villacarte group

Senior Information Security Engineer (Figma)

Priority #1 for this role: close the gaps our recent external audit found, then keep pushing our attack surface tighter from there, so our websites and client portals stay up and untampered, our email domains can't be used to scam people,…

villacarte group · На сервисе с: 28.09.26 16:44

Зарплата не указанаРоссияКазахстанУфаАлматыНовосибирскУдалёнка
Локации (удалёнка):УфаАлматыНовосибирск

Удалённая работа — географически не привязана. Щёлкни по любой из локаций, чтобы открыть оригинальную карточку.

About the Role

Priority #1 for this role: close the gaps our recent external audit found, then keep pushing our attack surface tighter from there, so our websites and client portals stay up and untampered, our email domains can't be used to scam people, and our data doesn't walk out the door. No security posture is ever fully "done", what we want is someone who keeps this at the top of their list, not squeezed in between other things.

We're hiring a Senior Information Security Engineer to own the external security of our company websites and client-facing portals, our email domains, and our data. You'll work closely with our DevOps team (who own infrastructure execution) and our in-house developers (who own application code) to get fixes shipped, and you'll run our external pentest/audit program as the outside check that it's actually working.

There's a secondary layer of work too (access governance across our ~40-service SaaS portfolio, evaluating security tooling). You own that as far as your bandwidth allows. If it starts eating into the primary mission, that's your signal to make the case for hiring someone under you, not to let either side slip.

Reports to: CIO

Key Responsibilities

Priority #1: close and keep closing the external attack surface

  • Own the security and integrity of our public websites and client-facing portals: hardened access to DNS/CDN/hosting panels so changes can't happen outside a controlled process, removal of wildcard DNS records, closing of exposed admin/API endpoints
  • Stop email spoofing and account takeover: SPF and DMARC on every company domain, moved all the way from p=none to p=reject, with DKIM verified for every sending system (Google Workspace, Zoho, SendPulse, and others), plus enforced 2FA/phishing-resistant login and anomalous-login monitoring on Google Workspace, especially for sales staff. This is what actually stops the costliest scenario for a real estate business: someone hijacking a live deal thread to redirect a client's wire transfer
  • Prevent data theft: get secrets out of client-side code, add CAPTCHA and rate limiting on public forms, enforce HTTPS/HSTS and secure cookie flags, and lock down access to the systems that actually hold sensitive data (our CRM's client and deal records, HR data, financial systems, and our password vault): admin account audits and 2FA there are core to this mission, not an afterthought
  • Keep an eye out for signs that client or business data is being accessed or exfiltrated anywhere in the above
  • Partner with DevOps on CDN/WAF-level controls, and with developers on application-level fixes. You set the requirement and drive it to closure; they usually hold the keys to the actual change
  • Scope, select, and manage external pentest and security audit vendors: this is your outside check that the attack surface is actually closed, not just believed to be closed

Secondary scope (own it if you have the bandwidth; justify a hire if you don't)

  • Security governance of the rest of our third-party SaaS portfolio (~35 lower-sensitivity tools: Zoom, Miro, Figma, Adobe, Dropbox, and similar): who holds admin accounts, 2FA adoption, risky configurations
  • Assess whether we need to invest in SIEM, DLP, EDR, or something else, and build the business case if you think we should. We're not pre-committed to any tool; this is your call to make and defend when you have time for it

Requirements

  • 5+ years in information security or security engineering, with a track record of actually closing attack-surface issues (DNS/email spoofing, exposed secrets, unpatched perimeter gaps), not just reporting on them
  • Practical, hands-on experience with email/domain authentication (SPF/DMARC/DKIM), TLS/HSTS, and web security headers
  • Experience hardening Google Workspace (or similar) against account takeover: 2FA/phishing-resistant auth, anomalous-login monitoring, and locking down admin access to high-value systems (CRM, HR, finance)
  • Experience finding or driving remediation of real-world web application weaknesses: exposed secrets, missing CAPTCHA/rate limiting, CORS and header misconfigurations
  • Comfortable working cross-functionally with DevOps and developers to get fixes shipped, rather than operating in isolation
  • Experience scoping and managing external security audit or pentest vendors
  • Working knowledge of Linux and Windows, and core networking concepts

Nice to Have

  • Experience governing identity/access across a large portfolio of SaaS tools (2FA rollout, admin account audits)
  • Solid understanding of what SIEM, DLP, and EDR tooling actually solve, and experience building a business case for (or against) adopting one
  • Experience with CDN/WAF platforms (Gcore, Cloudflare)
  • Awareness of data protection/privacy considerations relevant to handling client leads and personal data

What We Offer

  • Fully remote work, or based in Phuket
  • Flexible working hours (start between 8:00 and 11:00, Phuket time)
  • A tightly scoped mandate: reduce and keep closing our external attack surface, with real authority to drive that work through DevOps and development
  • Room to grow a team: if the secondary scope justifies it, make the case and we'll hire under you
  • International team and dynamic environment

Похожие вакансии Кибербезопасность

hh.ru
villacarte group

Senior Information Security Engineer

villacarte groupНа сервисе с: 28.09.26 17:01
Зарплата не указанаРоссияПермьУдалёнка

About the Role

Priority #1 for this role: close the gaps our recent external audit found, then keep pushing our attack surface tighter from there, so our websites and client portals stay up and untampered, our email domains can't be used to scam people, and our data doesn't walk out the door. No security posture is ever fully "done", what we want is someone who keeps this at the top of their list, not squeezed in between other things.

We're hiring a Senior Information Security Engineer to own the external security of our company websites and client-facing portals, our email domains, and our data. You'll work closely with our DevOps team (who own infrastructure execution) and our in-house developers (who own application code) to get fixes shipped, and you'll run our external pentest/audit program as the outside check that it's actually working.

There's a secondary layer of work too (access governance across our ~40-service SaaS portfolio, evaluating security tooling). You own that as far as your bandwidth allows. If it starts eating into the primary mission, that's your signal to make the case for hiring someone under you, not to let either side slip.

Reports to: CIO

Key Responsibilities

Priority #1: close and keep closing the external attack surface

  • Own the security and integrity of our public websites and client-facing portals: hardened access to DNS/CDN/hosting panels so changes can't happen outside a controlled process, removal of wildcard DNS records, closing of exposed admin/API endpoints
  • Stop email spoofing and account takeover: SPF and DMARC on every company domain, moved all the way from p=none to p=reject, with DKIM verified for every sending system (Google Workspace, Zoho, SendPulse, and others), plus enforced 2FA/phishing-resistant login and anomalous-login monitoring on Google Workspace, especially for sales staff. This is what actually stops the costliest scenario for a real estate business: someone hijacking a live deal thread to redirect a client's wire transfer
  • Prevent data theft: get secrets out of client-side code, add CAPTCHA and rate limiting on public forms, enforce HTTPS/HSTS and secure cookie flags, and lock down access to the systems that actually hold sensitive data (our CRM's client and deal records, HR data, financial systems, and our password vault): admin account audits and 2FA there are core to this mission, not an afterthought
  • Keep an eye out for signs that client or business data is being accessed or exfiltrated anywhere in the above
  • Partner with DevOps on CDN/WAF-level controls, and with developers on application-level fixes. You set the requirement and drive it to closure; they usually hold the keys to the actual change
  • Scope, select, and manage external pentest and security audit vendors: this is your outside check that the attack surface is actually closed, not just believed to be closed

Secondary scope (own it if you have the bandwidth; justify a hire if you don't)

  • Security governance of the rest of our third-party SaaS portfolio (~35 lower-sensitivity tools: Zoom, Miro, Figma, Adobe, Dropbox, and similar): who holds admin accounts, 2FA adoption, risky configurations
  • Assess whether we need to invest in SIEM, DLP, EDR, or something else, and build the business case if you think we should. We're not pre-committed to any tool; this is your call to make and defend when you have time for it

Requirements

  • 5+ years in information security or security engineering, with a track record of actually closing attack-surface issues (DNS/email spoofing, exposed secrets, unpatched perimeter gaps), not just reporting on them
  • Practical, hands-on experience with email/domain authentication (SPF/DMARC/DKIM), TLS/HSTS, and web security headers
  • Experience hardening Google Workspace (or similar) against account takeover: 2FA/phishing-resistant auth, anomalous-login monitoring, and locking down admin access to high-value systems (CRM, HR, finance)
  • Experience finding or driving remediation of real-world web application weaknesses: exposed secrets, missing CAPTCHA/rate limiting, CORS and header misconfigurations
  • Comfortable working cross-functionally with DevOps and developers to get fixes shipped, rather than operating in isolation
  • Experience scoping and managing external security audit or pentest vendors
  • Working knowledge of Linux and Windows, and core networking concepts

Nice to Have

  • Experience governing identity/access across a large portfolio of SaaS tools (2FA rollout, admin account audits)
  • Solid understanding of what SIEM, DLP, and EDR tooling actually solve, and experience building a business case for (or against) adopting one
  • Experience with CDN/WAF platforms (Gcore, Cloudflare)
  • Awareness of data protection/privacy considerations relevant to handling client leads and personal data

What We Offer

  • Fully remote work, or based in Phuket
  • Flexible working hours (start between 8:00 and 11:00, Phuket time)
  • A tightly scoped mandate: reduce and keep closing our external attack surface, with real authority to drive that work through DevOps and development
  • Room to grow a team: if the secondary scope justifies it, make the case and we'll hire under you
  • International team and dynamic environment
hh.ru
международный аэропорт внуково

Инженер по системам безопасности (СКУД)

международный аэропорт внуковоНа сервисе с: 23.07.26 14:14↑ Вакансия с автоподнятием
114k–114k ₽РоссияМоскваОфис
Обязанности:
  • Обеспечение работоспособности, настройки и технического состояния систем безопасности объектов;
  • Организация бесперебойной работы систем;
  • Осуществлять внедрение и модернизацию технических систем безопасности;
  • Формировать отчетность СКУД;
  • Оперативное решение по вопросу восстановления работоспособности систем безопасности;
  • Разработка проектов, ТЗ по системам безопасности;
  • Организация и укрепление защиты технических каналов от утечек информации; Составление отчетности по результатам работы и мониторинга систем безопасности;
  • Вносить рекомендации по повышению эффективности систем.
Требования:
  • Опыт работы с слаботочными сетями,Trassir, СКУД Parsec;
  • Знание сетевых технологий (TCP/IP, VLAN, WiFi, маршрутизация);
  • Умение читать и составлять техническую документацию;
  • Защита технических каналов от утечек информации;
  • Разработка проектов и ТЗ по системам безопасности;
  • Знание ИТ структуру (аппаратное и программное обеспечение, данные, организационное обеспечение).
  • Знание ПО Trassir, СКУД Parsec, монтажные навыки СВН, СКУД.
Условия:
  • Официальное трудоустройство с первого дня работы (мы полностью соблюдаем ТК РФ);
  • График работы 5/2 с 09:00 до 18:00;
  • Стабильную официальную заработную плату;
  • Льготное пользование собственным Медицинским центром (включая стоматологию);
  • Интересную работу в развивающейся высокотехнологичной компании.
hh.ru
Г

Специалист по безопасности ИТ-продуктов

газпромнефть-региональные продажиНа сервисе с: 30.06.26 17:31↑ Вакансия с автоподнятием
Зарплата не указанаРоссияСанкт-ПетербургГибрид

Направляем энергию в дело. Мы развиваем цифровую платформу сбытового департамента «Газпром нефти», запускаем IT-проекты и совершенствуем клиентский опыт, чтобы скорые приезжали к людям, промышленные предприятия добывали, а люди успевали по своим делам и путешествовали.

Центр информационной безопасности приглашает IT-инженеров по информационной безопасности. Основная задача – повысить уровень безопасности в существующих и создаваемых системах. Выбирайте преимущества и бонусы работы в стабильной компании, реализуйте себя в масштабных проектах.

РОЛЬ И ЗАДАЧИ В КОМАНДЕ:

  • Выступать в роли специалиста по информационной безопасности для продуктовых, проектных команд.
  • Участвовать в проработке новых продуктов, сервисов и изменений в существующих ИТ-системах с точки зрения информационной безопасности.
  • Анализировать бизнес-задачи и технические решения на предмет соответствия требованиям ИБ.
  • Проводить security review архитектурных и технических решений.
  • Формировать и обосновывать требования ИБ к продуктам, API, веб-приложениям, мобильным приложениям, интеграциям и инфраструктурным компонентам.
  • Участвовать в threat modeling: выявлять ключевые сценарии атак, критичные активы, доверенные границы и возможные точки компрометации.
  • Сопровождать процессы безопасной разработки: от требований и дизайна до тестирования и промышленного запуска.
  • Взаимодействовать с командами разработки, архитекторами, аналитиками, DevOps, владельцами продуктов и смежными подразделениями ИБ.
  • Помогать в разборе инцидентов информационной безопасности и фрода, связанных с продуктами и ИТ-системами.
  • Формировать, систематизировать и тиражировать лучшие практики по Product Security и Application Security.
  • Повышать осведомленность продуктовых и инженерных команд в вопросах безопасной разработки и защиты данных.

НЕОБХОДИМЫЕ ОПЫТ И НАВЫКИ:

  • Высшее техническое образование.
  • Опыт взаимодействия с командами разработки, аналитиками, архитекторами, DevOps и владельцами продуктов.
  • Понимание принципов безопасной разработки приложений и типовых этапов SDLC.
  • Способность объяснять требования ИБ простым языком и аргументировать решения для технических и бизнес-команд.
  • Знание типовых уязвимостей веб-приложений, API, мобильных приложений, операционных систем и прикладного ПО.
  • Понимание способов эксплуатации уязвимостей и подходов к их устранению.
  • Понимание базовых принципов защиты веб-приложений, API, внешнего периметра и микросервисной архитектуры.
  • Понимание принципов работы средств защиты: WAF, IDS/IPS, FW, SIEM, VPN, proxy, DLP, сканеров уязвимостей, антивирусной защиты.
  • Знание основ сетевого взаимодействия: TCP/IP, HTTP/HTTPS, TLS, DNS, REST, SOAP, gRPC, WebSocket.
  • Понимание базовых механизмов защиты операционных систем Windows/Linux, СУБД, веб-серверов и контейнерных сред.
  • Знание современных механизмов аутентификации и авторизации: OAuth 2.0, OpenID Connect, SAML, Kerberos, JWT, MFA.
  • Готовность разбираться в новых технологиях и развиваться в направлении Product Security / Application Security.
  • Знание стандартов и лучших практик в области ИБ: OWASP, CIS, NIST, ISO 27001, PCI DSS, ГОСТ, РД ФСТЭК, законодательство РФ.

МЫ ПРЕДЛАГАЕМ.

Официальные гарантии:

  • Бессрочный трудовой договор.
  • Фиксированная часть вознаграждения обсуждается индивидуально.
  • Годовое премирование по итогам общих достижений и индивидуального результата.
  • ДМС со стоматологией и страхование жизни.

Заботу о сотрудниках:

  • Профессиональное развитие в IT-сообществе лидирующей в отрасли компании.
  • Корпоративный спорт, командные турниры и забеги.
  • Комфортный офис в центре города: капсула сна, лекторий, спортзал, кафе и киноклуб.
  • Семейные мероприятия: праздники и спортивные мероприятия на свежем воздухе.
  • Поддержка волонтерских инициатив сотрудников, экологичного поведения и участие в благотворительных проектах.

Присоединяйтесь к IT-команде департамента региональных продаж «Газпром нефти»!

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.