Skip to main content
MacPaw

Senior Infrastructure Security Engineer

RemoteNot specified
Published
Role
Security
Experience
Senior
Salary not disclosed
Check eligibility

The listing doesn't say where it hires from. Check the description or the employer's site before applying.

No BS summary

Senior infrastructure security engineer with strong Terraform, Python/Go and GCP production security experience. Must have in-depth Kubernetes and bare-metal Linux security skills and proven infrastructure vulnerability management and incident response. Fluent Ukrainian and at least Upper-Intermediate English.

Core skills

TerraformGCPKubernetes

Required skills

Python/GoInfrastructure-as-CodeIAM (least privilege)Network segmentationRBACAdmission controlOPAKyvernoNetwork policiesRuntime threat detectionImage provenanceBare-metal Linux securityLinux hardeningHost-based controlsMulti-tenancy risk mitigationInfrastructure vulnerability managementIncident managementThreat containmentRoot cause analysis (RCA)CI/CD securityAgentic AI automation

Optional skills

Experience securing agentic AI systems in productionCNAPP/CSPM platforms (Wiz, Sysdig, Orca, Prisma Cloud)NixOS or other immutable Linux distributionsCloudflare edge security controlsExperience operating under ISO 27001 or SOC 2 Type II frameworksSecurity certifications (CKS, OSCP, GCP Professional Cloud Security)

Required languages

English Upper-Intermediate},{Ukrainian Fluent

What you'll do

  • Take dedicated ownership of securing production infrastructure, establishing compliance control baselines, and maintaining a strong security posture.
  • Participate in Wiz CNAPP service adoption.
  • Drive Kubernetes and cloud posture hardening across GCP, including RBAC reviews, admission control, network policies, and runtime threat detection.
  • Take ownership of the infrastructure vulnerability backlog, driving remediation down against severity-based SLAs in close collaboration with SRE.
  • Build and ship agentic AI security automation into code-reviewed repositories to streamline vulnerability management and operational security workflows.
  • Collaborate closely with the SRE team to embed security controls into CI/CD pipelines and Infrastructure-as-Code without adding unnecessary friction.

What they require

  • Strong expertise in Infrastructure-as-Code and automation using Terraform.
  • Python or Go skills to build security tooling rather than just filing tickets.
  • Hands-on experience with incident management, threat containment, and root cause analysis (RCA) for infrastructure security incidents.
  • Demonstrated ability to work with Service Reliability Engineers (SRE) team as a technical peer, driving security engineering through influence and shared goals.
  • Hands-on production cloud security experience at scale on GCP (IAM least privilege, network segmentation, runtime detection, and posture hardening).
  • In-depth Kubernetes security experience in production: RBAC, admission control (OPA/Kyverno), network policies, runtime detection, and image provenance.
  • Proven experience in bare-metal and self-hosted Linux infrastructure security (host-based controls, Linux hardening, and multi-tenancy risk mitigation outside managed cloud).
  • Experience in infrastructure vulnerability management: triage, SLA management, and driving remediation through engineering teams.
  • Ability to write and ship agentic AI automation into production repositories to enhance security operations.
  • At least an Upper-Intermediate level of English and fluent Ukrainian.

The company behind CleanMyMac, Setapp, ClearVPN, and a growing ecosystem of products used by millions of people worldwide.

SoftwareMid-size
Salary not disclosed