Role Description
Toloka is growing rapidly, adding new platforms and infrastructure across multiple cloud environments. We are hiring a senior, hands-on security engineer to own infrastructure security and vulnerability management:
-
Kubernetes and service-mesh security
-
Cloud hardening
-
Vulnerability remediation
This is a senior, self-directed role. It requires the ability to define scope and drive execution independently, with ownership of core security tooling and processes from day one.
What you'll actually do
-
Own vulnerability management.
-
Operate and maintain the vulnerability-management platform.
-
Ensure container images are scanned and patched on a defined cadence.
-
Maintain supply-chain scanning tooling and its severity-classification configuration.
-
Define and enforce remediation SLAs.
-
Own cloud security across multiple providers.
-
AWS, GCP, and Azure hardening, logging, and service-account governance.
-
Own Kubernetes and service-mesh security.
-
Operate the service mesh and maintain the policy-as-code rollout.
-
Audit and secure infrastructure in newly added environments.
-
Review build pipelines and infrastructure in newer parts of the business as they come online, and remediate findings.
-
Contribute to security architecture and design review.
-
Review new integrations and internal systems for security risk.
-
Support workforce and endpoint security.
-
Contribute to VDI and browser-isolation initiatives as the program matures.
-
Use coding agents for first-pass review of infrastructure-as-code, container configuration, and cloud policy.
Key Priorities for the First 6 Months
-
Weeks 1β2: Onboard to the cloud environment, Kubernetes architecture, and existing security tooling.
-
Month 1: Establish ownership of the vulnerability-management process; findings triaged and remediated on a defined cadence.
-
Month 2: Complete configuration of supply-chain scanning tooling; implement automated image scanning and patching; deploy initial policy-as-code rules.
-
Month 3: Complete policy-as-code rollout in at least one environment; begin infrastructure audits in newly added environments.
-
Month 4: Close outstanding cloud logging and service-account gaps; establish and enforce a documented multi-cloud hardening baseline.
-
Months 5β6: Full ownership of infrastructure and cloud security as a domain; independently deliver security-architecture design reviews.
Core Tech Stack
-
Kubernetes and service mesh
-
Policy-as-code tooling (Kyverno/OPA)
-
Terraform
-
AWS/GCP/Azure
-
Vulnerability-management and supply-chain scanning platforms
-
Container tooling
-
CI/CD
-
Git
Detections and access rules are managed as code through pull requests. Familiarity with coding/agentic tools for infrastructure review is expected.
Qualifications
-
Production experience hardening cloud infrastructure (IAM, logging, service accounts, network security, on at least one major cloud provider; multi-cloud experience is a plus).
-
Kubernetes and container security (service mesh and policy-as-code).
-
Vulnerability-management experience (SCA/SAST tooling and SLA-driven remediation practice).
-
Fluency with coding agents (experience using agentic tools for infrastructure-as-code review or investigation work).
-
Ability to work independently at a senior level (defining scope and priorities without detailed direction).
-
Clear written and verbal communication (able to run design reviews and communicate risk to engineers and leadership).
Nice to Have, None Required
-
Experience securing multi-tenant or multi-identity-domain environments.
-
Supply-chain security tooling (SBOM, Socket, JFrog, or similar).
-
Secure-SDLC or AppSec experience.
-
Terraform/IaC at scale.
-
Relevant certifications (e.g. AWS/GCP/Azure security specialties, CKS).
Benefits
-
Contract (B2B) collaboration, with a path into a project team if things go well.
-
Flexible, fully remote schedule (40 hours per week).
-
Work at the leading edge of AI development, alongside a dedicated and dynamic team of experts.
-
Projects with customers that are AI industry leaders and well-known household names.
-
Friendly community.