Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
Teya provides a financial platform for local businesses across Europe, with simple tools, thoughtful design, and human support. It aims to make financial services easier for cafés, restaurants, salons, shops, and entrepreneurs.
задачи
Design, implement, and continuously improve a Secure SDLC from design through production
Embed security into planning and delivery through threat modelling, security requirements, and automated controls
Lead application security reviews for new systems, major features, and high-risk changes across web, API, mobile, and backend services
Define and maintain secure architecture patterns for authentication, authorisation, APIs, data protection, and multi-tenant isolation
Own the application security tooling stack (SAST, DAST, SCA) and integrate it into CI/CD with high-signal, low-noise outputs
Partner with engineers to triage and remediate vulnerabilities based on exploitability, impact, and regulatory risk
Work with Security Operations to improve application-level logging, telemetry, and incident response readiness
Advise engineering teams and raise the bar through practical guidance, documentation, and targeted training
требования
5+ Years in security engineering, with a demonstrable track record of shipping platforms rather than only performing reviews or writing policy
Production Go experience, including designing, writing, testing, and shipping production Go services. Applications without production Go will not progress
Software engineering fundamentals: version control, code review, testing, CI/CD, observability, and on-call for services you have built
Hands-on experience with payment HSM services, either cloud-hosted or on-premises operated as a service
Payment key management experience, including PIN keys, DUKPT, master/session key hierarchies, and TR-31 or TR-34 key exchange
Experience with key lifecycle management and PCI PIN and PCI-DSS scope
Experience designing and rolling out SAST/DAST/SCA toolchains; routine threat modelling; familiarity with modern AppSec tooling or equivalents
AWS cloud security expertise, including IAM design, workload identity, network isolation, and integration patterns between application workloads and HSM-backed key services
Written communication skills for publishing runbooks, standards, ADRs, and reporting dashboards
Comfortable working in a small team with real regulatory scope; PCI-DSS, PCI PIN, DORA, and GDPR are constraints on the work
Будет плюсом: open-source contributions or side projects, payments industry experience, regulated fintech environment experience (FCA, ECB, or equivalent supervisory scope)
условия
Flexible working hours, provided they suit both the candidate and the team
Health insurance
Physical and mental health support through a partnership with MyFitness
25 Days of annual leave plus bank holidays
Possibility to visit other Teya offices when travel is safe and appropriate
Friday lunch in the office
Friendly, comfortable, high-end work equipment and an informal office environment