вчера

security engineer infrastructure security

ориентир по рынку
вакансия зп не указана
в среднем 320 875 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Toloka AI creates data that powers leading GenAI models and innovations. It combines experts, a global crowd, and a technology platform to teach AI models to reason and evaluate their efficacy and safety.

задачи

  • Own vulnerability management and operate the vulnerability-management platform;
  • Ensure container images are scanned and patched on a defined cadence;
  • Maintain supply-chain scanning tooling and severity-classification configuration;
  • Define and enforce remediation SLAs;
  • Own cloud security across AWS, GCP, and Azure, including hardening, logging, and service-account governance;
  • Own Kubernetes and service-mesh security;
  • Operate the service mesh and maintain policy-as-code rollout;
  • Audit and secure infrastructure in newly added environments;
  • Review build pipelines and infrastructure and remediate findings;
  • Contribute to security architecture and design reviews;
  • Review new integrations and internal systems, including AI agents running in production, for security risk;
  • Support workforce and endpoint security initiatives;
  • Contribute to VDI and browser-isolation initiatives;
  • Use coding agents for infrastructure-as-code, container configuration, and cloud-policy reviews;
  • Verify agent findings against source configuration;
  • Establish ownership of the vulnerability-management process during the first month;
  • Configure supply-chain scanning, automated image scanning and patching, and initial policy-as-code rules;
  • Complete policy-as-code rollout in at least one environment;
  • Begin infrastructure audits in newly added environments;
  • Close cloud logging and service-account gaps;
  • Establish and enforce a documented multi-cloud hardening baseline;
  • Independently deliver security-architecture design reviews.

требования

  • Production experience hardening cloud infrastructure, including IAM, logging, service accounts, and network security;
  • Experience with at least one major cloud provider;
  • Experience with Kubernetes and container security;
  • Experience with service mesh such as Cilium or Istio;
  • Experience with policy-as-code such as Kyverno or OPA;
  • Vulnerability-management experience;
  • Experience with SCA/SAST tooling and SLA-driven remediation;
  • Experience using agentic tools for infrastructure-as-code review or investigation work;
  • Ability to verify agentic-tool output;
  • Ability to define scope and priorities without detailed direction;
  • Clear written and verbal communication skills;
  • Ability to run design reviews and communicate risk to engineers and leadership;
  • Nice to have: multi-cloud experience, experience securing multi-tenant or multi-identity-domain environments, supply-chain security tooling such as SBOM, Socket, or JFrog, secure-SDLC or AppSec experience, Terraform/IaC at scale, relevant certifications such as AWS/GCP/Azure security specialties or CKS.

условия

  • Contract (B2B) collaboration;
  • Path into a project team if things go well;
  • Flexible schedule of 40 hours per week;
  • Fully remote work;
  • Work on AI development projects with leading customers;
  • Friendly community.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.