSO, and audit trails;
Secure AI systems against prompt injection and risks involving tools, agents, MCP, retrieval, and data ingestion;
Manage data-residency requirements;
Secure employee identity and company systems, including SSO, MFA, privileged access, onboarding, offboarding, access reviews, MDM, endpoint security, and SaaS access;
Conduct threat modelling and secure design reviews across pods;
Set security priorities and the roadmap based on actual risk;
Decide what to build, buy, automate, or defer;
Grow the security team and hire into it;
Represent security to enterprise clients;
Lead the SOC 2 programme on Drata.
требования
5+ Years of hands-on security work across more than one discipline;
Strong application security expertise, including web application and API attacks, code review, and targeted penetration testing;
Strong understanding of authentication and authorization, including OAuth, OIDC, sessions, token handling, access control, and API breach failure modes;
Cloud security fundamentals covering identity, network, workload, and pipeline security;
Defensive security experience investigating real incidents and building or improving detection and alerting;
Experience with threat modelling and secure architecture for cloud, container, and API systems;
Engineering background and comfort working in a codebase;
Ability to prioritize based on risk, business impact, and available resources in resource-constrained environments;
Willingness to build a security team;
Working proficiency with Claude Code, with specific examples;
Good judgement about security pace in a company that ships daily;
Experience with SOC 2, ISO 27001, or demanding enterprise security reviews;
Excellent spoken and written English;
Availability for European or African time zones within ±3 hours of CET;
Nice to have: Prior Go experience, prior leadership experience, AI and LLM security, early security hire experience, experience leading or mentoring security engineers, Go, self-built security tooling or automation, MDM, endpoint protection and identity provider administration, compliance automation tooling, security certifications, GDPR depth, travel or GDS exposure, German.