9 сен

security engineer in SaaS

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Action1 provides an autonomous endpoint management platform for Fortune 500 companies. Its cloud-native SaaS platform delivers operating system and third-party patching, peer-to-peer patch distribution, and real-time vulnerability assessment without requiring a VPN.

задачи

  • Support Product Security Incident Response Team (PSIRT) and vulnerability-handling activities;
  • Validate, triage, track, and coordinate security reports;
  • Provide practical remediation guidance to engineering teams;
  • Help validate security fixes and reduce product security risks;
  • Review code, APIs, and system architecture to identify security issues early;
  • Conduct threat modeling and security design reviews;
  • Improve security automation within engineering workflows;
  • Support SAST, SCA, secrets scanning, and other security controls;
  • Maintain software bills of materials (SBOMs), dependency visibility, and remediation follow-up;
  • Support security assessments, vulnerability assessments, and penetration testing;
  • Maintain vulnerability-handling playbooks, product security procedures, and incident response runbooks.

требования

  • 3+ Years of experience in product security, application security, DevSecOps, or a related cybersecurity field;
  • Strong software engineering background and the ability to work effectively with engineering teams;
  • Understanding of application, API, infrastructure, and software supply chain security risks;
  • Experience applying cloud security concepts and practices;
  • Understanding of identity and access management, network security, logging, monitoring, and secure cloud architecture patterns;
  • Familiarity with vulnerability management, incident response, security assessments, and secure software development lifecycle practices;
  • Experience with threat modeling and security design reviews;
  • Strong communication skills, including professional communication with external security researchers and vendors;
  • Ability to work independently and collaboratively in a fast-moving environment;
  • Nice to have: Genuine interest in cybersecurity and motivation to grow as a product security expert, hands-on experience with AWS security controls, best practices, and architecture patterns, hands-on experience with C++ or JavaScript, experience with security testing and automation using scripts, APIs, CI/CD pipelines, or specialized tools, experience conducting threat modeling for SaaS, API, cloud, or on-premises product components, experience with SBOM generation, dependency visibility, or software supply chain security.

условия

  • The opportunity to work on a real-world security product used by IT and security teams;
  • High ownership and a direct impact on product security practices;
  • Close collaboration with engineering, product, and security teams;
  • A fast-growing software company with low bureaucracy and practical decision-making;
  • The opportunity to improve security processes, automation, and engineering workflows;
  • A supportive team that values clear thinking, ownership, and continuous learning.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.