LotusFlare is a US product company that was founded in 2014 by former executives from Facebook. Our founders led the team that helped Facebook reach over two billion users on mobile, during the years when the company invented the discipline of Growth.
25 квітня 2025

Security Engineer / DevSecOps (вакансія неактивна)

Краків (Польща)

POSITION SUMMARY

As a Security Engineer on the Infrastructure Team at LotusFlare you will be responsible to drive the overall IT security standards across our cloud native DNO stack. This incorporates security policies and domain security concepts along with the implementation and the lifecycle of security technologies in LotusFlare’s infrastructure.

You will be reporting to the VP of Infrastructure and engage directly with infrastructure and product engineering teams.

Our office is located in the vibrant area of Krakow, at Aleja Pokoju 18. We encourage you to join us in the office to collaborate, connect, and contribute to our team’s success.

REQUIREMENTS

  • 3+ years of DevOps or DevSecOps experience
  • Experience securing CI/CD pipelines Familiarity with modern DevSecOps tooling (SAST, DAST, SCA, IaC scanning)
  • Bachelor’s degree
  • Cloud-native infrastructure stack experience with tools like Terraform, Ansible and etc;
  • Experience in the implementation of security controls and familiarity with SCAP and continuous security monitoring solutions
  • Knowledge in the development and implementation of the following concepts:
    — Network Security Concepts
    — Linux System Security and System Hardening
    — Data Classification and Data Security Concepts
    — Cloud Security, particularly AWS
  • Understanding of various user access controls, SSO, user profile integrity and access management controls
  • Ability to analyze and resolve complex infrastructure resource and application deployment issues
  • Minimum Intermediate level of English

RESPONSIBILITIES

  • Actively managing the security of our cloud-native runtime environment
  • Evolving LotusFlare’s GRC with regular senior management reporting of compliance and risk KPIs
  • Clearly and promptly communicate and negotiate security technical topics with both technical and non-technical audiences
  • Drive security improvements to production cloud environments
  • Perform targeted offensive security testing
  • Implement continuous monitoring systems and tools to automatically identify potential security issues at the code, application and infrastructure layers
  • Conduct security audits in cloud environments
  • Review code and other production changes with the goal to maintain the security standards
  • Develop documentation listing recommendations and best practices for infrastructure and organizational security standards
  • Stay current on emerging security threats, vulnerabilities, and controls for the cloud
  • Working with backend engineering teams on architecting, profiling, and monitoring high-performance high availability product components as microservices, providing mission-critical real-time functionality on the control plane of mobile and fixed networks
  • Evolving the infrastructure and keeping our stack up to date with the latest technologies

WE OFFER

  • Hybrid work environment;
  • Yearly bonus;
  • Paid lunches;
  • Private medical insurance;
  • The company covers accountant assistance expenses;
  • ZUS coverage;
  • Paid sick leaves;
  • 21 working days of vacation, public holidays;
  • Training and workshops.