Security & Compliance Engineer
Platform.sh via Stack Overflow
Oct 24th 2018
This is a full-time, permanent, remote position.
What we need
To reinforce our commitment to customers' privacy, we are looking to grow our security & compliance team. If you're looking for an exciting, high-growth opportunity with an award-winning, cutting-edge company, this could be the job for you.
For its PaaS solution, https://platform.sh is looking for a Security & Compliance Engineer with a taste for Python and Go, great Linux system understanding, outstanding written English skills, experience working on PCI and/or SOC compliance, and a real hunger for the challenges of building compliant distributed systems.
This position is unique and well suited for engineers wanting to transition into a heavy security and compliance role. We are targeting developers/sysadmins that like writing documentation. Initially, this high-visibility position will be non-coding while we overcome a bubble of compliance activities (and get the candidate on-boarded). After a few months, this role will grow into a part-time SecOps engineering position based upon the skill set and interests of candidate.
Security, privacy and compliance controls are at the heart of what we do as our mission is to simplify the cloud. The job is to transform what is often regarded as red-tape and constraints to a well-oiled machine where everything is automated, where every constraint becomes a feature making the product better.
The ideal candidate will work Western Europe Afternoon & USA-friendly hours, ideally residing in the Americas or Western Europe.
Directly reporting to our Data Protection Officer (VP), and in close interaction with our Chief Product Officer, CTO, VP of Infrastructure, and our Engineering and Customer Support teams, you will be responsible for:
- Acting as a technical liaison between our compliance department and our product, engineering, and operations staff
- Creating documentation and processes in English to help satisfy compliance requirements
- Evaluating, deploying, and possibly creating, systems and tools that will enhance our support and operations efficiency
- Supporting our data protection officer and compliance team with information requests, pen testing, disaster recovery, and related activities
- Executing our security incident management process
- Working with appropriate teams to deploy and operate security tools and solutions
- Ensuring all systems, security applications, and services in environment are securely configured and managed through operating system appropriate security platforms and tools
- Ensuring optimal operation of all security solutions and tools
- Automating all the above, so we can instead drink margaritas (or non-alcoholic beverages, of course)
The ideal candidate:
Must meet these requirements:
- works Western Europe and USA-friendly hours
- has excellent written English skills (as in, you could have been a tech writer or commercial author in another life)
- has proven experience with Linux (preferably Debian-based)
- knows markdown
- has experience implementing PCI, SOC, or related
- can operate largely independently (“go take that hill”) with management support
- has proven successful experience in an operations role
- has had good exposure to cloud services (AWS, Azure, & GCP in particular)
- understands how an OS works, knows networking, how git works, and the constraints of a distributed system
- is proficient in Python or GoLang
- Has an understanding of
- Patch and Vulnerability Management process
- Principle of Least Privilege
- Incident response
- Identity and Access Management
Nice to have :
- resides in the Americas
- has experience with containerization technologies (LXC/LXD, Docker)
- Has experience with vendor management
- Has experience with Puppet
- has demonstrated the ability to successfully manage cloud-based infrastructure for a fast growing organization
- knowledge of Magento Ecommerce, Symfony, Drupal, eZ Platform, or Typo3
- Has experience with Drupal
- Has experience with Rust
- relational database skills
- public speaking experience
- ability to speak French or German a plus
- ability to kick ass in Chess or beat Zork without using a map
- CISSP, CISM, Security+, GCED, GICSP, GCIH, SSCP, or CASP Certification or similar will get you moved to the top of the queue and is highly desirable
- CIPM/E, CIPP/E, CIPM/E certification or similar will get you moved to the top of the queue
- Can bravely take on new challenges like a Gryffindor, analyzes problems like Ravenclaw, protects our infrastructure and client data like a Slytherin, and talks with clients like a Hufflepuff.