O pozícii
The role focuses primarily on integrating security into software development, reviewing code and architecture, and securing CI/CD pipelines. The position also includes cloud, infrastructure, Blue Team, network security, and compliance activities.
Responsibilities
- Join planning sessions, lead threat modeling, and review security-critical pull requests as a collaborative partner.
- Continuously assess the codebase, prioritizing authentication, authorization, cryptography, API security, and sensitive data handling.
- Introduce and maintain SAST, dependency scanning, secret detection, and other automated security checks across CI/CD pipelines.
- Secure build and deployment pipelines through code signing, access controls, and supply chain integrity measures.
- Manage vulnerabilities from triage through coordinated remediation and verification.
- Build a security-conscious engineering culture through code reviews and knowledge sharing.
- Partner with the CISO on gap analysis between security standards and cloud infrastructure practices, and drive improvements.
- Support Blue Team operations by contributing to log management, detection rules, and alert investigation through SIEM and observability platforms.
- Maintain edge and network security configurations, including Cloudflare WAF, rate limiting, and access rules.
- Contribute to security policies and compliance efforts for employee devices and frameworks such as ISO 27001, SOC 2, and DORA.
Requirements
- At least 3 years of professional software development experience, including writing production code and understanding how applications are architected and shipped.
- Ability to read and review code with confidence. Experience with Java is preferred; strong proficiency in TypeScript, C#, Go, or another language is also suitable.
- Deep understanding of the OWASP Top 10 and secure coding principles.
- Ability to identify vulnerabilities in practice during code reviews and architecture discussions.
Conditions
- Location: Prague or Remote
- Salary: Competitive