вчера

security engineer in cloud infrastructure

ориентир по рынку
вакансия зп не указана
в среднем 322 588 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Nasuni is a SaaS data infrastructure company that manages, protects, and activates unstructured enterprise data. Its AI-ready platform helps organizations use file data for intelligent automation, analytics, and global collaboration.

задачи

  • Lead initiatives to improve Nasuni's cloud security posture across AWS, Azure, and GCP, including workload security, IAM hardening, network segmentation, encryption, and least-privilege enforcement;
  • Lead cloud security assessments and configuration reviews, and remediate misconfigurations and security gaps using Wiz and cloud-native tools;
  • Drive zero-trust initiatives and cloud-native security controls across the multi-cloud infrastructure;
  • Translate architectural standards into operational security controls and provide feedback to improve those standards;
  • Evaluate and implement security controls for container and Kubernetes workloads, CI/CD pipelines, and Infrastructure as Code;
  • Contribute implementation guidance, operational security expertise, and risk assessments to cloud security architecture and design reviews;
  • Lead execution and continuous improvement within the vulnerability management program across AWS, Azure, and GCP;
  • Assess and enforce vulnerability SLAs and risk-based prioritization frameworks aligned with business risk appetite;
  • Analyze vulnerability data, synthesize trends, and produce executive-ready reporting on exposure, remediation velocity, and risk posture;
  • Drive systemic remediation with DevOps, SRE, IT/infrastructure, and engineering teams;
  • Tune and optimize scanning coverage, detection fidelity, and platform configuration across vulnerability management tooling;
  • Identify program gaps, define improvement roadmaps, and present recommendations to security leadership;
  • Embed security controls into CI/CD pipelines, IaC templates, and cloud provisioning workflows;
  • Drive security-as-code practices, including policy-as-code, automated misconfiguration detection, and runtime security controls;
  • Define and enforce secure configuration baselines across cloud workloads, operating systems, and network infrastructure;
  • Assess and harden container and Kubernetes environments, and support secrets management and workload identity practices;
  • Contribute to complex and high-severity incident responses within the cloud security domain;
  • Advise the SecOps team on incident response playbooks and runbooks for cloud and infrastructure-related security events;
  • Conduct threat hunting in cloud environments and contribute to detection engineering with the SecOps team;
  • Participate in post-incident reviews and systemic improvements that reduce recurring cloud security events;
  • Partner with GRC to align vulnerability management and cloud security controls with compliance requirements;
  • Own technical evidence preparation and control documentation for audit and compliance activities;
  • Advise engineering and business teams on security considerations for new technologies, integrations, and infrastructure decisions;
  • Mentor colleagues and peers, guide technical decisions, share expertise, and improve cloud security capabilities;
  • Lead security tooling evaluations and contribute to platform investment and program improvement decisions;
  • Design, improve, and scale repeatable AI-assisted security workflows for vulnerability analysis, cloud security assessments, remediation prioritization, and operational efficiency while maintaining validation, security, and risk-management practices.

требования

  • 6–9 Years of experience in security engineering, cloud security, or a closely related discipline;
  • Demonstrated ownership of complex cloud security workstreams in a multi-cloud or cloud-native environment;
  • Proven experience leading or significantly contributing to a vulnerability management program, including tool operation, process design, and stakeholder engagement;
  • Experience securing cloud-native SaaS products or working in complex cloud-first technology environments;
  • Experience designing or operationalizing repeatable AI-assisted workflows for security engineering, vulnerability management, security analysis, automation, or operational efficiency;
  • Deep hands-on AWS security expertise, including IAM, VPC/networking, GuardDuty, Security Hub, CloudTrail, KMS, and AWS-native hardening practices;
  • Strong working knowledge of CSPM tools;
  • Experience with container security, Kubernetes security, and IaC security tooling such as Terraform or CloudFormation;
  • Familiarity with CI/CD security integration and DevSecOps practices;
  • Strong understanding of network security, protocols, and infrastructure security fundamentals, including TCP/IP, DNS, TLS, VPN, and firewall design;
  • Working knowledge of IAM, Zero Trust principles, secrets management, and authentication protocols including OAuth 2.0, OIDC, and SAML;
  • Experience with scripting or automation for security workflows using Python, Bash, or equivalent;
  • Ability to validate AI-generated outputs using security expertise, testing, data analysis, or other structured review mechanisms before production use;
  • Familiarity with NIST CSF, CIS Benchmarks, and OWASP frameworks;
  • Strong command of vulnerability severity frameworks such as CVSS and EPSS and risk-based prioritization methodologies;
  • Experience conducting technical risk assessments and security design reviews;
  • Ability to explain complex security risks and trade-offs clearly to engineering, IT/infrastructure peers, and non-technical leadership;
  • Strong written communication skills for vulnerability reports, security assessments, and architectural recommendations;
  • Collaborative working style with the ability to influence through expertise and build trust across teams;
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience;
  • Nice to have: Azure and GCP experience, direct experience with Wiz, AWS Security Specialty, CISSP, CCSP, GIAC GCSA, or equivalent cloud security credentials.

условия

  • Relocation support is available.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.