Задачи:
— проводить пентест Web, API, мобильных приложений, инфраструктуры, сетей и облака;
— выполнять white-box / SAST-анализ исходного кода;
— работать с разработчиками, DevOps и Blue Team;
— использовать Burp Suite, Nmap, Metasploit, Nessus/OpenVAS, Hydra, sqlmap, Impacket, BloodHound и др.;
— участвовать в построении SecSDLC;
— готовить отчёты по результатам работ.
Требования:
— знание OWASP Top 10 / API Top 10 / Mobile Top 10;
— понимание TCP/IP, HTTP/S, DNS, LDAP, SMB;
— опыт в Pentest / Network Security;
— уверенное владение Linux;
— опыт работы с Burp Suite, Nmap, Metasploit и инструментами анализа уязвимостей;
— знание OWASP, MITRE ATT&CK, D3FEND.
Задачи:
- Design and implement robust services and libraries for payments integration across Kraken products
- Write reusable, testable, and highly efficient codebase
- Collaborate with cross-functional teams including Product, Design, and Frontend Engineering to ensure seamless integration of new features and improvements in a large scale distributed systems architecture
- Partner closely with crypto native engineers
Требования:
- 3+ years of experience in software engineering
- Proficiency in writing clean, scalable backend code in a systems language, preferably Rust or Node/Typescript
- Commitment to a security-first mindset when designing systems
- Ability to autonomously debug issues across the stack including OS, network, and application layers
- Familiarity with distributed systems and technologies including RPC protocols, Kafka, and Event Driven Systems
Задачи:
— Закрытие инфраструктуры, CI/CD, Kubernetes, мониторинг, секреты и автоматизация.
— Настройка и оптимизация CI/CD в GitLab CI.
— Внедрение и поддержка Kubernetes.
— Настройка мониторинга с Prometheus, Grafana, Loki, Alertmanager.
— Автоматизация инфраструктуры с использованием Terraform и Ansible.
— Управление секретами и доступами через HashiCorp Vault.
— Работа с базами данных PostgreSQL и mongoDB, включая HA и backup/restore.
— Обеспечение безопасности: RBAC, NetworkPolicy, Pod Security.
— Работа с инфраструктурой в Yandex Cloud и proxmox.
Практический опыт:
— Работа с нейронными сетями для трекинга лиц на Tesla T4.
— Создание админки для управления терминалами.
— Разработка MVP моделей новых систем.
— Настройка локальной инфраструктуры в ЦОДе компании.
— Участие в разработке инфраструктуры новых продуктов.
— Выполнение функций SRE на проектах во время мероприятий.
— Внедрение CDN и Kubernetes, настройка инфраструктуры с возможностью отключения интернета, сокращение времени релизов на 20%.
— Настройка Terraform-инфраструктуры в Yandex Cloud и proxmox, автоматизация кластеров, сети, DNS, балансировщиков и IAM.
— Внедрение Prometheus, Grafana, Loki, Alertmanager и blackbox, сокращение времени обнаружения инцидентов до 3 минут.
— Оптимизация GitLab CI: добавление кэширования, параллельных джобов, встроенное SAST/DAST-сканирование образов, сокращение времени сборки с 10 до 3-5 минут.
— Внедрение агента для поиска уязвимостей.
— Внедрение HashiCorp Vault с настройкой Kubernetes auth, AppRole и доставки секретов через Agent Injector.
— Опыт работы с big data объемом около 20 ТБ.
Требования:
— Опыт работы DevOps-инженером от 3 лет.
— Знание и опыт работы с Linux, Docker, Kubernetes, GitLab CI, Terraform, Ansible, Vault, Prometheus, Grafana, Loki, Alertmanager.
— Опыт работы с PostgreSQL, Yandex Cloud.
— Навыки автоматизации и обеспечения безопасности инфраструктуры.
Условия:
— Формат работы: удалённо или гибрид.
— Занятость: full-time или part-time.
— Оформление обсуждаемо.
— Ожидаемая зарплата: 200000 рублей в месяц.
Задачи:
— Проводить проверки приложений и сервисов на наличие уязвимостей (SAST, SCA, DAST, обнаружение секретов, фаззинг), готовить POC‑эксплуатации и понятные отчёты для команд;
— Проводить триаж уязвимостей: оценка риска и влияния, приоритизация, постановка задач на исправление, контроль сроков и качества устранения уязвимостей;
— Участвовать в проектировании: проводить моделирование угроз (например, STRIDE), ревью архитектуры по безопасности и дизайн‑решений, формулировать требования к аутентификации, авторизации, шифрованию и журналированию;
— Развивать SSDLC и DevSecOps: определять и внедрять контроли по безопасности на этапах требований, дизайна, разработки, тестирования и эксплуатации, настраивать гейты безопасности в GitLab CI/CD;
— Сопровождать и развивать AppSec‑инструменты: интеграция сканеров в конвейер разработки, настройка политик, исключений и отчётности, участие в выборе и пилотах новых решений;
— Участвовать в аудитах безопасности сервисов и разборах инцидентов: анализ причин, выработка устойчивых мер, предотвращающих повторное возникновение уязвимостей целого класса;
— Консультировать команды разработки и архитекторов по вопросам безопасной разработки, разбору и устранению уязвимостей, шаблонам безопасного кодирования;
— Проводить тренинги, воркшопы и семинары по AppSec (OWASP Top 10 / API Security, безопасная аутентификация и управление сессиями, защита API и интеграций и т.п.);
— Исследовать новые векторы атак и тренды в AppSec, предлагать улучшения процессов и инструментов.
Требования:
— Высшее техническое образование (желательно профильное ИБ или сопоставимый практический опыт в разработке/безопасности приложений);
— Опыт работы в роли инженера по безопасности приложений от 3 лет, участие в реальных проектах по защите веб‑ или API‑сервисов в продакшене;
— Практический опыт внедрения и эксплуатации инструментов: SAST, SCA, DAST, фаззинг, поиск секретов. Интеграция этих инструментов в CI/CD (желательно GitLab CI/CD);
— Опыт работы с Docker, Kubernetes, GitLab (или аналогичными системами контроля версий и CI/CD);
— Умение проводить ревью кода с фокусом на безопасность, давать разработчикам понятные и практичные рекомендации;
— Владение одним из языков программирования (Python / Go / Bash);
— Глубокое понимание причин возникновения и способов эксплуатации уязвимостей из OWASP Top 10 и OWASP API Security, а также практического устранения этих проблем;
— Навыки общения: умение объяснить сложные технические риски понятным языком, договариваться о приоритетах, конструктивно отстаивать позицию безопасности;
— Готовность брать ответственность за результат: от качества найденных уязвимостей до того, чтобы команда действительно внедрила устойчивое исправление, а не обходной костыль;
— Предпочтение отдаётся кандидатам, имеющим опыт работы в транзакционном бизнесе или платежных системах, с глубоким пониманием платёжных технологий и особенностей работы в сегментах B2B/B2G.
What We Do:
Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact.
Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection.
Huntress now secures more than 5M endpoints and 11M identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other.
What You'll Do:
In this role, you will turn targeted outreach into qualified conversations with security and IT decision-makers. You will build trust with internal IT teams and channel partners by asking clear questions, following up honestly, and learning what matters to each prospect.
You will bring Warrior Spirit to a quota-driven role by staying resilient through changing priorities and the daily work of building pipeline. You will Give a $h*t about the details that move opportunities forward, from thoughtful outreach and timely follow-up to accurate CRM data and a clear understanding of how Huntress helps customers and partners stay protected.
Responsibilities:
Prospect internal IT departments with 50 to 3,000 employees through phone, email, and LinkedIn.
Establish trust and rapport with channel partners through phone, email, and LinkedIn while learning about their solutions, team composition, territories, and ideal customer profile.
Work collaboratively with the team to create outbound prospecting strategies for channel partners and mid-market internal IT departments.
Develop and manage contact and opportunity pipelines, ensuring timely follow-up on both.
Work closely with the Account Executive team to set demos, assist with closing deals, and build a passionate understanding of Huntress products, our human-led SOC, monthly educational webinars, and competitor offerings.
Meet and exceed monthly, quarterly, and annual sales quotas while maintaining accurate prospect and opportunity data in Salesforce and documenting all interactions.
Explore practical AI tools to support prospect research, outreach preparation, account prioritization, and follow-up while applying sound judgment to the work.
What You Bring to the Team:
You have 1+ year of outbound calling experience, preferably in cybersecurity, technology, or SaaS solutions, with a proven track record of success.
You have knowledge of cybersecurity solutions, including endpoint security.
You communicate clearly and effectively in both written and verbal conversations.
You can work independently and stay organized in a remote environment.
You have experience using Salesforce and sales engagement tools such as LinkedIn, Outreach, and Sales Navigator.
Familiarity with the VAR and reseller community is a bonus.
You are excited to explore AI and use it to work faster and smarter, with good judgment about when and how to apply it.
What We Offer:
100% remote work environment - since our founding in 2015
Generous paid time off policy, including vacation, sick time, and paid holidays
12 weeks of paid parental leave
Highly competitive and comprehensive medical, dental, and vision benefits plans
401(k) with a 5% contribution regardless of employee contribution
Life and Disability insurance plans
Stock options for all full-time employees
One-time $500 reimbursement for building/upgrading home office
Annual allowance for education and professional development assistance
$75 USD/month digital reimbursement
Access to the BetterUp platform for coaching, personal, and professional growth
Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are.
We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status.
We do discriminate against hackers who try to exploit businesses of all sizes.
Accommodations:
If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to accommodations@huntresslabs.com. Please note that non-accommodation requests to this inbox will not receive a response.
Huntress uses artificial intelligence tools to assist in reviewing and evaluating job applications, including resume screening, skills assessment, and candidate matching and comparisons. These AI tools support our human recruiters in the initial review process, but do not make final hiring decisions without human involvement. By submitting your application, you acknowledge this use of AI in our recruitment process. Please review our Candidate Privacy Notice for more details on our practices and your data privacy rights.
Задачи:
— Проектирование и разработка CoinJoin-протокола и transaction flow.
— Формирование, проверка и подписание Bitcoin-транзакций.
— Работа с UTXO, PSBT, SegWit и Taproot.
— Интеграция с Bitcoin Core через RPC.
— Реализация coin selection и fee estimation.
— Работа с sighash и различными сценариями подписания транзакций.
— Реализация multisig / threshold-signature сценариев там, где они необходимы архитектуре.
— Обработка особенностей mempool, propagation, replacement и подтверждения транзакций.
— Проектирование системы с учетом non-custodial модели: сервис не должен получать контроль над средствами пользователей.
— Участие в threat modeling и техническом аудите протокола совместно с security engineer.
— Code review и принятие ключевых архитектурных решений по Bitcoin-части проекта.
Требования:
— Глубокое понимание Bitcoin protocol и UTXO-модели.
— Практический опыт работы с Bitcoin Core и Bitcoin Core RPC.
— Уверенное понимание структуры Bitcoin-транзакций.
— Опыт работы с PSBT.
— Хорошее понимание SegWit и Taproot.
— Понимание sighash и механики подписания Bitcoin-транзакций.
— Опыт реализации или использования fee estimation и coin selection.
— Понимание устройства Bitcoin mempool и жизненного цикла транзакции.
— Опыт разработки на одном или нескольких языках: Rust, C++, Go, Python.
— Опыт проектирования надежных backend/protocol-систем.
Будет большим плюсом:
— Опыт разработки Bitcoin Core или непосредственной работы с его кодовой базой.
— Опыт с rust-bitcoin, BDK или аналогичными Bitcoin-библиотеками.
— Опыт разработки CoinJoin, JoinMarket-подобных или других privacy-oriented Bitcoin-протоколов.
— Опыт построения non-custodial Bitcoin-сервисов.
— Опыт с multisig, threshold signatures и современными схемами управления ключами.
— Понимание privacy-модели Bitcoin и методов blockchain analysis.
Что важно в этой роли:
Мы ищем не просто backend-разработчика, который когда-то интегрировал криптовалютный API. Нужен инженер, который понимает Bitcoin на уровне протокола и способен самостоятельно принимать решения по архитектуре транзакций, подписям, UTXO и взаимодействию с Bitcoin Core.
Задачи:
— Разработка coordinator API.
— Реализация жизненного цикла CoinJoin-сессий.
— Управление состоянием участников и раундов.
— Разработка очередей и фоновых процессов.
— Интеграция backend-сервисов с Bitcoin-нодами.
— Реализация rate limiting и механизмов защиты API.
— Authentication / authorization для внутренних и внешних компонентов системы.
— Обработка ошибок, retries, timeouts и отказов отдельных компонентов.
— Разработка observability: metrics, structured logging, tracing, alerts.
— Работа над производительностью и устойчивостью системы под нагрузкой.
— Совместная работа с protocol, security и DevOps-инженерами.
Требования:
— Сильный опыт backend-разработки production-систем.
— Опыт разработки API и распределенных сервисов.
— Уверенная работа хотя бы с одним из языков: Rust, Go, Python.
— Опыт работы с PostgreSQL, Redis или аналогичными системами хранения состояния.
— Опыт построения очередей и asynchronous processing.
— Понимание concurrency и race conditions.
— Опыт проектирования rate limiting и защиты публичных API.
— Понимание observability и эксплуатации production-систем.
— Умение проектировать системы, устойчивые к частичным отказам.
Будет плюсом:
— Опыт интеграции с Bitcoin Core RPC.
— Понимание UTXO-модели Bitcoin.
— Опыт с blockchain / cryptocurrency infrastructure.
— Опыт разработки non-custodial сервисов.
— Знакомство с CoinJoin и privacy-протоколами.
— Опыт разработки high-load или security-sensitive систем.
Что важно в этой роли:
Bitcoin-экспертиза будет преимуществом, но от backend-инженера мы прежде всего ожидаем умения строить надежную серверную систему: coordinator должен корректно работать при параллельных запросах, сбоях участников, повторных запросах, высокой нагрузке и попытках злоупотребления API.
Heliax is a remote-first company that researches, develops, deploys, and maintains open-source protocols and mechanisms to serve everyday needs, including Anoma and Namada projects.
Applicants must be based in Europe (including the UK) and willing to travel to Berlin for initial onboarding.
Responsibilities:
— Design new cryptographic protocols (e.g. shielded state sync) to meet specified information flow, security, and performance goals.
— Evaluate and analyze existing cryptographic protocols and proof systems (e.g. zkSNARKs, zkSTARKs, Halo2, ProtoStar, Risc0 zkVM) for security, expressivity, and performance.
— Update, reimplement, and combine cryptographic protocols, customizing them for proofs-of-concept and production use-cases.
— Produce comprehensive technical specifications for cryptographic designs and collaborate with engineers on implementations.
— Implement, review, and test cryptographic operations and protocols, primarily in Rust, and evaluate implementations for correctness and performance.
Requirements:
— Mathematical and/or cryptographic background in relevant subfields (complexity theory, abstract algebra, cryptographic protocol design).
— Expertise (formal or informal) in constructive protocol design and analysis of distributed cryptographic protocols.
Nice to have:
— Published papers in mathematics, theoretical CS, and/or cryptography.
— Experience with distributed systems and/or operating systems architecture/design.
— Experience with Zerocash/Zexe/VeriZexe and related architectures.
— Academic qualifications in a relevant field (cryptography or mathematics).
Stack includes Rust, zkSNARKs, zkSTARKs, Halo2, ProtoStar, Risc0 zkVM, Arkworks, elliptic curves, hash functions, DKG, threshold encryption.
Benefits:
— Relocation and visa assistance for Germany.
— High degree of independence in working conditions and task prioritization.
— Work closely with a small cross-disciplinary team on research-led projects.
— Opportunity for travel, including initial onboarding in Berlin.
About OkWhen
OkWhen builds technology that powers live, virtual, and hybrid events. Their platform supports conference management, registration, payments, mobile apps, content libraries, webinars, LMS functionality, CEU tracking, sponsor management, and operational workflows.
The Outcome We’re Hiring For
You will own meaningful parts of the application and consistently deliver reliable software without requiring constant supervision. You will improve system performance, reduce technical debt, and turn operational problems into simple, maintainable products. This role requires understanding the existing system, making sound technical decisions, and following work through from discovery to production.
Responsibilities:
— Design, build, test, deploy, and maintain production software
— Develop backend services and APIs using C# and ASP.NET/.NET
— Build and maintain web applications using Angular
— Design, optimize, and troubleshoot SQL Server databases and queries
— Maintain and extend mobile applications using .NET MAUI
— Investigate and resolve production issues
— Improve application reliability, performance, security, and observability
— Write automated tests and maintain technical documentation
— Participate in code reviews and establish engineering standards
— Collaborate with product, operations, and event-production teams
— Break ambiguous business problems into clear technical plans
— Use AI-assisted development tools responsibly to improve speed without sacrificing quality
Requirements:
— 7+ years of professional software development experience
— Strong commercial experience with C#, .NET, and ASP.NET Core
— Strong experience with Angular and TypeScript
— Advanced working knowledge of SQL Server, database design, and query optimization
— Production experience with .NET MAUI or Xamarin
— Experience designing and consuming REST APIs
— Experience with Git, CI/CD, debugging, and automated testing
— Demonstrated ability to work independently in an existing codebase
— Strong written and verbal communication
— Comfortable owning outcomes, not just completing assigned tasks
Preferred Qualifications:
— Experience with SaaS platforms
— Experience with event management, registration, payments, LMS, or communications systems
— Cloud experience with Azure or AWS
— Experience with distributed systems, queues, integrations, or real-time applications
— Experience modernizing legacy applications
— Experience mentoring other developers
Conditions:
— Health Care Plan (Medical, Dental & Vision)
— Retirement Plan (401k, IRA)
— Paid Time Off (Vacation, Sick & Public Holidays)
— Family Leave (Maternity, Paternity)
— Training & Development
— Work From Home
About Delinea:
Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to seamlessly govern their interactions across the modern enterprise. Leveraging AI-powered intelligence, Delinea’s leading cloud-native Identity Security Platform applies context throughout the entire identity lifecycle – across cloud and traditional infrastructure, data, SaaS applications, and AI. It is the only platform that enables you to discover all identities – including workforce, IT administrator, developers, and machines – assign appropriate access levels, detect irregularities, and respond to threats in real-time. With deployment in weeks, not months, 90% fewer resources to manage than the nearest competitor, and a 99.995% uptime, Delinea delivers robust security and operational efficiency without compromise.
What You Will Own:
— Price and packaging architecture across the portfolio: tiering, licensing metrics, add-on structure, bundling.
— Proposal quality into the monthly Price Committee: analysis, financial model, recommendation, and action register through to closure.
— Discount governance, including band policy and guardrails.
— Monetization for new categories: NHI governance, AI agent identity, StrongDM, consumption-based licensing.
— Commercial readiness at launch, ensuring packaging and pricing ship with the product.
— The single source of truth for pricing, packaging and quoting guidance, partnering with Product Marketing on seller enablement.
— Price realization, attach rate and competitive position, informed by competitor pricing, market benchmarks and win/loss data.
What We Are Looking For:
— 12+ years across pricing strategy, monetization, product management or product marketing, including 5+ years owning pricing as a named function.
— Experience building a monetization function where none existed: cadence, governance, documentation, analytical bench.
— Experience preparing and defending recommendations to a formal pricing committee or equivalent decision body.
— Demonstrated design of tiered packaging for enterprise software, strong financial modeling (pricing impact, ARR and expansion, discount optimization).
— Credibility with executive peers, holding a position on pricing under pressure without direct authority over sales or finance.
Strongly preferred:
— Cybersecurity or identity security (PAM, IAM, SIEM, endpoint); exposure to NHI, machine identity or secrets management.
— Consumption-, usage-, or outcome-based pricing models alongside seat-based subscription.
— Working knowledge of CPQ (Salesforce CPQ, Apttus); pricing through M&A integration or a major commercial model transition. MBA a plus.
Why Now:
Pricing at Delinea has been carried by people doing it well alongside a full portfolio, and the surface area keeps growing. The opportunity is to make monetization a professional discipline, with a decision forum that already works. This role is built for owning monetization end-to-end rather than managing an approval queue.
Why work at Delinea?
— Meaningful work, a culture of innovation and great career progression.
— Core values: Spirited, Trust, Respect, Ownership, Nimble, Global.
— Competitive salaries, meaningful bonus program, excellent benefits including healthcare insurance, pension/retirement matching, life insurance, employee assistance program, time off plans, and paid company holidays.
Delinea is an Equal Opportunity and Affirmative Action employer prohibiting discrimination and harassment of any type.
Candidates are required to complete comprehensive criminal background check, verification of education, and employment, and social media sites may be reviewed upon conditional offer of employment.
Задачи:
— Развертывание и эксплуатация Bitcoin Core nodes.
— Построение отказоустойчивой инфраструктуры для backend-сервисов.
— Мониторинг состояния Bitcoin-нод и внутренних сервисов.
— Настройка metrics, logging, alerting и dashboards.
— Secrets management и безопасная работа с credentials.
— Backup и disaster recovery.
— Автоматизация deployment и infrastructure provisioning.
— CI/CD.
— Контроль доступов и сегментация инфраструктуры.
— Анализ и устранение production-инцидентов.
— Capacity planning и оптимизация ресурсов.
— Совместная работа с security engineer над hardening инфраструктуры.
Требования:
— Опыт DevOps/SRE в production-системах.
— Linux на уверенном уровне.
— Docker и контейнерная инфраструктура.
— Опыт с Kubernetes или аналогичными orchestration-платформами.
— Infrastructure as Code: Terraform, Ansible или аналоги.
— Опыт построения monitoring/alerting систем.
— Понимание сетей, firewall, TLS и управления доступом.
— Практический опыт secrets management.
— Опыт построения backup/recovery процессов.
— Умение расследовать production-инциденты.
Будет плюсом:
— Опыт эксплуатации Bitcoin Core nodes.
— Понимание Bitcoin P2P/networking.
— Опыт эксплуатации blockchain infrastructure.
— Опыт с security-sensitive или financial infrastructure.
— Опыт защиты публичных сервисов от DDoS/DoS.
— Опыт построения privacy-oriented инфраструктуры.
Что важно в этой роли:
Для проекта критична не только доступность сервисов, но и минимизация инфраструктурных рисков и утечек метаданных. Поэтому нам нужен инженер, который рассматривает security и privacy как часть инфраструктурной архитектуры, а не как отдельный этап после запуска.
About LawnStarter
LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $100M in annual bookings. The company is expanding beyond lawn care to become a one-stop shop for all home services, operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform.
About Analytics at LawnStarter
The analytics team supports the entire company including product, marketing, operations, and finance. The data platform includes a centralized Redshift data warehouse, modeled in dbt and orchestrated by Airflow, with Segment feeding event data. The team is mid-migration to Lightdash as the single BI platform, replacing Tableau and Metabase. Currently, data quality, tracking standards, and platform hygiene are side tasks handled by analysts.
The Role
The Analytics Engineering Manager will be the first dedicated person for data governance, responsible for data trustworthiness and the roadmap to improve it quarterly. Responsibilities include ensuring quality and freshness of source data, pipelines, reports, metric definitions, Segment event tracking standards, Lightdash workspace health, data feeding ML models, and data security. The role involves collaborating with product, marketing, ops, and finance to prioritize platform work. It is a hands-on role starting solo, building automation, checks, fixing issues, and establishing scalable processes. Eventually, the manager will hire a Lead Analytics Engineer and grow the function as needed.
Key differentiators of the role:
- First dedicated governance role, reshaping existing standards.
- Owns the data roadmap, discovering business needs and prioritizing work.
- Whole-stack ownership from source data to ML models.
- Leading the migration to Lightdash, setting up permissions and norms.
Responsibilities:
- Develop and manage the data roadmap balancing business needs and platform health.
- Automate monitoring of data quality and freshness, resolve incidents.
- Maintain data lineage and impact analysis to assess downstream effects of changes.
- Administer Lightdash workspace, permissions, and rollout.
- Extend and guard the semantic layer with governed metric definitions.
- Govern Segment event tracking catalog, standards, and drift detection.
- Ensure AI data readiness for internal AI tools querying the warehouse.
- Manage data security, privacy, access controls, and compliance with US state laws.
- Maintain governance documentation, ownership models, and review processes.
Challenges to solve:
- Convert business requests into a prioritized data roadmap.
- Ensure Lightdash migration improves platform usability without dashboard sprawl.
- Complete and maintain a trustworthy semantic layer.
- Manage event-tracking standards and prevent entropy.
- Proactively detect and prevent data pipeline breakages with automation and lineage.
Success metrics for year 1:
- Zero pipeline incidents from unannounced data changes.
- Zero freshness incidents; stakeholders never see stale dashboards.
- All business areas use official, well-maintained metrics and dashboards.
- Every Segment event has an owner and meets standards.
- Governance operates as a documented, sustainable system.
Requirements:
- Passion for data governance as a craft.
- Daily use of AI tools for automation, anomaly triage, and documentation.
- Hands-on manager who codes, debugs, and configures personally.
- Product-minded, able to translate vague requests into prioritized plans.
- Automation-first approach to quality checks.
- Ability to enforce standards with clear rules and good tooling.
Role exclusions:
- Not a large-team leadership role; starts solo with potential to hire one lead.
- Not a policy or committee role; hands-on fixing with code and conversations.
- Not a BI analyst role; focuses on platform and guardrails, not dashboard building.
- Not a mature system babysitting role; involves building and evolving the platform.
Technologies involved:
- Warehouse & pipelines: Redshift, dbt, Airflow
- Ingestion: Fivetran, custom Airflow pipelines
- Event tracking: Segment
- BI tools: Lightdash (primary), Tableau and Metabase (sunsetting)
- AI tooling: Claude Code, Codex, Brain (internal AI toolkit)
- Observability: AI-powered Analytics Engineer agent for monitoring and anomaly detection
Benefits:
- Base salary $75k-$120k/year
- Fully remote with asynchronous collaboration
- Flexible PTO
Equal employment opportunity statement included.
Задачи:
— Проектировать и реализовывать критичные компоненты: policy engine, signing orchestration, key lifecycle, recovery flows, approvals, audit trails, multi-tenant wallet/account сервисы
— Строить высоконагруженные multi-tenant SaaS-системы (изоляция тенантов, rate limiting, backpressure и т.д.)
— Работать с distributed systems, reliability patterns, security-by-design
— Активно использовать AI-инструменты (Claude Code, Cursor, Codex) как core-компетенцию
Требования:
— Сильные CS fundamentals (concurrency, distributed systems, consistency и т.д.)
— 7+ лет backend на Go
— Реальный опыт работы с современными AI coding tools + умение критически проверять AI-код
— Опыт построения высоконагруженных multi-tenant SaaS
— Опыт работы в криптоиндустрии (криптобиржи, блокчейн-проекты, Web3)
Будет большим плюсом:
— Опыт в custody/wallets/MPC/HSM/Ledger
— Blockchain (EVM + Bitcoin обязательно, остальное в плюс)
— Регулируемая среда (SOC 2, ISO 27001 и т.д.)
— Kubernetes, SRE-практики
Условия:
— AI-first культуру с бюджетом на инструменты
— Сильную команду (криптографы, security, SRE, Product)
— Оплата в EUR / USD / криптовалюта
— Полностью удалённый формат работы
Nebius is a powerful AI cloud infrastructure for developers to build, train, and deploy generative AI apps and ML models in a secure, high-performance environment.
The position is on-site in Amsterdam, Netherlands, with a project duration of 3 months. Valid work authorization in the country of residence is required.
Cohere is a leading security-first enterprise AI company that builds cutting-edge foundation AI models and end-to-end products designed to solve real-world business problems.
Work format: Remote or on-site in Toronto, London, New York, San Francisco.
Задачи:
— Проводить security review AI/LLM-решений: LLM-приложений, AI-агентов, RAG, векторных БД, интеграций с внешними API и облачными LLM;
— Участвовать в threat modeling AI-решений: prompt injection, jailbreak, утечки данных, небезопасные tool calls, избыточные привилегии AI-агента, RAG/data poisoning;
— Проверять наличие и корректность защитных механизмов: guardrails, фильтры персональных данных, ограничения длины prompt/response, rate limiting, валидация ответов, контроль вызовов tools;
— Оценивать безопасность работы с данными: персональные данные, конфиденциальная информация, источники данных для RAG, embeddings, индексы векторных БД;
— Проверять, что AI-агенты работают по принципу минимально необходимых привилегий и не выполняют чувствительные операции без ручного подтверждения;
— Проверять изоляцию пользовательских сессий, контекстов и памяти AI-решений;
— Участвовать в проверке безопасности локального запуска LLM в Kubernetes: контейнеры, RBAC, secrets, network policies, ingress, resource limits;
— Формировать требования к логированию, аудиту и трассировке AI-решений: trace ID, логи prompt/response, вызовы модели, вызовы tools, действия AI-агента;
— Разрабатывать тестовые сценарии для проверки AI-решений на prompt injection, утечки данных, обход ограничений и небезопасное поведение агента;
— Помогать командам разработки и эксплуатации безопасно использовать локальные и облачные LLM.
Требования:
— Опыт в кибербезопасности от 2–3 лет в одной или нескольких областях: Application Security, DevSecOps, Cloud Security, Kubernetes Security, API Security, Product Security;
— Понимание принципов security review, threat modeling и безопасной разработки;
— Понимание web/API-безопасности: аутентификация, авторизация, OAuth2/OIDC, SAML, JWT, RBAC, service-to-service-взаимодействие;
— Базовое понимание AI/LLM-стека: LLM, prompt, system prompt, context window, embeddings, RAG, vector database, AI-agent, agent memory, tools/function calling;
— Понимание основных рисков LLM-приложений: prompt injection, indirect prompt injection, jailbreak, утечка чувствительных данных, раскрытие system prompt, небезопасная обработка ответа модели, excessive agency;
— Понимание особенностей безопасности RAG и векторных БД: например, Milvus, Qdrant, Weaviate, pgvector, Chroma, Elasticsearch/OpenSearch vector search;
— Понимание рисков работы с персональными и конфиденциальными данными при использовании локальных и облачных LLM;
— Базовое понимание Kubernetes и контейнерной безопасности: secrets, service account, RBAC, network policy, resource limits;
— Умение формулировать понятные и проверяемые требования безопасности для продуктовых команд.
Что мы ищем в кандидатах:
— Опыт security review AI/LLM, RAG, чат-ботов, AI-ассистентов или агентских решений;
— Знакомство с OWASP Top 10 for LLM Applications, OWASP Agentic AI Threats, MITRE ATLAS, NIST AI RMF;
— Понимание безопасности agent tools/function calling: allowlist tools, схемы входных параметров, контроль прав, human-in-the-loop;
— Опыт работы с SIEM/security logging: проектирование событий безопасности, аудит действий, расследование инцидентов;
— Понимание подходов к безопасному исполнению кода, сгенерированного моделью: sandbox, изоляция контейнеров, запрет доступа к secrets, ограничения сети и ресурсов;
— Базовые навыки Python, работы с JSON/YAML, API-тестирования или автоматизации security checks.
Будет плюсом:
— Опыт с OpenAI/Azure OpenAI, AWS Bedrock, Google Vertex AI, Anthropic или другими LLM-провайдерами;
— Опыт с локальными open-source LLM и inference-сервисами;
— Опыт настройки или проверки guardrails, фильтров персональных данных, DLP-подходов, content moderation;
— Опыт участия в AI red teaming или разработке тестов на prompt injection и data leakage.
Условия:
— Формат: Гибридный (от 2-х дней в неделю, м. Технопарк);
— Бесплатный доступ к телемедицине и очным приемам в частных клиниках (включая стоматологию и сессии с психологами);
— Условия ипотечного кредитования от Сбербанка;
— Индивидуальный план развития;
— Английский язык с корпоративным преподавателем и скидки на курсы в Skyeng, компенсация обучения от ведущих платформ;
— Официальное оформление, стабильные выплаты, оплата больничного и отпуска, современная техника;
— Частичная компенсация спортивного абонемента, бесплатные занятия сквошем и футболом.
Задачи:
— разработка технически сложных систем с большими потоками событий, security-телеметрией, аналитическими запросами и высокой нагрузкой
— участие в создании AI-first security engineering platform с возможностью влиять на технические решения с самого начала
Требования:
— 6+ лет коммерческой разработки
— Go как основной рабочий язык
— опыт работы с highload и большими потоками событий/данных
— опыт с traffic, telemetry, security, SIEM, протоколами, blockchain, event processing будет преимуществом
— опыт работы с Kafka, NATS, Redpanda или похожим стеком
— опыт работы с ClickHouse или другим аналитическим хранилищем
— опыт production-разработки backend- и data-сервисов
— глубокое понимание сложных технических систем и решения проблем производительности и обработки данных
— опыт работы с AI-инструментами: Claude Code, Codex, Cursor, Copilot
Условия:
— официальное оформление, белая заработная плата
— доход от 350 000 ₽ net
— формат работы: полностью удалённо, офис или гибрид
— офисы расположены на Кипре и в Москве
senior
от 350 000 ₽
300 000 – 300 000
Удалённоmiddle
58 500 – 78 000 $
300 000 – 340 000 $
Удалённо
75 000 – 120 000 $
ГибридmiddleМосква
Зарплата не указана
Все вакансии в одном месте — страница 7 · Job Hunters