Откликайтесь
на вакансии с ИИ

Senior Software Engineer, Security
Отличная вакансия для опытного инженера: современный стек (GCP, Go/Python/TS), фокус на автоматизацию и AI, а также высокая степень автономности. Компания демонстрирует быстрый рост и четкое видение продукта.
Сложность вакансии
Высокая сложность обусловлена требованием глубоких знаний GCP, Kubernetes и опыта работы сразу с тремя языками (TypeScript, Python, Go). Роль предполагает полную ответственность за архитектуру безопасности и автоматизацию без наличия SOC.
Анализ зарплаты
Учитывая требования к Senior-уровню и глубокую экспертизу в Cloud Security (GCP), рыночная зарплата для таких ролей в Европе и США значительно выше среднего. Данная позиция предполагает высокую ответственность за архитектуру, что обычно оплачивается по верхней границе рынка.
Сопроводительное письмо
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь уже сейчас
Присоединяйтесь к миссии по созданию самого надежного слоя безопасности и переведите защиту данных на новый уровень с помощью AI и автоматизации!
Описание вакансии
Senior Software Engineer, Security
OUR MISSION AND WHY IT MATTERS
We are on a mission to make humans the strongest security layer.
Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.
We don't just simulate risks. We build the tools that detect and stop them.
WHY THIS ROLE MATTERS
We're growing fast, over 50% year over year, and our security has to scale with the product: through tooling and code, not headcount. There is no manned SOC here and no plans for one.
You will build our security observability: the pipeline that collects, processes and routes security events and logs across our Google Cloud platform, and the detections, alerting and dashboards on top of it. You won't start from zero. Dashboards, audit logging, alerting and a SIEM build-out are underway, and you inherit working security automation: an automated vulnerability triager covering our npm, Maven, Go and Python ecosystems, remediation nudging with CI tests, and the scanning-stack integrations around them. Your job is to take all of it from working to excellent.
WHAT YOU'LL OWN AND DRIVE
\* Own the architecture and outcomes of our security event and log pipeline on GCP, and the detections, alerting and dashboards on top of it, engineered as code: reviewed, tested, deployed through CI/CD.
\* Own and extend our security automation: the vulnerability triager, the remediation nudging automation, and our scanning-stack integrations (GitHub Advanced Security, dependency ownership, issue sync).
\* Build and improve the tooling our GRC function relies on every day.
\* Turn recurring manual security work into code, for example automating our churned-customer data-removal monitoring end to end.
\* Harden our cloud security architecture together with SRE/Platform: trust boundaries, IAM and least privilege, network egress, secrets, infrastructure-as-code.
\* Drive technical decisions and mentor through code review: act as a multiplier who raises the bar on how security software gets built here.
\* Contribute to our agentic security tooling (AI-assisted PR review and security review) alongside the team.
WHAT MAKES YOU THRIVE HERE
You'll probably have at least five years of experience building production software, but we care less about how long you've been active and more about what you've built, how it was built, and why it worked. You are comfortable owning outcomes at system scale, turning ambiguous problems into shipped systems, and influencing how adjacent teams build securely.
You have
\* deep, hands-on experience with Google Cloud: IAM, networking, logging and eventing services, containers and Kubernetes.
\* production experience in at least one of TypeScript, Python or Go, and no fear of the other two. We work in a large monorepo spanning all three.
\* experience building data or event pipelines, observability systems, or detection tooling, and the instinct to treat all of it as software: version-controlled, reviewed, tested.
\* a genuine pull toward security. A security title is not required; an engineer who wants their work to protect things is.
\* AI agents in your daily workflow. We expect you to use modern AI tools everywhere to expand and scale your reach.
WHO YOU'LL WORK WITH
You'll join the Product Security team: a small, high-leverage group whose job is to address any security concern a product team or customer raises. You build the platforms; your teammates run the programs on top of them and cover application security and compliance. You'll work daily with SRE/Platform and the product engineering teams.
WHAT YOU CAN EXPECT FROM US
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- TypeScript
- Python
- Kubernetes
- CI/CD
- IAM
- Google Cloud Platform
- Infrastructure as Code
- Go
- SIEM
- GitHub Advanced Security
Возможные вопросы на собеседовании
Проверка опыта работы с инфраструктурой как кодом и понимания специфики безопасности в облаке.
Как бы вы спроектировали конвейер обработки логов безопасности в GCP, чтобы обеспечить минимальную задержку при обнаружении угроз и соблюдение принципа наименьших привилегий?
Оценка навыков автоматизации и умения работать с уязвимостями в разных экосистемах.
Опишите ваш подход к автоматизации триажа уязвимостей в монорепозитории с использованием различных языков программирования. Как вы минимизируете количество ложноположительных срабатываний?
Проверка готовности кандидата использовать современные AI-инструменты для повышения эффективности.
Как вы интегрируете AI-агентов в свой ежедневный рабочий процесс разработки и как они могут помочь в проведении код-ревью с точки зрения безопасности?
Оценка опыта работы с сетевой безопасностью и контейнеризацией.
Какие стратегии вы используете для ужесточения безопасности сетевого трафика (egress) и управления секретами в кластерах Kubernetes?
Проверка лидерских качеств и умения влиять на процессы в смежных командах.