Senior Platform Security Engineer / DevOps
25k - 34k PLN25 000 - 34 000 PLN/ mies.B2B
SeniorFull-time·B2B
#455635·Dodano dziś·0
Źródło: FourthwallTech Stack / Keywords
GCPGKETerraformGitLab CI/CDFluxSOPSLinuxPostgreSQLOAuthOIDC
Firma i stanowisko
Fourthwall is where online creators (YouTubers, streamers, podcasters and other independent brands) run shops, merchandise, donations and memberships. More than 500,000 creators use it. The platform you would co-own is the one that runs their businesses.
Wymagania
- Owned a production cloud platform at a senior level with experience in consequential changes, failures, and recovery.
- End-to-end security engineering experience: platform hardening, vulnerability management, security design review, incident handling, VDP or bug bounty operation.
- Proficient with Terraform and GitOps in production; familiarity with Flux.
- Deep knowledge of Kubernetes security: RBAC, network policy, workload identity, admission control; experience operating admission webhooks.
- Strong understanding of identity: cloud IAM, OAuth, OIDC, service-to-service identity (mTLS, workload identity), and short-lived credentials.
- Enough application security knowledge to assess and route VDP reports using the OWASP Top 10.
- Experience with security checks in CI/CD (secret, dependency, image, IaC scanning) and tuning false positives.
- Heavy use of AI tools like Codex or Claude in daily work.
- Ability to write automation in a general-purpose language or shell and review code.
- Clear written and spoken English to explain risk to engineers, security researchers, and leadership.
Nice to have:
- Threat modeling or offensive security experience.
- SRE practices such as SLOs.
- SOC 2 or PCI DSS compliance experience.
Obowiązki
- Co-own the GCP and GKE platform, including networking, IAM, secrets, GitOps, CI/CD, observability, and PostgreSQL.
- Manage the platform-security backlog: reduce standing privilege, manage long-lived credentials, and track infrastructure vulnerabilities.
- Develop guardrails: configuration, policies, alerting, and automated pipeline scanning (secrets, dependencies, images, Terraform, code), including AI-based security review.
- Run the vulnerability disclosure programme (VDP): intake, validation, severity assignment, routing, communication, tracking fixes, and disclosure.
- Define and execute recovery objectives, run restore/failover/access exercises, and manage runbooks and postmortems.
- Implement AI and automation in operations to improve on-call experience and automate responses.
- Provide fast security advice on risky designs and changes; translate recurrent questions into guardrails or defaults.
The first 90 days:
- Map critical platform parts and main risks.
- Organize the VDP queue with severity, ownership, and report age.
- Implement initial high-risk guardrails.
- Conduct at least one restore or access exercise.
- Deliver improvements to production infrastructure.
Benefity
- B2B contract.
- Remote work within Poland with flexible hours and agreed team overlap.
- MacBook.
- Private healthcare.
- Sports card.
- English lessons.
- Equity in a US-based company.
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Kursy językowe
Udziały pracownicze
Inne informacje
Remote only within Poland as explicitly stated. On-call duties included with rotation via PagerDuty.
FOURTHWALL
3 aktywne oferty