InfoSec (DevSecOps) Engineer
Tech Stack / Keywords
Firma i stanowisko
LoopMe is a global team of skilled engineers developing and maintaining real-time bidding platforms for leading advertisers worldwide. The company specializes in AI-driven advertising technology and uses agile methodology to deliver product features rapidly.
Wymagania
- Experience in information security or related fields (formal education and hands-on).
- Minimum 2 years of hands-on experience in InfoSec/DevSecOps roles, preferably in cloud environments such as GCP, AWS, or Azure.
- Strong understanding of network protocols (TCP/IP, DNS, HTTP/S, VPN).
- Hands-on experience securing infrastructure based on GCP, Kubernetes, ClickHouse, Kafka, PostgreSQL.
- Familiarity with security tools: SIEM systems, vulnerability management, IAM/SSO/MFA (e.g., Okta, Azure AD).
- Incident response and forensic investigation experience.
- Solid understanding of security standards and frameworks: ISO/IEC 27001, NIST, OWASP, DevSecOps principles.
- Strong understanding of security principles, including encryption, authentication, access control.
- Experience with security tools and technologies for monitoring and incident response.
- Proficiency in securing Kubernetes, PostgreSQL, ClickHouse, Envoy, and Kafka.
- Experience with security tooling in cloud platforms such as GCP, AWS, Azure.
- Scripting skills in Bash, Python, or PowerShell for automation.
Nice to have:
- Relevant certifications such as CISSP, CISM, CompTIA Security+, GCP Security Engineer.
- Excellent communication skills and ability to collaborate with technical and non-technical stakeholders.
Obowiązki
- Develop and implement information security policies and protection procedures.
- Perform risk assessments, security audits, and threat analysis.
- Monitor and respond to security incidents and conduct investigations.
- Implement and maintain security tools such as SIEM, DLP, WAF, and others.
- Integrate DevSecOps practices into development workflows including Secure SDLC and code reviews.
- Ensure compliance with security standards like ISO/IEC 27001, NIST, OWASP, and CIS Controls.
- Provide cybersecurity awareness training to employees.
- Support secure architecture for platforms including GCP, Kubernetes, ClickHouse, Kafka, PostgreSQL, and Envoy.
- Conduct proof-of-concept for new security integrations and participate in security budget discussions with stakeholders and management.
Benefity
- Competitive compensation package.
- Flexible working schedule with hybrid work model.
- Annual performance bonus.
- One month of workation (ability to work from anywhere in the world for one month).
Inne informacje
Informujemy, że administratorem danych jest Loopme sp. z o.o. z siedzibą w Krakowie, ul. Cieszyńska 13 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
Loopme
6 aktywnych ofert