ESG News

ESG News

ESG News operates as a pioneering ESG media platform in Bulgaria, providing comprehensive news and insights on sustainability, ESG investing, events, and policy developments.

Internet Software & Services
11-50
Founded 2022

Description

  • Tune and evolve application security guardrails such as SAST, software composition analysis, secret scanning, and related controls to reduce noise and improve actionability.
  • Improve cloud and infrastructure-as-code security guardrails across AWS environments and CI/CD workflows.
  • Drive vulnerability management across application vulnerabilities, dependency risks, bug bounty findings, penetration test findings, and third-party advisories.
  • Help teams identify, own, prioritize, and remediate cloud misconfigurations using pragmatic, developer-friendly workflows.
  • Run lightweight, practical threat-modelling sessions for new products, features, services, and architectural changes.
  • Build scripts, integrations, dashboards, and other automation that reduce manual effort and improve visibility into security risk.
  • Provide security input into application and cloud design reviews, AWS architecture decisions, and larger technical changes.
  • Partner closely with product, platform, and engineering teams to embed security into design, delivery, and operations.
  • Support incident response and feed lessons learned back into patterns, tooling, and guidance.
  • Mentor security engineers and coach engineering teams; may include line management of one or two security engineers.

Requirements

  • Practical experience across both application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritization, ownership, remediation tracking, and noise reduction.
  • Experience improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning, or improving security tooling in CI/CD workflows such as SAST, software composition analysis, secret scanning, or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery, or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills with the ability to influence engineers and technical leaders without gatekeeping.
  • Evidence of improving application security, cloud security, or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.
  • Experience leveraging AI for AppSec and CloudSec, which is desirable but not essential.
  • AWS Certified Security – Specialty or equivalent practical AWS security experience.
  • Terraform or CloudFormation expertise is desirable.
  • Incident-management or incident-response experience is desirable.
  • Experience with Splunk or similar logging/SIEM platforms is desirable.
  • Experience with security metrics, dashboards, or reporting that helped drive measurable risk reduction is desirable.
  • Experience mentoring or line-managing security engineers is desirable.

Benefits

  • A warm, collaborative culture with support for your growth, career aspirations, and wellbeing.
  • The opportunity to reach millions and create work that matters at a globally recognized news organization.
  • A commitment to diversity, equity, and inclusion, including efforts to remove barriers for underrepresented groups.
  • Reasonable adjustments and personalization during the application and interview process for candidates with disabilities.
  • Support from a disability confident employer and Valuable 500 signatory.
  • Flexibility to use AI tools to assist with the application process, provided all information is authentic and accurate.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Technician

Unlimited Technology 51-250 Professional Services

Unlimited Technology is hiring a full-time Security Installation Technician to install, program, troubleshoot, and maintain access control and IP camera systems at client sites.

1 hour, 17 minutes ago

Senior Information Security Engineer – Data

Rubrik 1K-5K IT Services

Rubrik is hiring a Senior Security Engineer to operate its SIEM environment and help build a Security Data Lake platform that supports security monitoring, analytics, and automated SecOps across a global multi-cloud footprint.

AWS Azure CI/CD Databricks Elasticsearch GCP Kubernetes LLM Python SIEM Snowflake Splunk Terraform
1 hour, 32 minutes ago

Senior Product Security Analyst

Omilia 251-1K IT Services

Omilia is hiring a Senior Product Security Analyst to own product and application security reviews across the software lifecycle, helping protect cloud-based SaaS products, platforms, and customers as the company scales.

Agile AWS Microservices Penetration Testing
2 hours, 39 minutes ago

Senior Technical Security Application Engineer, Secured Spaces

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Senior Technical Security Application Engineer to own the design, commissioning, and lifecycle sustainment of intrusion detection and access control systems for secured spaces supporting its defense technology operations.

3 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers