29 авг

security engineer in SaaS security

ориентир по рынку
вакансия зп не указана
в среднем 325 071 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Semaphore is a remote-first software company helping engineering teams build, test, and deliver software securely and reliably. Its products include Semaphore Cloud and self-hosted enterprise solutions for critical development workflows.

задачи

  • Run the vulnerability-management lifecycle, including scanning, triage, prioritization, remediation, exceptions, and verification;
  • Operate and improve security monitoring and SIEM tooling, including alert quality, dashboards, detection rules, and integrations;
  • Investigate security alerts and lead the technical response to security incidents;
  • Improve the security of Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services;
  • Own technical controls for identity and access management, least privilege, just-in-time access, secrets, and certificates;
  • Automate patching, evidence collection, recurring control checks, and other security operations;
  • Coordinate penetration tests and drive technical findings through remediation and verification;
  • Translate SOC 2 and ISO 27001 control requirements into effective technical implementations;
  • Produce clear technical evidence for internal and external audits in partnership with the Compliance Manager;
  • Maintain security runbooks, system documentation, risk-based priorities, and operational metrics;
  • Help engineering teams make practical security decisions without adding unnecessary process;
  • Provide clear, practical security guidance to Engineering and Infrastructure teams and drive security issues to closure;
  • Design, implement, operate, test, and remediate technical security controls.

требования

  • Proven ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment;
  • Strong Linux systems, networking, and cloud-security fundamentals;
  • Hands-on experience with vulnerability management, patching, hardening, and remediation at scale;
  • Experience operating SIEM or security-monitoring systems and investigating security events;
  • Practical understanding of IAM, privileged access, secrets management, certificates, and network controls;
  • Ability to automate operational work using Python, Bash, infrastructure-as-code, or similar tools;
  • Experience participating in incident response and communicating clearly during high-pressure situations;
  • Working knowledge of ISO 27001, SOC 2, or similar security-control frameworks;
  • Strong written and spoken English;
  • Ability to work independently in a remote, asynchronous team;
  • Good risk judgment, including the ability to distinguish urgent security problems, acceptable exceptions, and low-value processes;
  • Nice to have: Experience with Wazuh or a comparable SIEM/security-monitoring platform, Teleport, PAM, or just-in-time access systems, securing large Linux server fleets or hybrid cloud/on-premise environments, CI/CD systems, build infrastructure, containers, and software supply-chain security, supporting SOC 2 or ISO 27001 audits from the technical-control side, relevant certifications such as Security+, CISSP, CISM, GIAC, or ISO 27001.

условия

  • Full-time employment;
  • Optional office work in Novi Sad;
  • SOC 2 Type 2 and ISO 27001:2022 compliance environment.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.