Senior Platform Security Engineer / DevOps

25k - 34k PLN/ mies.B2B
SeniorFull-time·B2B
#455635·Dodano dziś·0
Źródło: Fourthwall
Aplikuj teraz

Tech Stack / Keywords

GCPGKETerraformGitLab CI/CDFluxSOPSLinuxPostgreSQLOAuthOIDC

Firma i stanowisko

Fourthwall is where online creators (YouTubers, streamers, podcasters and other independent brands) run shops, merchandise, donations and memberships. More than 500,000 creators use it. The platform you would co-own is the one that runs their businesses.

Wymagania

  • Owned a production cloud platform at a senior level with experience in consequential changes, failures, and recovery.
  • End-to-end security engineering experience: platform hardening, vulnerability management, security design review, incident handling, VDP or bug bounty operation.
  • Proficient with Terraform and GitOps in production; familiarity with Flux.
  • Deep knowledge of Kubernetes security: RBAC, network policy, workload identity, admission control; experience operating admission webhooks.
  • Strong understanding of identity: cloud IAM, OAuth, OIDC, service-to-service identity (mTLS, workload identity), and short-lived credentials.
  • Enough application security knowledge to assess and route VDP reports using the OWASP Top 10.
  • Experience with security checks in CI/CD (secret, dependency, image, IaC scanning) and tuning false positives.
  • Heavy use of AI tools like Codex or Claude in daily work.
  • Ability to write automation in a general-purpose language or shell and review code.
  • Clear written and spoken English to explain risk to engineers, security researchers, and leadership.

Nice to have:

  • Threat modeling or offensive security experience.
  • SRE practices such as SLOs.
  • SOC 2 or PCI DSS compliance experience.

Obowiązki

  • Co-own the GCP and GKE platform, including networking, IAM, secrets, GitOps, CI/CD, observability, and PostgreSQL.
  • Manage the platform-security backlog: reduce standing privilege, manage long-lived credentials, and track infrastructure vulnerabilities.
  • Develop guardrails: configuration, policies, alerting, and automated pipeline scanning (secrets, dependencies, images, Terraform, code), including AI-based security review.
  • Run the vulnerability disclosure programme (VDP): intake, validation, severity assignment, routing, communication, tracking fixes, and disclosure.
  • Define and execute recovery objectives, run restore/failover/access exercises, and manage runbooks and postmortems.
  • Implement AI and automation in operations to improve on-call experience and automate responses.
  • Provide fast security advice on risky designs and changes; translate recurrent questions into guardrails or defaults.

The first 90 days:

  • Map critical platform parts and main risks.
  • Organize the VDP queue with severity, ownership, and report age.
  • Implement initial high-risk guardrails.
  • Conduct at least one restore or access exercise.
  • Deliver improvements to production infrastructure.

Benefity

  • B2B contract.
  • Remote work within Poland with flexible hours and agreed team overlap.
  • MacBook.
  • Private healthcare.
  • Sports card.
  • English lessons.
  • Equity in a US-based company.
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Kursy językowe
Udziały pracownicze

Inne informacje

Remote only within Poland as explicitly stated. On-call duties included with rotation via PagerDuty.

FOURTHWALL

FOURTHWALL

3 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz