SOFTSWISS logo
SOFTSWISS

Winning combination of software products for iGaming

Infrastructure Security – Tech Lead

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

Poland

Posted

65 days ago

Salary

0

Seniority

Senior

Job Description

Infrastructure Security – Tech Lead

SOFTSWISS

• Define technical direction and architectural decisions across all Infrastructure Security domains • Lead security infrastructure reviews for new and existing systems • Develop and maintain technical standards, security policies, and security baselines across domains • Own the Vulnerability Management process across infrastructure domains • Technical growth and mentorship of team members • Act as Tier 3 technical escalation point during Incident Response

Job Requirements

  • 7+ years in infrastructure security, including 3+ years in a Architector or Lead role
  • Strong investigative and analytical problem-solving skills
  • Practice in building security processes in the corporate environment
  • Deep hands-on experience with at least one major cloud provider (AWS, GCP, or OCI) focused on security services
  • Hands-on Linux system administration expertise
  • Server hardening expertise: CIS Benchmarks, DISA STIG, immutable OS concepts (e.g., Talos Linux)
  • Proficiency in IaC tooling: SaltStack and Terraform
  • Deep expertise in Kubernetes security: RBAC, Pod Security Standards, Admission Controllers, NetworkPolicy
  • Experience in development and automation (Python/Go)
  • Experience in SQL, ESQL/DSL (ElasticSearch)
  • Experienced in technical mentorship and task decomposition for teammates
  • Strong knowledge of Common Secure Network Architectures, Firewalls, IDP/IPS environments
  • Hands-on experience designing and implementing Zero Trust Architecture (ZTA)
  • Structured written and oral communication to ensure clarity
  • Ability to formalise security requirements into policies, standards, and control frameworks
  • Familiarity with enterprise security architecture frameworks (TOGAF/SABSA)
  • Upper Intermediate or higher English level.

Benefits

  • Full-time remote work opportunities and flexible working hours
  • Private insurance
  • Additional 1 Day Off per calendar year
  • Sports program compensation
  • Comprehensive Mental Health Programme
  • Free online English lessons with a native speaker
  • Generous referral program
  • Training, internal workshops, and participation in international professional conferences and corporate events.

Related Categories

Related Job Pages

More Security Engineer Jobs

GoDaddy logo

Security Engineer - Vulnerability Management

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a

Location Details: Remote, India At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings Join Our Team... GoDaddy’s Vulnerability Management team, part of the Information Security organization, is responsible for maintaining strong security hygiene and driving high-impact initiatives that improve transparency and strengthen our overall security posture! We are looking for a Vulnerability Management Engineer to develop the architecture and capability roadmap that supports the strategic goals of GoDaddy Global Security. In this role, you will work closely with cross-functional teams to find vulnerabilities across our global infrastructure. You will assist in fixing these issues, support internal partners, and help protect GoDaddy’s growing attack surface as the company expands. What you'll get to do... - Craft and implement security solutions to identify risks, build capability roadmaps, and secure GoDaddy’s infrastructure—both cloud and on-prem—through vulnerability scanning, perimeter validation, and remediation support - Conduct detailed vulnerability assessments, impact analysis, and perimeter scanning using tools like Tenable and Qualys; validate results and provide actionable recommendations and mitigation plans - Monitor and report data for the Vulnerability Management Program from internal and external sources - Collaborate with compliance teams to ensure appropriate scanning, testing, reporting, and mitigation efforts meet compliance standards, while also supporting validation of false positives and user remediation efforts - Drive process maturity and automation by developing policies, tools, practices, and partnerships to enhance security operations and improve efficiency and throughput - Provide leadership and mentorship to team members while maintaining updated knowledge on evolving threat landscapes, attacker techniques, and effective countermeasures Your experience should include... - 5+ years of experience in vulnerability management within mid-to-large IT organizations, especially in cloud environments; proven track record in security risk assessments, web and network vulnerability scanning, reporting, and threat modeling - Strong hands-on experience with AWS Cloud security, including defining and implementing security controls; In-depth knowledge of desktop and server OS like RedHat/CentOS Linux and Windows Server - Conducting detailed vulnerability assessments, impact analysis, perimeter scanning using tools like Tenable and Qualys, and identifying and remediating zero-day vulnerabilities and other critical risks - Experience crafting automated security solutions using scripting or programming languages such as Python, Shell/BASH, Ruby, Java, C/C++, Perl. - Ability to craft and implement security solutions, identify risks, and build capability roadmaps - Proficient in tracking/reporting key vulnerability management metrics, monitoring threats, collaborating with compliance teams for scanning/testing/reporting, supporting user remediation and false positives; skilled in tools like Microsoft Office Suite, Jira, ServiceNow You might also have... - Bachelor’s Degree in a relevant field or equivalent work experience - Expert in designing and implementing vulnerability management controls aligned with major security standards (CIS, PCI-DSS, NIST, ISO 27001) - Familiarity with CVSS, CWE, and vulnerability scoring methodologies - Experience with Tanium and BurpSuite tools - Hands-on experience in penetration testing - AI-related security experience or knowledge We've got your back...  We offer a range of total rewards that may include paid time off, retirement savings (e.g., 401k, pension schemes), bonus/incentive eligibility, equity grants, participation in our employee stock purchase plan, competitive health benefits, and other family-friendly benefits including parental leave. GoDaddy’s benefits vary based on individual role and location and can be reviewed in more detail during the interview process. We also embrace our diverse culture and offer a range of Employee Resource Groups (Culture). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way. We encourage you to apply even if your experience or skillset doesn’t align perfectly with every requirement. We value a wide range of backgrounds and transferable skills, and we are excited to support learning and growth. About us... GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. GoDaddy is the place people come to name their idea, build a professional website, attract customers, sell their products and services, and manage their work. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. To learn more about the company, visit About Us. At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences and perspectives. But we also know that’s not enough to build true equity and belonging in our communities. That’s why we prioritize integrating diversity, equity, inclusion and belonging principles into the core of how we work every day—focusing not only on our employee experience, but also our customer experience and operations. It’s the best way to serve our mission of empowering entrepreneurs everywhere, and making opportunity more inclusive for all. To read more about these commitments, as well as our representation and pay equity data, check out our Diversity and Pay Parity annual report which can be found on our Diversity Careers page. GoDaddy is proud to be an equal opportunity employer. GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. Refer to our full EEO policy. Our recruiting team is available to assist you in completing your application. If they could be helpful, please reach out to myrecruiter@godaddy.com. GoDaddy doesn’t accept unsolicited resumes from recruiters or employment agencies.

India
Job Closed
Full TimeRemoteTeam 10,001+Since 1978H1B No Sponsor

• Provide enterprise-wide thought leadership and architectural direction for Identity and Access Management (IAM). • Shape Home Depot’s AI identity strategy and maturity. • Partner with cybersecurity, engineering, architecture, and operations teams.

United States
$170K - $190K / year
Job Closed
ICF logo

Computer Security Systems Specialist

ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, en

Description The Work: ICF is looking for an enthusiastic Computer Security System Specialist to join our team. If you are interested in designing, implementing, and managing enterprise security systems to protect organizational networks, systems, and data from cyber threats, then this may be the role for you. Job Location: This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses, and also prohibits personal VPN connections. - You may be asked to travel once a quarter to an office. - Our core work hours are 10am - 4pm Eastern Time with the option to start earlier or work later depending on your time zone. What You Will Do: - Design, implement, and maintain enterprise security solutions such as firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection, and security monitoring platforms. - Monitor networks and systems for security threats and lead investigations of suspicious activities or incidents. - Conduct vulnerability assessments, risk analyses, and penetration testing to identify and remediate security weaknesses. - Lead incident response efforts, including containment, eradication, recovery, and post-incident analysis. - Develop, implement, and enforce information security policies, procedures, and standards. - Manage and optimize Security Information and Event Management (SIEM) systems and other security monitoring tools. - Collaborate with IT infrastructure, application, and cloud teams to ensure secure system architecture and deployments. - Support regulatory compliance initiatives and security audits (e.g., internal or external). - Provide guidance and mentorship to junior security analysts and IT staff on cybersecurity best practices. - Research emerging cybersecurity threats, vulnerabilities, and mitigation strategies to proactively strengthen defenses. - Participate in security awareness initiatives and training programs across the organization. What You Will Bring With You: - Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field from an accredited university. - 5+ years of experience in information security, cybersecurity operations, or network security. - Strong knowledge of network security, system hardening, encryption, authentication, and access control mechanisms. - Hands-on experience with security technologies such as SIEM, IDS/IPS, firewalls, endpoint detection and response (EDR), and vulnerability management tools. - Experience investigating and responding to cybersecurity incidents. - Strong analytical, troubleshooting, and problem-solving skills. - Ability to communicate technical security concepts to both technical and non-technical stakeholders. - Candidate must be able to obtain and maintain a Public Trust - Candidate must reside in the U.S., be authorized to work in the U.S., and all work must be performed in the U.S. What We Would Like You To Bring With You: - Professional certifications such as CISSP, CISM, CEH, CompTIA Security+, or GIAC certifications. - Experience with cloud security platforms (AWS, Azure, or Google Cloud). - Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS Controls, or SOC 2. - Experience with automation or scripting (Python, PowerShell, Bash) for security operations. - Knowledge of DevSecOps or secure software development practices. Professional Skills: - Highly effective analytical, problem-solving, and decision-making capabilities. - Excellent communication and interpersonal skills to interface effectively at all levels of the business. #DMX-HES #Li-cc1 #Indeed Working at ICF ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy. We will consider for employment qualified applicants with arrest and conviction records. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.  Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. Candidate AI Usage Policy At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.   Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The pay range for this position based on full-time employment is: $81,499.00 - $138,549.00 Nationwide Remote Office (US99)

United States
$81.5K - $138K / year
Job Closed
HealthVerity logo

Security Compliance Program Manager

HealthVerity

HealthVerity is a technology startup that provides software tools and products to help healthcare providers integrate patient data from a wide variety of source

Ensure compliance with FedRAMP and HIPAA regulations by developing policies and procedures. Collaborate with cross-functional teams for security assessments and continuous monitoring, while conducting risk assessments to maintain regulatory adherence.

Connecticut + 15 moreAll locations: Connecticut | Delaware | Florida | Georgia | Illinois | Indiana | Massachusetts | Maryland | Michigan | North Carolina | New Jersey | New York | Ohio | Pennsylvania | Tennessee | Virginia