Security Engineer

4 дней назад


Украина, Украина Crunch Полный рабочий день

We are looking for a hands-on Security Engineer to join our cross-project core team and take ownership of security across three products:

  1. A Java-based platform with microfrontends running on Azure.

  2. A web portal built with NestJS and React.

  3. An AI portal built with NestJS and React, running on Azure and AWS (Bedrock, Lambda, Kendra).

You will work closely with our architecture team to prepare and maintain security plans, perform threat modelling, and execute security testing for applications, cloud infrastructure, SSO, and authorization services.

Responsibilities
  • Own application and infrastructure security across three projects:

    • Java microservices and microfrontends on Azure (Container Apps, Static Web Apps, databases).

    • Web portal based on NestJS and React.

    • AI portal on Azure and AWS (Bedrock, Lambda, Kendra).

  • Prepare and refine security plans and threat models together with the architecture team.

  • Perform security testing of Azure infrastructure:

    • Azure Container Apps, Static Web Apps, databases, networking, and related services.

    • Review Azure security posture (e.g., Defender for Cloud, logging, monitoring).

  • Perform security testing of web applications:

    • Frontend (React / microfrontends) and backend services (Java, NestJS).

    • APIs, authentication and authorization flows, and integrations.

  • Assess the security of AI services running on AWS:

    • Bedrock, Lambda functions, Kendra, and data flows between Azure and AWS.

    • Identify risks related to data exposure, prompt injection, access control, and logging.

  • Review and harden SSO and authorization:

    • Analyze Keycloak (deployed on Azure) configuration, OIDC/OAuth2 flows, session management, and token handling.

    • Review roles and permissions implemented via OpenFGA; validate least-privilege, multi-tenant isolation, and access control rules.

  • Analyze and validate existing threat models and the security plan; propose updates based on new findings.

  • Identify security vulnerabilities and propose mitigation strategies with clear prioritization (risk, impact, effort).

  • Use a combination of manual testing and automated tools to perform:

    • Web application security testing (OWASP Top 10, API security).

    • Infrastructure and configuration security assessments.

  • Provide clear, structured security testing reports with:

    • Findings, risk rating, business impact.

    • Recommended remediation steps and follow-up actions.

  • Collaborate with architecture, development, and DevOps teams to ensure fixes are properly implemented and verified.

Requirements
  • Proven experience in security testing of cloud environments, preferably Azure (infrastructure, PaaS services, networking, identity).

  • Experience in web application security testing, including strong practical knowledge of:

    • OWASP Top 10, API security, and common web vulnerabilities.

    • Authentication and authorization patterns (OAuth2, OIDC, JWT).

  • Experience with security testing tools, such as:

    • OWASP ZAP, Burp Suite, or similar DAST tools.

    • SAST / dependency scanning / code quality tools (e.g., SonarQube).

    • Cloud security posture tools (e.g., Azure Security Center / Defender for Cloud).

  • Good understanding of:

    • Network security (firewalls, segmentation, VPNs, secure connectivity).

    • Application security (secure coding principles, input validation, session management).

    • Cloud security best practices (identity, secrets management, logging, monitoring).

  • Ability to document findings clearly and propose actionable improvements for technical and non-technical stakeholders.

  • Ability to read and reason about code and APIs in at least some of the stack:

    • Java, TypeScript/JavaScript (NestJS, React).

  • Experience working in close collaboration with architecture and engineering teams.

Nice to Have
  • Experience with Azure security services:

    • Defender for Cloud, Key Vault, Azure Firewall, Application Gateway / WAF, Azure Front Door.

  • Experience with AWS security concepts and services, especially in the context of:

    • Lambda, IAM, Bedrock, Kendra, and secure data flows between clouds.

  • Hands-on experience with:

    • Automated security scanning in CI/CD pipelines.

    • Infrastructure-as-code security (Terraform, Bicep, or similar).

  • Experience securing SSO solutions:

    • Keycloak, OIDC/OAuth2, and federation scenarios.

  • Understanding or experience with authorization frameworks:

    • Policy-based access control (e.g., OpenFGA, Open Policy Agent).

  • Security-related certifications (e.g., AZ-500, SC-200, AWS Security Specialty, OSCP, CEH, CISSP, CCSP) are a plus.


  • Senior Security Engineer

    2 недель назад


    Украина, Украина Description Ciklum Полный рабочий день 20 000 ₴ - 32 000 ₴ в год

    DescriptionCiklum is looking for a Senior Security Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners,...

  • Senior Security Engineer

    1 неделя назад


    Украина, Украина Description Ciklum Полный рабочий день 45 000 ₴ - 90 000 ₴ в год

    DescriptionCiklum is looking for a Senior Security Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners,...

  • Senior Information Security Engineer

    2 недель назад


    Украина, Украина Description Ciklum Полный рабочий день 40 000 ₴ - 60 000 ₴ в год

    DescriptionCiklum is looking for a Senior Information Security Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and...

  • Junior Information Security Engineer

    1 неделя назад


    Украина, Украина Description Ciklum Полный рабочий день 20 000 $ - 60 000 $ в год

    DescriptionCiklum is looking for a Junior Information Security Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and...

  • Senior Migration Engineer

    4 дней назад


    Украина, Украина N-iX Полный рабочий день

    N-iX is looking for a  Senior Migration Engineer for one of our clients.Our customer is the European online car market, with over 30 million monthly users and a presence in 18 countries. As a Senior Migration Engineer, you will play a pivotal role in shaping the future of online car markets and enhancing the user experience for millions of car buyers and...

  • DevOps Engineer

    2 недель назад


    Украина, Украина Globaldev Group Полный рабочий день 30 000 ₴ - 60 000 ₴ в год

    We are seeking a skilled and proactive DevOps Engineer to join our technology team. The ideal candidate will take ownership of the infrastructure, build and deploy pipelines, and operational reliability of our platforms. A key aspect of this role will be collaborating closely with our external hosting provider, who delivers Infrastructure as a Service...

  • Middle DevOps Engineer

    1 неделя назад


    Украина, Украина Description Ciklum Полный рабочий день 45 000 $ - 90 000 $ в год

    DescriptionCiklum is looking for a Middle DevOps Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners,...

  • Site Reliability Engineer

    2 дней назад


    Украина, Украина Description Ciklum Полный рабочий день

    DescriptionCiklum is looking for a Senior Site Reliability Engineer to join our team full-time in Ukraine.We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and...

  • Cloud Engineer

    2 дней назад


    Украина, Украина Hygge Software Полный рабочий день

    About the RoleWe're looking for a skilled Cloud / DevOps Engineer to design, deploy, and maintain scalable cloud infrastructure that supports machine learning workloads and data-intensive applications. You'll work closely with ML engineers and developers to ensure smooth integration, automation, and reliability across our systems.Key ResponsibilitiesDesign,...

  • Senior Backend Engineer

    7 дней назад


    Украина, Украина AllStars-IT Полный рабочий день

    Senior Backend EngineerLevelDepartmentDevelopmentTypeFull TimeProjectMuvan.AILocations:UkrainePolandRomaniaJob DetailsPosted on:December 8, 2025About the CompanyEstablished in 2004, ALLSTARSIT was founded with a clear vision: to enhance the landscape of global IT employment by bridging the gap between companies and skilled professionals. The core belief was...