- Страна
- Чехия
Откликайтесь
на вакансии с ИИ

Senior Security Engineer
FTMO — успешный и быстрорастущий финтех с отличной репутацией. Вакансия предлагает работу над современным стеком технологий в офисе класса А в центре Праги с сильной корпоративной культурой.
Сложность вакансии
Роль требует глубоких знаний в области безопасности облачных сред (GCP/AWS), автоматизации через IaC и опыта работы от 5 до 10 лет. Высокая планка ожиданий по внедрению стандартов SOC2 и ISO27001 добавляет сложности.
Анализ зарплаты
Зарплата в объявлении не указана, но для позиции Senior Security Engineer в Праге рыночный диапазон составляет от 120 000 до 180 000 CZK в месяц. FTMO как прибыльный финтех обычно предлагает конкурентоспособные условия на уровне верхней границы рынка.
Сопроводительное письмо
I am writing to express my strong interest in the Senior Security Engineer position at FTMO. With over 7 years of experience in infrastructure and security, including a deep focus on cloud security and automation, I am confident in my ability to help FTMO "shift security left" and build a resilient foundation for your global fintech operations. My background in hardening Kubernetes environments and managing complex IAM policies across GCP and AWS aligns perfectly with the technical requirements of your team.
Throughout my career, I have successfully integrated vulnerability scanning into CI/CD pipelines and led incident response activities using the MITRE ATT&CK framework. I am particularly drawn to FTMO's culture of open communication and meaningful work. I am eager to bring my expertise in Infrastructure-as-Code and security standards like SOC2 and ISO27001 to your Prague-based team and contribute to the continued growth of your innovative trading platform.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в ftmo уже сейчас
Присоединяйтесь к лидеру чешского финтеха и создавайте безопасную инфраструктуру будущего в самом сердце Праги!
Описание вакансии
At FTMO, we believe that company growth starts with people. We are a team that pushes forward together, supports one another, and celebrates shared achievements. Our environment creates space for talents to grow – individually, as a team, and across the whole company.
In this role, you will leverage your system administration and security skills to design and maintain robust security controls across our cloud environments, networks, and operating systems. Your core mission is to "shift security left," ensuring that top-notch security practices are baked directly into the foundation of our infrastructure. You will team up with our global infrastructure and operations teams to implement security technologies, harden systems, and build out the best infrastructure security practices possible.
What will be your agenda?
- Write and review Infrastructure-as-Code (like Terraform and CloudFormation) to automate secure infrastructure deployments.
- Lock down and harden operating systems, databases, network devices, and container platforms like Kubernetes.
- Design and roll out cloud security controls across GCP, AWS and Azure, handling everything from IAM to encryption.
- Review network firewall configurations, implement segmentation, and monitor traffic to catch security anomalies.
- Wire security tools (like vulnerability scanners) directly into our deployment pipelines for continuous monitoring.
- Manage logging solutions to detect incidents, and jump into blue team exercises and incident response activities.
- Evaluate and reduce supply chain risks tied to third-party libraries, operating systems, and firmware.
- Partner with Security Analysts to assess risks and ensure our infrastructure stays compliant with standards like SOC2, ISO27001, NIST, etc.
- Champion a strong security culture across teams through training and knowledge sharing.
What do you bring to the table?
- A university degree in computer science, computer engineering, or a related engineering discipline.
- 5 to 10 years of relevant tech experience, including 2 to 3 years specifically in security (with a strong focus on security-driven development and automation).
- Hands-on experience in Security Engineering.
- Solid understanding of major security standards, including SOC2, ISO27001/ISO27002, NIST, OWASP, and SANS.
- Comfortable with cloud security concepts in GCP.
- Proficiency in scripting, ideally using Python or Bash.
- A good grasp of the MITRE ATT&CK framework and how to apply it to threat intelligence and incident response.
- Experience with security testing techniques like SAST, DAST, IAST, and pen-testing frameworks.
- The ability to write clear, concise security standards and strategies to guide the team.
What would be nice to have?
- Experience in the financial or FinTech sector.
- Certifications like CISSP, CISA, CEH, or Security+.
Why join the FTMO team?
- We are a Czech fintech that, since 2015, has grown from an idea into a global project. 🚀
- 300+ amazing teammates. We’re a great team who learn from each other every day.🤜🤛
- How do we work? We focus on meaningful work and open communication, while only adopting processes that make our lives easier.
- Prague, Národní třída. Enjoy our modern offices at the Quadrio shopping center, offering beautiful views and excellent accessibility.
- What if I don’t trade? No worries. We’ll show you what our product is all about and introduce you to the basics of trading.
- Free fruit, snacks, and coffee are always within reach in the office.
- How do we promote strong relationships and well-being? Company cottage, team building events, and running club.
- We prefer working from the office. We believe you will feel right at home at our Quadrio Offices.
\The benefits mentioned above apply to on-site employees in our Prague office.*
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- AWS
- Azure
- Python
- Terraform
- GCP
- ISO 27001
- Kubernetes
- Bash
- NIST
- SOC2
- OWASP
- CloudFormation
- MITRE ATT&CK
- SAST
- DAST
- IAST
Возможные вопросы на собеседовании
Проверка практического опыта автоматизации безопасности.
Расскажите о вашем опыте внедрения проверок безопасности в CI/CD пайплайны с использованием Terraform или CloudFormation.
Оценка навыков защиты облачной инфраструктуры.
Как бы вы организовали управление доступом (IAM) и сегментацию сети в мультиоблачной среде (GCP/AWS) для минимизации рисков?
Проверка знаний методологий реагирования на инциденты.
Как вы используете фреймворк MITRE ATT&CK при планировании мониторинга и реагирования на инциденты?
Оценка опыта работы с комплаенсом.
Какие основные контроли безопасности вы бы внедрили в первую очередь для подготовки инфраструктуры к сертификации SOC2 или ISO27001?
Проверка навыков обеспечения безопасности цепочки поставок.
Каким образом вы оцениваете и минимизируете риски, связанные с использованием сторонних библиотек и Open Source компонентов?
Похожие вакансии
Senior Information Security (ИБ)
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Сеньор AppSecOps-инженер
Старший эксперт SIEM
Старший инженер внедрения SIEM
Senior Security Auditor
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Чехия