mayflower

DevSecOps

Our team is developing a payment gateway for accepting funds from users on behalf of merchants, as well as sending funds from merchants to users. The system involves storing user payment data and is subject to PCI DSS compliance. It contai…

mayflower · На сервисе с: 05.08.26 11:09

от 5 000 € (≈ от 468k ₽)КипрЛимассолОфис

Our team is developing a payment gateway for accepting funds from users on behalf of merchants, as well as sending funds from merchants to users. The system involves storing user payment data and is subject to PCI DSS compliance. It contains multiple integrations with payment systems, providers, and other gateways and processors, including 3DS.

Job Responsibilities

  • Design, implement, and manage infrastructure with a focus on establishing security controls and ensuring secure configuration, in collaboration with DevOps.
  • Automate cloud operations, ensuring all deployments and configurations conform to security baselines.
  • Implement infrastructure security best practices such as IAM, network security, encryption, and monitoring.
  • Develop and maintain CI/CD pipelines that integrate automated security checks such as SCA and SAST.
  • Implement security monitoring and logging systems using services such as CloudWatch, CloudTrail, AWS Security Hub, and related tooling.
  • Implement and manage security alerting mechanisms, ensuring timely detection of and response to security incidents.
  • Apply security best practices in daily operations, including password management, phishing prevention, and security evaluation of new solutions.
  • Conduct security assessments and periodic reviews as mandated by PCI DSS, ensuring continuous maintenance of processes such as vulnerability and change management.
  • Manage and control access across various services.
  • Prepare for and actively participate in PCI DSS audits, ensuring controls and evidence are in place.
  • Collaborate with development, operations, and security teams to promote a culture of shared security responsibility across all stages of the system lifecycle.
  • Train and advise team members on DevSecOps principles and secure engineering practices.
  • Participate in task definition, estimation, and prioritization, and contribute to planning activities on weekly, monthly, quarterly, and annual horizons.
  • Continuously optimize AWS infrastructure for security, performance, scalability, and cost efficiency.
  • Maintain clear documentation and provide regular reports on security posture, audit readiness, and operational metrics.

Important and Challenging Tasks

  • Preparation for and participation in PCI DSS audits.
  • Ensuring infrastructure compliance with high security standards.
  • Continuous improvement and optimization of infrastructure and security processes.

Technology Stack

  • AWS (WAF, Shield, GuardDuty, Security Hub, KMS, Secrets Manager, Inspector, etc.).
  • Kubernetes, Docker, Helm.
  • Terraform, Terragrunt, OpenTofu.
  • GitLab CI/CD.
  • SAML, SSO, MFA.
  • ELK Stack, CloudWatch, CloudTrail.
  • Linkerd.

Job requirements

You’ll thrive here if you have:

  • 3+ years of experience with Cloud infrastructure.
  • Proficiency in DevSecOps tools and methodologies, including CI/CD, containerization (Docker), and orchestration (Kubernetes).
  • Knowledge and application of security best practices in cloud environments, particularly AWS.
  • Understanding of PCI DSS requirements and experience implementing and maintaining compliance in AWS.
  • Experience implementing security controls and monitoring for AWS (AWS WAF, Shield, GuardDuty, Control Tower, Security Hub, CloudTrail Insights, KMS, CloudHSM, Macie, Secrets Manager, Inspector).
  • Experience with logging and monitoring tools (AWS CloudWatch, ELK).
  • Deep understanding of networking concepts and protocols, including VPNs, firewalls, and load balancers.
  • Experience with security groups and IAM in AWS.
  • Experience with Helm.
  • Experience with SAML authentication configuration.
  • Experience with SSO solutions.
  • Knowledge of encryption techniques and key management.
  • English proficiency at B1 level or higher.

Preferred Qualifications:

  • AWS certifications (AWS Certified Solutions Architect, AWS Certified Security – Specialty).
  • Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP).
  • Experience implementing a DevSecOps culture within an organization.
  • Knowledge of security champion programs and security training for development teams.
  • Experience with Terraform / OpenTofu and Terragrunt.
  • Knowledge of the CKS (Certified Kubernetes Security Specialist) certification program.
  • Knowledge of GitOps (Helmfile / ArgoCD / FluxCD).
  • Experience with service mesh (Linkerd).

Conditions

We know that great talent deserves great conditions, so here's what you can expect when joining us:

  • EU-based employment contract and a 3-year Cyprus work visa with full support for your relocation and visa processes, including assistance for your family.
  • EU passport. Opportunity to obtain an EU passport after 4 years of residence.
  • Full relocation package: flights to Limassol for you and your family, a company-covered apartment for the first month, and full relocation support to make your move smooth and hassle-free.
  • Provident fund (Cyprus): a long-term savings plan co-funded by you and the Company together (available after probation) that grows throughout your time with us in Cyprus.
  • Transparent performance reviews twice a year, with bonus opportunities and salary adjustments.
  • Private medical insurance for you and your family.
  • Corporate mobile plan (unlimited in Cyprus with roaming included).
  • Mindfulness & well-being support, including psychological assistance with 50% coverage.
  • 50% coverage of school and kindergarten fees for your children.
  • Fully covered sports benefits, and also access to in-house electric scooters and bike rentals.
  • Professional growth support: language courses, conferences, training programs, and coaching.
  • Peer recognition program: receive and share kudos for great work.
  • A fully equipped office in Limassol’s city center, with everything you need for deep work and collaboration.
  • Free breakfasts and lunches in the office and an in-house coffee bar with high-quality drinks and a health bar stocked with nutritious snacks.
  • A strong engineering culture: international teams, corporate events, team buildings, and hackathons — because great work happens in great communities.

Recruitment process

  • HR interview (40 min).
  • Technical interview (1.5 hour).
  • Final interview.
  • Recommendations check.
  • Job Offer.

Похожие вакансии Кибербезопасность

hh.ru
лига цифровой экономики

Инженер информационной безопасности

лига цифровой экономикиНа сервисе с: 12.08.26 13:45↑ Вакансия с автоподнятием
Зарплата не указанаРоссияМоскваОфис

Проекты по эксплуатации распределенной инфраструктуры гос. заказчиков в части обеспечения информационной безопасности

Твои задачи:

  • Администрирование и сопровождение средств защиты информации
  • Участие в процессе внутренней безопасности подразделения
  • Опыт работы с ОС семейства Windows и Linux
  • Будет плюсом опыт работы со средствами антивирусной защиты (например, Kaspersky), SIEM, системами контроля привилегированных пользователей (например, СКДПУ), реагирования на инциденты ИБ (например, R-Vision) и сканерами уязвимостей (например, MaxPatrol 8 / MaxPatrol VM).
  • Опыт работы с системами виртуализации (например, VMware/VirtualBox) и системами мониторинга (Zabbix или др.)
  • Знание актуальных техник и тактик кибератак, а также нормативной базы по ИБ (приказы ФСТЭК № 21, 117 и 239).
    Теоретические и практические знания сетевых технологий (TCP/IP, VLAN, Routing, Troubleshooting)
  • Навыки автоматизации процессов (написание скриптов, например Python и Bash)

Что мы обеспечим:

  • Технику для комфортной работы
  • ДМС, частичную компенсацию фитнеса, доступ к сервису корпоративных скидов, внутренние обучение и многое другое
  • Работу в профессиональной среде, состоящей из высококлассных экспертов, которая позволит тебе быстро расти как эксперту
  • Ежегодные сессии профессионального развития, результатом которой является план индивидуального развития каждого сотрудника и получение обратной связи
  • Сообщества по интересам: Лига Спорта, Лига Творчества, Лига Интеллекта и др., а также возможность организовать свое сообщество и получить поддержку от компании
Соц.сети
C
Зарплата не указанаРоссияМоскваГибрид

Руководитель группы дежурных аналитиков SOC

Локация: #Москва (гибрид)
Зарплата: ₽. Обсуждается на собеседовании.
Компания: ••••••••

Обязанности:
• Операционное управление сменой:

— Организация сдачи/приёмки дежурств
— Контроль укомплектованности и графика дежурств
— Распределение нагрузки между дежурными аналитиками
— Мониторинг и соблюдение KPI и SLA

• Управление инцидентами в зоне ответственности команды:
— Управление обработкой инцидентов в системе IRP и JiraSM
— Обеспечение эскалации инцидентов на команду CERT

• Работа с командой:
— Менторство и обучение команды L1
— Контроль метрик и качества работы дежурных аналитиков
— Распределение проектных задач и контроль за их выполнением
— Общее управление командой, проведение 1:1

• Коммуникации и отчётность:
— Формирование отчётностей по итогам смен
— Оперативное уведомление заинтересованных лиц об инцидентах
— Взаимодействие с другими подразделениями компании в своей зоне ответственности

• Технические и процессные задачи:
— Ведение базы знаний и документации подразделения
— Участие в создании контента SOC в своей зоне ответственности
— Тюнинг системы мониторинга, настройка исключений и фильтров

Требования:
• Глубокое понимание киберугроз, методов атаки и принципов работы сетей/систем
• Способность ясно мыслить и принимать решения при критических инцидентах
• Знание модели Kill Chain, фреймворка MITRE ATT&CK и цикла обработки инцидентов SANS Incident Response (SANS IR)

••••••••

#Гибрид

hh.ru
В

Специалист по информационной безопасности

винити ранНа сервисе с: 24.09.26 17:31
140k–160k ₽РоссияМоскваОфис
Обязанности:
  • организация категорирования объектов КИИ и актуализация результатов;

  • подготовка пакета организационно-распорядительных документов по защите информации (Приказ о назначении ответственных, Политика ИБ, Инструкции для администраторов и пользователей);

  • организация регистрации и реагирования на компьютерные атаки;

  • выдача УКЭП, МЧД, настройка работы в различных ГИС;

  • внедрение и эксплуатация программных и аппаратных средств информационной безопасности.

Требования:
  • высшее образование по специальностям «Информационная безопасность», «Компьютерная безопасность» или смежным техническим специальностям (информатика, вычислительная техника);
    - профессиональная переподготовка: наличие дипломов о профессиональной переподготовке по программам в области защиты информации (объем не менее 500 часов);
    - стаж в сфере обеспечения ИБ: от 3 лет.
    Опыт в организации защиты объектов КИИ или в государственных НИИ. Взаимодействие с регуляторами. Глубокое знание № 187-ФЗ, 149-ФЗ, 152-ФЗ, 63-ФЗ и др. Понимание категорирования объектов КИИ, разработки моделей угроз, создания Систем обнаружения атак.
  • Желательно наличие сертификатов: CISA, CISM, CISSP (международные); «Специалист по защите информации» (национальный стандарт).

Условия:
  • оформление по ТК РФ;

  • ежегодный оплачиваемый отпуск 28 дней;

    расположение: 5 мин. от м. Сокол;

    испытательный срок: 3 месяца;

    бесплатная парковка для сотрудников;

    полный соц. пакет.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.