Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
The client is a technology company building and scaling product engineering across Fintech, iGaming, and Marketing. It turns innovative ideas into high-performing engines and launches them at scale.
задачи
Design and implement robust security architecture from cloud infrastructure to the application layer, applying secure-by-design principles;
Collaborate with product managers, architects, and developers to build and scale the security controls platform ecosystem;
Validate and prove security implementations in infrastructure, application deployment manifests, and automated CI/CD pipelines;
Define policies, controls, and capabilities to protect global products and environments;
Build and automate declarative threat modeling to identify and mitigate application risks;
Oversee product security strategy for migrating legacy data center workloads to AWS;
Advise engineering and product teams on cybersecurity and participate in planning cycles and technical committees;
Influence the security roadmap and make architectural decisions protecting production environments;
Safeguard real-money flows and critical financial data.
требования
Proven experience analyzing and securing applications developed with JavaScript and TypeScript;
Hands-on experience integrating security scanning and tooling into CI/CD pipelines using GitLab and Jenkins;
Experience with Infrastructure-as-Code models such as Terraform, Helm, or CloudFormation;
Strong development experience in Python and Shell scripting;
Deep familiarity with Docker and service mesh technologies such as ISTIO;
Strong background in architecture and security reviews, threat modeling, and application risk mitigation within an Agile framework;
Strong understanding of supply chain security, software integrity, and secure software delivery;
Familiarity with industry regulations and frameworks including PCI-DSS, ISO 27001, and NIST, as well as privacy laws such as GDPR;
Nice to have: In-depth experience architecting secure services on Kubernetes/AWS, industry certifications such as CISSP, CISM, CCSK, CCSP, or CEH.
условия
Autonomy to influence the security roadmap and make architectural decisions;
Support for advanced certifications, conference attendance, and research time;
Comprehensive benefits package including competitive compensation and health coverage;