Cossack Labs — вакансії

  • Product / Startup
  • 11-50
  • 2014
  • Київ, Львів, London
  • Blockchain / Crypto, CyberSecurity, SaaS, Software Development & Hi-Tech

Актуальні вакансії компанії

Досвід не має значення Lead Full-time Не має значення Є тестове завдання Office, Remote Київ
25.09.20244
Детальніше
  • OWASP
  • MITRE Att&ck
  • API

Cossack Labs is looking for an Security Solutions Architect to join our Security team and work with us on building secure software and solutions for our customers. If you are interested in designing and building security solutions that address complex risks and threats, reviewing and implementing API protocols and subsystems, designing security controls, working hand-in-hand with software developers to build secure systems – this may be the position for you.
Markets: EU, UK, USA.

You will:

  • Architect security features, modules and protocols in mission critical software, ensuring alignment with business objectives, functional and non-functional requirements.
  • Assess and evaluate the security design of systems, components and their API.
  • Search for security weaknesses in software designs from novel fields and areas.
  • Perform risk analysis and threat modelling to evaluate available and missing security controls.
  • Collaborate with stakeholders, including developers, product managers, and executives, to gather requirements and translate them into security architecture.
  • Participate in SSDLC for our products and our customers’ products. Explain architecture choices, work together with developers to select security controls that would improve security without restricting usability/performance.
  • Stay up to date with emerging security threats, vulnerabilities, and controls (read articles and papers, follow CVE updates, understand how threat landscape is changing, understand how to apply described ideas, read NIST guidelines).
  • Dive into application security, infrastructure security, cloud and on-prem infrastructures, dedicated hardware, IoT security, ML security, and weird stuff beyond casual imagination with our team of skilled engineers. See example of our work.
  • Share your work as conference talks, blogposts (see React Native security example, contribute to open source standards like OWASP.

We would expect you to have:

  • Experience designing and implementing security controls in a technically diverse environment.
  • Experience in performing design review and architecture for multi-component systems (web, cloud, hardware).
  • Understanding security standards and methodologies (NIST, ISO, CMMI, SOC).
  • Understanding SSDLC and its difficulties. OWASP SSDLC, NIST SSDF.
  • Communication skills: you will communicate about security technical topics with both technical and non-technical audiences (C-level managers, developers, product owners).
  • An overall understanding of what information security is, how real-world risks and threats affect the choice of security controls. How to combine detective, preventive and corrective controls.
  • Experience in popular security tools required for the job, or ability to learn them quickly.

As a plus you’d have:

  • Understanding risk management and threat modelling (NIST RMF, FAIR, STRIDE, MITRE ATT&CK).
  • Understanding of application security verification and software maturity frameworks: OWASP SAMM, OWASP ASVS, OWASP MASVS.
  • A certain area of expertise and deep interest: web, cloud, IoT, infrastructure – an area where you have “seen things” and ready to share experience.
  • Experience with clouds: AWS, Azure, GCP, understanding the "cloud responsibility gap".
  • Basic knowledge in cryptography: understanding the differences between symmetric and asymmetric cryptography, hashing, KDF.
  • Knowledge in one of several business domains: banking/finance/payment processing, cryptocurrencies.
  • Practical experience in any programming language.
Відгукнутися
Досвід не має значення Middle Full-time Не має значення Є тестове завдання Office, Remote Київ, Львів
25.09.20244
Детальніше
  • Linux
  • Bash
  • Python
  • Ruby
  • Rust
  • С/С++
  • Golang
  • Docker
  • KVM
  • IaC
  • PostgreSQl
  • MySQL
  • CI/CD
  • AWS
  • GCP
  • Microsoft Azure

This vacancy is exclusively for Ukrainian residents within Ukraine (preferably Kyiv or Lviv).

We are seeking a DevSecOps Engineer to join our Infrastructure Team. We have already hired two new team members and are ready to hire two more as part of our expansion plan. Whether you are a junior engineer just starting your career or a middle-level professional looking to take the next step, we are excited to hear from you.
We are ready to invest time in your education if you are prepared to work diligently and responsibly. In this role, you can evolve into a modern Security Infrastructure Engineer, Site Reliability Engineer, or Solution/Cloud Architect based on the tasks and challenges that captivate you. Our Infrastructure Team provides software and hardware solutions for mission-critical projects, including power grid operators, payment processors, legal firms, and applications with millions of users, so we have many challenging tasks that will offer you opportunities to grow and develop.
Our software is well-known amongst security-aware teams, recommended by OWASP, and popular for easily solving complicated security challenges. Apart from building "off-the-shelf" solutions, we design custom security controls for novel problems.
Markets: EU, UK, USA.

You will:

  • Plan, build, and maintain infrastructure for internal, developer, customer, and R&D purposes.
  • Design and implement hardened systems.
  • Participate in security assessments.
  • Enhance SSDLC for our products.
  • Participate in formulating internal procedures, standards, and workflows.

We would expect you to have:

  • Good knowledge of Linux systems and networking.
  • Understanding of main Internet systems and services.
  • Solid skills in programming in at least two scripting languages: Bash/Python/Ruby.
  • Basic experience in at least one of the non-scripting languages: C/C++/Go/Rust.
  • Understanding of software development key principles and lifecycle.
  • Basic knowledge of main cryptography and security protocols, algorithms, approaches and instruments.
  • Familiarity with Docker and KVM.
  • Familiarity with IaC tools and approaches.
  • Basic troubleshooting skills.
  • Some experience with at least one of PostgreSQL/MySQL.

As a plus you’d have:

  • Deep Linux architecture understanding.
  • Knowledge of advanced networking.
  • Advanced virtualisation skills.
  • Familiarity with cloud platforms.
  • Advanced knowledge of monitoring approaches and technologies.
  • CI/CD, packaging experience.
  • Practical experience with bare metal and IoT devices (RPi and others).

You’ll feel comfortable working with us if you:

  • Understand the importance of fundamental knowledge.
  • Prefer to do well once than constantly generate monkey patches.
  • Prefer finding and reading reference documentation before seeking assistance.
  • Don’t mind writing good technical documentation, even if you don’t particularly enjoy writing.
  • Determined for long-term cooperation.
  • Embrace healthy perfectionism, appreciate aesthetics, and possess a good sense of humour.

Technical stack:

  • Operating Systems: Linux Debian (mostly), RHEL, Alpine, and other Linux distributions for niche solutions (no MS products).
  • Virtualisation: KVM, Docker.
  • Monitoring: Prometheus, Elasticsearch.
  • IaC: Ansible, Chef, Terraform.
  • Languages: Bash, Python, Ruby, Go, Rust.
  • Databases: PostgreSQL (mostly), MariaDB/MySQL.
  • Dedicated server clusters in different DCs.
  • Clouds: AWS, GCP, Azure.
Відгукнутися

Переваги для співробітників Cossack Labs

  • Оплачувані лікарняні
  • Оплачувана відпустка
  • Освітні програми, курси
  • Регулярний перегляд зарплатні

Читайте нас в Telegram, щоб не пропустити анонси нових вакансій.