About the vacancy
The role focuses primarily on integrating security into software development, reviewing code and architecture, and securing CI/CD pipelines. The position also includes cloud, infrastructure, Blue Team, network security, and compliance activities.
Responsibilities
- Join planning sessions, lead threat modeling, and review security-critical pull requests as a collaborative partner.
- Continuously assess the codebase, prioritizing authentication, authorization, cryptography, API security, and sensitive data handling.
- Introduce and maintain SAST, dependency scanning, secret detection, and other automated security checks across CI/CD pipelines.
- Secure build and deployment pipelines through code signing, access controls, and supply chain integrity measures.
- Manage vulnerabilities from triage through coordinated remediation and verification.
- Build a security-conscious engineering culture through code reviews and knowledge sharing.
- Partner with the CISO on gap analysis between security standards and cloud infrastructure practices, and drive improvements.
- Support Blue Team operations by contributing to log management, detection rules, and alert investigation through SIEM and observability platforms.
- Maintain edge and network security configurations, including Cloudflare WAF, rate limiting, and access rules.
- Contribute to security policies and compliance efforts for employee devices and frameworks such as ISO 27001, SOC 2, and DORA.
Conditions
- Location: Prague or Remote
- Salary: Competitive