#вакансия #ukraine #security #remote #удалённо #devops #engineer
Вакансия Security Engineer / Product Security в компанию CloudBees.
Город и адрес офиса: УДАЛЕНКА ПО УКРАИНЕ
Формат работы: Одесса или удаленка
Занятость: полная
Зарплатная вилка: 3500-5000$
Описание вакансии:
https://jobs.dou.ua/companies/electriccloud/vacancies/97948/Desired Skills
Prior experience (3+ years) working within Application or Information Security teams.
3+ years scripting development experience (e.g. Go, Python, Ruby — bonus for python/django).
A passion for security, and the hacker mentality of doing whatever it takes to figure out and solve a problem.
Proficiency and in-depth understanding of cloud environments, AWS and/or GCP, docker and kubernetes.
Strong understanding of the OWASP Top Ten security risks and how to mitigate them.
Strong understanding of authentication/authorization frameworks (i.e. OAuth2, SSO)
Experience with tools for static/dynamic code analysis (e.g. Sonarqube, OWASP’s).
Proficiency with several app scanners, such as Arachni, ZAP, Anchore.
The ability to write a solid root-cause-analysis / explanation of a security issue is critical — including how to exploit, likelihoods of exploit, etc.
Exposure to compliance frameworks (e.g. GDPR, NIST 800 series, SOC2) a plus.
Up-to-date knowledge of latest security vulnerabilities (e.g. reported CVEs) against web application frameworks and libraries, including an understanding of their impact and exploitation techniques.
гибкий график, хорошая оплата труда, возможность удаленной работы
skype - barrracuda
https://www.facebook.com/maria.belonozhkoviber +380975436333
https://www.linkedin.com/in/maria-belonozhko-15ab49168/telegram -
You will be involved in a vast array of endeavors to build our security program, yet have a specific focus on application security, for both on-prem and SaaS offerings. You will act as the Subject Matter Expert and work with the various teams on security engineering topics.
Work with product engineering teams to architect solutions that are inherently secure, and aligns with our compliance targets.
Build and automate our appsec platform leveraging CI/CD practices, automating/coding everywhere possible.
Risk Assessments/Threat modeling service or application features.
Participate in triaging and acting on our HackerOne program.
Perform penetration testing as required.
Be part of our Incident Response team.
Create and execute training exercises to further educate developers’ security knowledge.
Code the necessary automation to ensure ongoing adherence to security practices/policies.
Help raise the profile of security across engineering. Help the security champions in teams.
We’re powering the continuous economy by building the world’s first end to end system for automated software delivery.