Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Semaphore is a remote-first software company helping engineering teams build, test, and deliver software securely and reliably. Its products include Semaphore Cloud and self-hosted enterprise solutions for critical development workflows.
задачи
Run the vulnerability-management lifecycle, including scanning, triage, prioritization, remediation, exceptions, and verification;
Operate and improve security monitoring and SIEM tooling, including alert quality, dashboards, detection rules, and integrations;
Investigate security alerts and lead the technical response to security incidents;
Improve the security of Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services;
Own technical controls for identity and access management, least privilege, just-in-time access, secrets, and certificates;
Automate patching, evidence collection, recurring control checks, and other security operations;
Coordinate penetration tests and drive technical findings through remediation and verification;
Translate SOC 2 and ISO 27001 control requirements into effective technical implementations;
Produce clear technical evidence for internal and external audits in partnership with the Compliance Manager;
Maintain security runbooks, system documentation, risk-based priorities, and operational metrics;
Help engineering teams make practical security decisions without adding unnecessary process;
Provide clear, practical security guidance to Engineering and Infrastructure teams and drive security issues to closure;
Design, implement, operate, test, and remediate technical security controls.
требования
Proven ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment;
Strong Linux systems, networking, and cloud-security fundamentals;
Hands-on experience with vulnerability management, patching, hardening, and remediation at scale;
Experience operating SIEM or security-monitoring systems and investigating security events;
Practical understanding of IAM, privileged access, secrets management, certificates, and network controls;
Ability to automate operational work using Python, Bash, infrastructure-as-code, or similar tools;
Experience participating in incident response and communicating clearly during high-pressure situations;
Working knowledge of ISO 27001, SOC 2, or similar security-control frameworks;
Strong written and spoken English;
Ability to work independently in a remote, asynchronous team;
Good risk judgment, including the ability to distinguish urgent security problems, acceptable exceptions, and low-value processes;
Nice to have: Experience with Wazuh or a comparable SIEM/security-monitoring platform, Teleport, PAM, or just-in-time access systems, securing large Linux server fleets or hybrid cloud/on-premise environments, CI/CD systems, build infrastructure, containers, and software supply-chain security, supporting SOC 2 or ISO 27001 audits from the technical-control side, relevant certifications such as Security+, CISSP, CISM, GIAC, or ISO 27001.
условия
Full-time employment;
Optional office work in Novi Sad;
SOC 2 Type 2 and ISO 27001:2022 compliance environment.