ESG News

ESG News

ESG News operates as a pioneering ESG media platform in Bulgaria, providing comprehensive news and insights on sustainability, ESG investing, events, and policy developments.

Internet Software & Services
11-50
Founded 2022

Description

  • Tune and evolve application security guardrails such as SAST, software composition analysis, secret scanning, and related controls to reduce noise and improve actionability.
  • Improve cloud and infrastructure-as-code security guardrails across AWS environments and CI/CD workflows.
  • Drive vulnerability management across application vulnerabilities, dependency risks, bug bounty findings, penetration test findings, and third-party advisories.
  • Help teams identify, own, prioritize, and remediate cloud misconfigurations using pragmatic, developer-friendly workflows.
  • Run lightweight, practical threat-modelling sessions for new products, features, services, and architectural changes.
  • Build scripts, integrations, dashboards, and other automation that reduce manual effort and improve visibility into security risk.
  • Provide security input into application and cloud design reviews, AWS architecture decisions, and larger technical changes.
  • Partner closely with product, platform, and engineering teams to embed security into design, delivery, and operations.
  • Support incident response and feed lessons learned back into patterns, tooling, and guidance.
  • Mentor security engineers and coach engineering teams; may include line management of one or two security engineers.

Requirements

  • Practical experience across both application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritization, ownership, remediation tracking, and noise reduction.
  • Experience improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning, or improving security tooling in CI/CD workflows such as SAST, software composition analysis, secret scanning, or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery, or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills with the ability to influence engineers and technical leaders without gatekeeping.
  • Evidence of improving application security, cloud security, or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.
  • Experience leveraging AI for AppSec and CloudSec, which is desirable but not essential.
  • AWS Certified Security – Specialty or equivalent practical AWS security experience.
  • Terraform or CloudFormation expertise is desirable.
  • Incident-management or incident-response experience is desirable.
  • Experience with Splunk or similar logging/SIEM platforms is desirable.
  • Experience with security metrics, dashboards, or reporting that helped drive measurable risk reduction is desirable.
  • Experience mentoring or line-managing security engineers is desirable.

Benefits

  • A warm, collaborative culture with support for your growth, career aspirations, and wellbeing.
  • The opportunity to reach millions and create work that matters at a globally recognized news organization.
  • A commitment to diversity, equity, and inclusion, including efforts to remove barriers for underrepresented groups.
  • Reasonable adjustments and personalization during the application and interview process for candidates with disabilities.
  • Support from a disability confident employer and Valuable 500 signatory.
  • Flexibility to use AI tools to assist with the application process, provided all information is authentic and accurate.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IoT & OT Network Engineer Associate

Nebius 51-250 Internet Software & Services

Nebius is hiring a Junior IoT & OT Network Engineer to support secure connectivity and network security for IoT, OT, and corporate environments within its Cyber Security organization.

DNS IoT Linux Network Security TCP/IP Wireshark
2 hours, 39 minutes ago

Security Engineer, DevSecOps - Mexico

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a remote Security Engineer for its DevSecOps team in Mexico to design and build cloud security automation, detection, and vulnerability management solutions that protect the company’s data and infrastructure.

AWS DevSecOps GCP GitHub Actions Go Python SIEM Terraform
8 hours, 4 minutes ago

Head of Security

Label Your Data 51-250 Internet Software & Services

Label Your Data is hiring a Head of Security to build and lead its standalone security function, owning security operations, strategy, and maturity while collaborating with the group security team.

Cybersecurity SIEM
9 hours ago

Anti-Bot Engineer (Remote, Full-Time) [HR177]

Smart Working Internet Software & Services

Smart Working is hiring a senior Anti-Bot Engineer to build and operate large-scale web scraping systems that reliably extract data from highly protected, fast-changing websites.

Docker Go HTTP JavaScript Kubernetes Playwright Puppeteer Python Rust Selenium
9 hours, 1 minute ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers