← Усі вакансії

Senior Infrastructure Security Engineer

MacPaw, Київ, за кордоном
Формат:
повний remote
Рівень:
senior
Джерело:
jobs.dou.ua
Відгукнутись на вакансію →

At MacPaw, we craft software that makes everyday tech life simpler, cleaner, and more enjoyable. From globally loved products like CleanMyMac and Setapp to emerging cybersecurity tools like ClearVPN and Moonlock, we are building a product ecosystem that reaches millions of people worldwide.

We believe humans and technology can reach their greatest potential together. By fusing high engineering standards, thoughtful design, and practical AI, we rethink how people interact with their devices and shape the daily tech routines of the future.

Working at MacPaw means owning outcomes, not just tasks. We build for global scale from day one, giving you the trust, freedom, and room to experiment.

In our team, we challenge ideas directly, support each other genuinely, and build software that makes a meaningful difference — both in the tech world and beyond.

We’re looking for a Senior Infrastructure Security Engineer to join our Information Security Team, supporting MacPaw’s product ecosystem as we transition to our next-generation setup.

Our Security and Infrastructure teams ensure that all MacPaw products run on a highly resilient, compliant, and rock-solid foundation, protecting user data and business operations at scale.

As a Senior Infrastructure Security Engineer, you will take dedicated ownership of securing our production infrastructure, establishing compliance control baselines, and maintaining a strong security posture. You’ll define, test, and coordinate security frameworks across bare-metal environments and GCP, working hand-in-hand with our SRE team as a technical peer and security partner.

If you’re excited to take ownership of MacPaw’s infrastructure security, reduce automated evidence coverage gaps, and collaborate on advanced CNAPP tools and agentic AI automation, we’d love to hear from you!

In this role, you will:

Participate in Wiz CNAPP service adoption.

Drive Kubernetes and cloud posture hardening across GCP, including RBAC reviews, admission control, network policies, and runtime threat detection.

Take ownership of the infrastructure vulnerability backlog, driving remediation down against severity-based SLAs in close collaboration with SRE.

Build and ship agentic AI security automation into code-reviewed repositories to streamline vulnerability management and operational security workflows.

Collaborate closely with the SRE team to embed security controls into CI/CD pipelines and Infrastructure-as-Code without adding unnecessary friction.

Skills you’ll need to bring:

Strong expertise in Infrastructure-as-Code and automation using Terraform.

Python or Go skills to build security tooling rather than just filing tickets.

Hands-on experience with incident management, threat containment, and root cause analysis (RCA) for infrastructure security incidents.

Demonstrated ability to work with Service Reliability Engineers (SRE) team as a technical peer, driving security engineering through influence and shared goals.

Hands-on production cloud security experience at scale on GCP (IAM least privilege, network segmentation, runtime detection, and posture hardening).

In-depth Kubernetes security experience in production: RBAC, admission control (OPA/Kyverno), network policies, runtime detection, and image provenance.

Proven experience in bare-metal and self-hosted Linux infrastructure security (host-based controls, Linux hardening, and multi-tenancy risk mitigation outside managed cloud).

Experience in infrastructure vulnerability management: triage, SLA management, and driving remediation through engineering teams.

Ability to write and ship agentic AI automation into production repositories to enhance security operations.

At least an Upper-Intermediate level of English and fluent Ukrainian.

As a plus:

Experience securing agentic AI systems in production (prompt injection, tool poisoning across MCP, human-in-the-loop approval flows, and kill switches).

Experience with CNAPP/CSPM platform migrations or ow

Схожі вакансії

З блогу Trackr

Усі статті →

Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot