Stay current on emerging threats and vulnerabilities, collaborate with engineering teams
Keep infrastructure updated with latest technologies
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
As Security Engineer on the Infrastructure Team at LotusFlare you will be responsible to drive the overall IT security standards across our cloud native DNO stack. This incorporates security policies and domain security concepts along with the implementation and the lifecycle of security technologies in LotusFlare’s infrastructure.
As Senior Security Engineer you will be reporting to the VP of Infrastructure and engage directly with infrastructure and product engineering teams.
REQUIRED SKILLS
At least 5+ years of experience in a similar technical security role
Experience with ITSMS frameworks ISO27000, NIST and SOC
Excellent knowledge in development and implementation of the following concepts:
Network Security Concepts
Linux System Security and System Hardening
Data Classification and Data Security Concepts
Cloud Security, particularly AWS
Understanding of various user access controls, SSO, user profile integrity and access management controls
Experience in Server Application security concepts and security controls
Experience with intrusion detection solutions and web application firewalls/L7 proxies
Planning and executing security audits and continuous security and threat monitoring
Knowledge of privacy frameworks like GDPR and related IT controls and implementations
DevSecOps experience, implementation of security controls and familiarity with SCAP and continuous security monitoring solutions
Ability to analyze and resolve complex infrastructure resource and application deployment issues
Minimum Intermediate level of English
RESPONSIBILITIES
Actively managing the security of our cloud-native runtime environment
Evolving LotusFlare’s GRC with regular senior management reporting of compliance and risk KPIs
Clearly and promptly communicate and negotiate security technical topics with both technical and non-technical audiences
Drive security improvements to production cloud environments
Perform targeted offensive security testing
Implement continuous monitoring systems and tools to automatically identify potential security issues at the code, application and infrastructure layers
Conduct security audits in cloud environments
Review code and other production changes with the goal to maintain the security standards
Develop documentation listing recommendations and best practices for infrastructure and organizational security standards
Stay current on emerging security threats, vulnerabilities, and controls for the cloud
Working with backend engineering teams on architecting, profiling, and monitoring high-performance high availability product components as microservices, providing mission-critical real-time functionality on the control plane of mobile and fixed networks
Evolving the infrastructure and keeping our stack up to date with the latest technologies
WE OFFER
Flexible schedule with a possibility to work from home
Yearly bonus
Paid Lunches
Private Medical Insurance
Company covers accountant assistance expenses
ZUS Coverage
Unlimited sick leaves
21 working days of vacation, public holidays
Trainings and workshops
Required profile
Experience
Level of experience:Senior (5-10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.