logo[мetahunt]
> DOU
senior

Security Engineer

Svitla Systems
type:Full-timecompany:Outsource
cisspcehci/cdkuberneteswafapi gatewaythreat modelingpythonbashjavanode.jsc#.net
experience5+ years
domainLogistics
locationUkraine (Kyiv, Lviv)
> full description

Svitla Systems Inc. is looking for a Senior Application Security Analyst for a full-time position (40 hours per week) in Ukraine. Our client is a Canadian courier and package delivery company. The company delivers nearly 500,000 parcels daily across Canada thanks to a technological platform offering more than 3500 optimized routes to almost 500 independent delivery employees. The company’s services are provided via a digital order tracking platform that lets suppliers and logistics service dealers accept bulk orders, track parcel delivery routes, check and communicate shipment details, manage bills and invoices, and fasten the cargo shipment processes by partnering with certified transporters, enabling clients to request and enjoy secured transportation of their parcels and cargos by being able to track them in real-time. The client’s customers include Amazon, Pitney Bowes, and Landmark Global, which handle shipping for Etsy and eBay.

You will join a team to contribute to the continuous improvement of the application security practice in a dynamic, growing organization. You will work in an environment where ideas are welcomed, contributions are recognized, and cross-functional collaboration enables teams to achieve ambitious outcomes. If you are motivated to drive change and partner with developers, DevOps, system administrators, architects, and cybersecurity stakeholders, we would like to hear from you.

Requirements:

  • Degree in computer science, 5 to 10+ years of experience or an equivalent combination of training and experience.
  • Security Certification(s) required: CISSP, CSSLP, CEH, OSCP, GIAC, or demonstrated equivalent security knowledge and experience.
  • Cloud or Vendor specific security certification(s) or demonstrated equivalent security knowledge and experience.
  • Hands-on security experience with implementation and support of CI/CD pipelines, Secret Management solutions, Image Management, Service Mesh, WAF, Cloud Firewall/rules management, Kubernetes, Container security, API gateway, Cloud Workload Protection & Cloud Posture, IaC, Compliance as Code, GitOps.
  • Hands-on experience with security testing, secure coding, training and secure product design.
  • Hands-on experience with security automation and incident response.
  • Strong understanding of APIs, web services, and modern software architecture.
  • Knowledge of scripting: Python, Bash.
  • Knowledge of development languages: At least one or two of the following: Java, Node.JS, C#, .Net.
  • Strong understanding of secure design and threat modeling methodologies.
  • Knowledge of information security risks, frameworks, regulatory requirements and industry best practices.
  • Familiarity with network protocols and cloud networking; good understanding of the network threat landscape.
  • Expert problem-solving skills and advanced interpersonal and communication skills.
  • Autonomous, with strong time management skills.
  • Broad knowledge of application security, including application development, application testing methodologies, security testing, secure coding, training and secure product design.
  • Broad knowledge of cloud security, including cloud deployment, automation, secure configuration and policies, and cloud security services.

Responsibilities:

  • Bring broad expertise in information security and application security to identify threats, recommend controls, and support business goals.
  • Define, implement, and continuously improve security controls and baseline configurations.
  • Assess control effectiveness across CI/CD pipelines and application platforms (desktop, web, mobile, containers, COTS).
  • Own and evolve application and cloud security services (tool selection, onboarding, configuration, operations, and testing).
  • Serve as the go-to advisor for application security across architecture, engineering, and secure coding practices.
  • Drive security automation and repeatable guardrails throughout the SDLC.
  • Lead threat modeling and secure design activities for key initiatives.
  • Partner with engineering, product, platform, architecture, and business teams to design and implement appropriate security features.
  • Act as a subject matter expert for application and cloud security topics.
  • Make decisions on complex issues and provide direction aligned with application and cloud security best practices.
  • Deliver outcomes with significant autonomy, using creative and practical approaches.
  • Create training materials, guidelines, secure patterns, and documentation.
  • Coordinate and host training sessions, knowledge-sharing forums, and AppSec/CloudSec communities of practice.
  • Mentor and enable stakeholders on web, mobile, API, and cloud security to uplift posture and address technical debt.
  • Advise developer squads on vulnerabilities, secure design, and application security best practices.
  • Educate teams on application and cloud risks, secure configuration, secure coding, and core security concepts.
Відгукнутись на вакансію