Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
BUX is a modern fintech company focused on investing products that democratize investing and affect millions of users. The company builds secure financial products and operates in a regulated environment.
задачи
Strengthen BUX's security posture through proactive risk management and continuous improvement;
Implement and manage Google Cloud Security Command Center Enterprise;
Configure and maintain security monitoring, threat detection, and alerting;
Conduct regular security assessments and vulnerability scans;
Develop and maintain security dashboards for visibility across cloud assets;
Implement and maintain security standards across the organisation;
Define and document security policies, standards, and best practices;
Establish secure development guidelines and support teams in adoption;
Ensure compliance with regulatory requirements and industry standards, including SOC 2, ISO 27001, GDPR, and DORA;
Work with the platform team to integrate security into CI/CD pipelines;
Support engineering teams with security questions, issues, and guidance;
Act as the security subject matter expert for development teams;
Review and advise on security aspects of system designs and architectures;
Assist with security incident investigation and response;
Provide security training and awareness programs for engineering staff;
Manage cloud security operations;
Configure and tune threat detection rules and security alerts;
Develop automated response playbooks for common security scenarios;
Monitor and respond to security findings, vulnerabilities, and misconfigurations;
Coordinate with external security partners and auditors as needed;
Drive continuous security improvement;
Stay current with emerging threats, vulnerabilities, and security technologies;
Evaluate and recommend security tools and solutions;
Track security metrics and report on security posture improvements;
Participate in on-call duties for security incidents.
требования
Senior / Staff-level experience in cloud security;
Expert knowledge of Google Cloud Platform (GCP) security;
Hands-on experience with Google Cloud Security Command Center Enterprise (SCC Enterprise);
Strong knowledge of SIEM/SOAR platforms and security operations;
Experience with cloud security posture management and compliance frameworks;
Knowledge of threat detection, vulnerability management, and incident response;
Understanding of regulatory compliance requirements, including SOC 2, ISO 27001, GDPR, and DORA;
Experience with Infrastructure as Code security using Terraform and Kubernetes;
Strong communication skills for collaboration across engineering teams;
Ability to translate complex security concepts for technical and non-technical audiences;
Nice to have: Security certifications such as CISSP, CCSP, GCSA, or GIAC; experience with AWS or Azure in addition to GCP; knowledge of DevSecOps practices and tooling; experience with container security and Kubernetes security best practices; familiarity with penetration testing and ethical hacking techniques; experience in regulated industries, particularly fintech or financial services; knowledge of secure coding practices and application security testing, including SAST/DAST.
условия
Office in Amsterdam, North Holland, Netherlands;
On-call duties for security incidents;
Opportunity to shape security strategy for a high-growth fintech company impacting millions of users;
Modern cloud technologies and freedom to introduce security tools and practices;
Collaboration with peers who value security and continuous improvement;
Opportunity to establish security best practices from the ground up as the company scales.