About the PositionToloka is growing rapidly, adding new platforms and infrastructure across multiple cloud environments. We are hiring a senior, hands-on security engineer to own infrastructure security and vulnerability management: Kubernetes and service-mesh security, cloud hardening, and vulnerability remediation.
This is a senior, self-directed role. It requires the ability to define scope and drive execution independently, with ownership of core security tooling and processes from day one.
What you'll actually do- Own vulnerability management. Operate and maintain the vulnerability-management platform. Ensure container images are scanned and patched on a defined cadence. Maintain supply-chain scanning tooling and its severity-classification configuration. Define and enforce remediation SLAs.
- Own cloud security across multiple providers. AWS, GCP, and Azure hardening, logging, and service-account governance.
- Own Kubernetes and service-mesh security. Operate the service mesh and maintain the policy-as-code rollout so that policy is enforced automatically.
- Audit and secure infrastructure in newly added environments. Review build pipelines and infrastructure in newer parts of the business as they come online, and remediate findings.
- Contribute to security architecture and design review. Review new integrations and internal systems, including AI agents running in production, for security risk.
- Support workforce and endpoint security. Contribute to VDI and browser-isolation initiatives as the program matures.
- Use agentic tooling in your workflow. Use coding agents for first-pass review of infrastructure-as-code, container configuration, and cloud policy, verifying findings against source configuration before acting on them.
Key Priorities for the First 6 MonthsThe first six months focus on establishing full ownership of infrastructure and vulnerability management.
- Weeks 1-2 - Onboard to the cloud environment, Kubernetes architecture, and existing security tooling.
- Month 1 - Establish ownership of the vulnerability-management process; findings triaged and remediated on a defined cadence.
- Month 2 - Complete configuration of supply-chain scanning tooling; implement automated image scanning and patching; deploy initial policy-as-code rules.
- Month 3 - Complete policy-as-code rollout in at least one environment; begin infrastructure audits in newly added environments.
- Month 4 - Close outstanding cloud logging and service-account gaps; establish and enforce a documented multi-cloud hardening baseline.
- Months 5-6 - Full ownership of infrastructure and cloud security as a domain; independently deliver security-architecture design reviews.
Core Tech StackKubernetes and service mesh, policy-as-code tooling (Kyverno/OPA), Terraform, AWS/GCP/Azure, vulnerability-management and supply-chain scanning platforms, container tooling, CI/CD, and Git. Detections and access rules are managed as code through pull requests. Familiarity with coding/agentic tools for infrastructure review is expected.
What We Evaluate- Production experience hardening cloud infrastructure - IAM, logging, service accounts, network security, on at least one major cloud provider (multi-cloud experience is a plus).
- Kubernetes and container security - service mesh (Cilium, Istio, or similar) and policy-as-code (Kyverno, OPA, or similar).
- Vulnerability-management experience - SCA/SAST tooling and SLA-driven remediation practice.
- Fluency with coding agents - experience using agentic tools for infrastructure-as-code review or investigation work, and verifying their output.
- Ability to work independently at a senior level - defining scope and priorities without detailed direction.
- Clear written and verbal communication - able to run design reviews and communicate risk to engineers and leadership.
Nice to Have, None RequiredExperience securing multi-tenant or multi-identity-domain environments; supply-chain security tooling (SBOM, Socket, JFrog, or similar); secure-SDLC or AppSec experience; Terraform/IaC at scale; relevant certifications (e.g. AWS/GCP/Azure security specialties, CKS).
What We Can Offer- Contract (B2B) collaboration, with a path into a project team if things go well;
- Flexible, fully remote schedule (40 hours per week);
- Work at the leading edge of AI development, alongside a dedicated and dynamic team of experts;
- Projects with customers that are AI industry leaders and well-known household names;
- Friendly community.