Security Engineer
150 - 180 PLN/ godz.B2B (netto)
SeniorFull-time·B2B
#313439·Dodano około miesiąc temu·59
Źródło: nofluffjobs.com🚫Oferta wygasła. Ta oferta pracy nie jest już aktywna i rekrutacja została zakończona.
Tech Stack / Keywords
Node.jsTypeScriptGCPOWASPCloud securityKubernetesAPISecurityCISSPOSCP
Firma i stanowisko
Join a team that's building the core digital infrastructure for a leading German health-tech platform. Our client pioneered the country's first digital sick note and has since become a trusted provider of digital care services.
Wymagania
- Experience with app and/or cloud security in real systems
- Comfortable with Kubernetes and GCP
- Knowledge of API security including OWASP API & Mobile Top 10
- Experience securing Node.js / TypeScript backends
- Ability to work independently and take ownership
Nice to have:
- Certifications: CISSP, CKS, CCSP, OSCP
Obowiązki
- Conduct practical penetration tests (Node.js/TypeScript, API, iOS/Android) using tools such as Burp Suite
- Identify and remediate vulnerabilities (e.g., authorization bypass, injection, deserialization flaws)
- Define and implement secure API standards (JWT/OAuth, TLS/mTLS, validation, rate limiting, CORS)
- Harden infrastructure (Kubernetes/GCP, Postgres, Redis/BullMQ) and secure mobile applications
- Create and continuously improve Secure SDLC practices (threat modeling, code reviews, SAST/DAST in CI/CD)
- Implement automated monitoring (eBPF, Falco) and support incident response
- Collaborate on GDPR, ISO 27001, and SOC 2 initiatives
- Write clean, testable code that's easy to understand and maintain across products
Oferta
- Work environment with zero micromanagement and autonomy
- 100% remote work, recruitment & onboarding
- Experienced team with 4 to 15+ years in commercial projects
- Unique memes & pets channel
- Private medical insurance and sports card
- Small teams
- International projects
Karta sportowa
Opieka zdrowotna
Idego Group Sp. z o.o.
6 aktywnych ofert