Перейти к содержимому
S
SpaceWhale
Київ

Инженер по безопасности (Security Engineer)

Ищем инженера по безопасности для финтех-компании. Вы будете отвечать за техническую сторону комплаенса, управление уязвимостями, облачную безопасность и проведение пентестов. Требуется опыт работы с инструментами для тестирования на проникновение и знание DevOps. Предлагаем роль с высоким уровнем влияния и прямой доступ к CISO.

middle удалённо ~2 176 036 ₸
Языки: Английский · Intermediate
salary intelligence

Зарплата не указана — оценили по рынку

На основе 110 похожих вакансий за 90 дней.

оценка p25–p75
994 140 – 3 462 505 ₸
медиана: 2 176 036 ₸
Хотите увидеть распределение по грейдам и городам? Зарплаты Security Калькулятор зарплат
Вакансии в Telegram-канале
Свежие вакансии Каждый день
Подписаться
??%
Match Score
Войдите и создайте резюме
Войти
описание

Что предстоит делать

<p><strong>About us:<br></strong>We are a group of regulated fintech and cryptocurrency companies. Security isn’t a feature for us — it’s the foundation the business stands on.<br><strong><br>About the role:<br></strong>You will be one of two founding security hires, working alongside a GRC Manager under the CISO: they own the compliance framework and audit calendar; you own the technical engineering and evidence that makes compliance real. This is a hands-on, high-ownership individual-contributor role in an environment governed by PCI DSS Level 1, ISO 27001, SOC 2, and CCSS.<br>You’ll have direct access to standalone security tooling — scanners, WAF/CDN security rules, cloud security posture tools — and work through a specify → implement → verify loop with DevOps and R&amp;D for anything embedded in infrastructure or application code they own. You define what must change and verify it changed; they implement in their systems. It’s a deliberate model that keeps change control clean in a regulated environment, and it means your requests need to be sharp — which is why we need someone with a real infrastructure background, not just a scanner operator.<br><strong><br>What you’ll do:<br><br>In priority order:<br></strong>• Be the security—engineering liaison — translate security requirements and audit-driven requests from the CISO into scoped engineering tasks; implement within your own security tooling scope; route infrastructure and code changes to DevOps and R&amp;D as tracked, well-specified requests; verify outcomes and report status proactively.<br>• Produce technical compliance evidence — cloud config exports, access reviews, network posture, scan results, change records, CI/CD execution logs — audit-ready, on the GRC Manager’s calendar and to their specifications.<br>• Run offensive security and validation — internal vulnerability scanning; reproduce and validate external pen test findings; verify remediation; challenge false positives with evidence; coordinate ASV scans and pen test cycles technically.<br>• Own CI/CD security gate outcomes — triage findings from pipeline gates (SAST, dependency/container scanning, SBOM); define checks and pass/fail thresholds; manage and monitor implementation of gate changes by their owners; package outputs as compliance evidence.<br>• Assess cloud and edge posture — research the cloud and CDN/WAF stack, find and test drift and misconfigurations, prioritize by risk, verify remediation; direct ownership of WAF security rules and posture tooling.<br>• Run vulnerability management end to end — scanning, triage, prioritization, fix coordination, closure verification.<br>• Co-build security monitoring — co-implement the detection layer of our agentic, Kubernetes-native monitoring platform with DevOps; contribute and execute detection logic; investigate what it surfaces.<br>• Support incident response — technical investigation, log analysis, containment under CISO direction.<br>What you’ll bring<br>• Solid DevOps / infrastructure foundation: AWS, Kubernetes, CI/CD, infrastructure-as-code, Linux — the specify→verify model only works when the specifier deeply understands the systems.<br>• Hands-on experience with offensive security tooling — penetration testing tools, red team frameworks, vulnerability scanners (e.g. Nessus, Burp Suite, Metasploit, Nmap, OpenVAS) — able to run scans, validate findings, and reproduce reported vulnerabilities.<br>• Shell scripting and automation (Bash).<br>• The communication muscle this role runs on: you can take “the assessor needs proof these controls exist” and come back with the right export, correctly scoped, first time.<br>• Sound judgment with elevated access and credentials; least-privilege discipline.<br><strong><br>Nice to have:<br></strong>• 2+ years in a security-titled seat (security engineering, vulnerability management, AppSec).<br>• Offensive certifications: OSCP, eJPT, PNPT or equivalent.<br>• Exposure to audit evidence production (PCI DSS, ISO 27001, SOC 2) — knowing what evidence looks like is a genuine differentiator.<br>• Python for security automation and tooling.<br>• Tooling: Trivy, SonarQube, Dependency-Track, GuardDuty, Defender, Cloudflare security.<br>• SIEM / detection engineering (Microsoft Sentinel).<br>• Interest in LLM/AI systems and their security.<br>• Fintech, payments, or crypto background.<br><strong><br>Why join<br></strong>• Founding hire: direct line to the CISO and real influence over the security roadmap — you’re not ticket #4 in a queue.<br>• Full breadth: offensive work, evidence, cloud posture, detection, incident response — not a narrow slice.<br>• A modern AI-assisted security stack whose detection layer you’ll co-build from close to the ground up.<br>• A GRC counterpart who owns the paperwork side of compliance, so your audit involvement stays technical.</p> <div> <a href="https://jobs.dou.ua/companies/spacewhale/vacancies/367518/#reply-btn-id">Відгукнутись на вакансію</a> </div>

навыки

Стек и инструменты

Поделиться

Подходит ли вам эта вакансия?

Зарегистрируйтесь и загрузите резюме — посчитаем % совпадения с этой вакансией, подсветим сильные стороны и что стоит подтянуть

Создать аккаунт PDF-парсинг резюме за 2 минуты

Похожие вакансии

6 вакансий
Онланта
О
Онланта
9 ч. назад

Специалист по информационной безопасности

~1 925 048 ₸ оценка

Компания «Онланта» ищет специалиста по информационной безопасности для участия в аудитах, разработке документации и консультировании по вопросам ИБ. Требуется опыт от 2 лет и знание российского законодательства в области ГИС, ПДн, КИИ. Предлагается работа в профессиональном окружении, ДМС и возможности обучения.

информационная безопасность ГИС ПДн +8
middle удал. hh
O
OTAKOYI
12 ч. назад

Cloud DevSecOps инженер

~1 925 048 ₸ оценка

Ищем опытного DevSecOps инженера для проектирования и защиты облачной инфраструктуры на AWS и Azure. Вы будете внедрять безопасные CI/CD пайплайны, автоматизировать инфраструктуру с Terraform и обеспечивать безопасность Kubernetes. Требуется 3+ года опыта и знание современных инструментов безопасности.

AWS Azure Terraform +16
middle удал. dou
Альфа-Банк
А
Альфа-Банк
14 ч. назад

Специалист по информационной безопасности (Application Security)

~1 925 048 ₸ оценка

Ищем специалиста по информационной безопасности для анализа архитектуры решений, моделирования угроз и поддержки команд разработки. Требуется опыт в Application Security, знание OWASP и Burp Suite, а также навыки анализа кода и работы с CI/CD. Предлагаем гибкий график, полную удалёнку или гибрид, ДМС и оплату профессионального развития.

информационная безопасность application security OWASP +7
middle удал. hh
Т
ТASlife
1 д. назад

Security Engineer (Microsoft / Cloud Security)

Компанія ТASlife шукає Security Engineer для налаштування та підтримки безпеки в Microsoft-середовищі (Defender, Intune, Azure, M365). Потрібен досвід від 3 років в ІБ або системному адмініструванні з фокусом на безпеку. Пропонують офіційне працевлаштування, віддалену роботу та медичне страхування.

Microsoft Defender Intune Azure +11
middle удал. dou
C
Cosmolot
2 д. назад

Системный инженер (Технический)

~1 925 048 ₸ оценка

Вакансия системного инженера в украинской IT-компании Cosmolot. Вы будете отвечать за безопасность и оптимизацию IT-среды: настройку Google Workspace, работу с EDR и MDM, управление доступом и устранение уязвимостей. Требуется опыт в кибербезопасности и администрировании, знание английского на уровне Intermediate+. Предлагают гибкий график, медстраховку, оплачиваемый отпуск и обучение.

Google Workspace EDR MDM +10
middle удал. dou
Pampadu.ru
P
Pampadu.ru
2 д. назад

Инженер по информационной безопасности

до ~1 821 000 ₸ (300 000 RUB)

Ищем опытного инженера по информационной безопасности для разработки и внедрения стандартов ИБ, настройки средств защиты и мониторинга угроз. Требуется опыт от 3 лет и знание нормативных требований. Предлагаем полную удаленку, ДМС и интересные проекты.

SIEM Firewall Информационная безопасность +5
middle удал. hc