Senior Cloud Application Security Engineer

6 dni temu


Warsaw, Polska Sportradar Pełny etat
Job Description

Senior Cloud Application Security Engineer

Location: Warsaw (Hybrid) or Anywhere from Poland (Remote)

Sportradar is the leading global provider of sports data and entertainment products and services. Since 2001, we have occupied a unique position at the intersection of the sports, media and betting industries; providing sports federations, news media, consumer platforms and sports betting operators with a range of solutions to help grow their business.

The Information Security group provides services to ensure confidentiality, integrity and availability of information and systems owned by Sportradar and its subsidiaries.

The Product Security unit within Information Security works primary with the Engineering group to ensure that the products & services developed by its Tribes are Secure-by-Design and remain Secure-in-Production. This includes coaching developers on secure development practices, building products for our cloud environment that help developers prevent vulnerabilities and misconfigurations arising over time, and managing the attack surface so that engineers can focus their remediation efforts on the highest criticality vulnerabilities specific to Sportradar’s risk profile. We also run an external Bug-Bounty programme for in-scope applications, as well as a Security Champions community across Sportradar.

ROLE OVERVIEW:

The Senior Cloud Application Security Development professional will be part of the Secure Software Development team within Product Security, dedicated to fixing identified application-level vulnerabilities whilst coaching Tribe members in secure development practices. The successful candidate will work in a consultative capacity across multiple tribes, so should be comfortable in dipping in to help solve different problems with different teams, nationalities, and locations. Excellent technical, interpersonal and communications skills are key to this role.

In addition to working with Tribes, the successful candidate should also be comfortable in developing tools and utilities to improve the security of cloud resources whilst not hindering developer productivity.

The role will report into the Senior Manager, Product Security and will be part of a multidisciplinary team of developers with experience in Secure Software Development (SSD) and Attack Surface Management (ASM) to deliver initiatives and guiding principles that will help identify and mitigate vulnerabilities within the products that Sportradar develops. The Senior Cloud Application Security Development professional will also work closely with 3rd parties (e.g. Bug Bounty programme) as well as other teams within the wider Security group (e.g. GRC, SOC, etc.).

THE CHALLENGE:

  • Respond to identified vulnerabilities in our applications and cloud environments without jeopardizing product roadmap.
  • Evangelize and coach engineers on secure design & development practices through threat modelling and help remediate findings through pair-programming sessions.
  • Cross pollination of secure development techniques and best practices across engineering tribes.
  • Collaborate across both SSD and ASM teams in Product Security to ensure unit initiatives are successfully delivered.
  • Be on-hand to assist colleagues as part of our incident response process should this be required.

YOUR PROFILE:

Personal Requirements:

  • You get excited by challenges, and have a positive, can-do attitude in working with different teams, locations and technologies to achieve the best outcome.
  • You are interested in cloud and application security and thrive on having multiple problems to solve, together with a continuous learning mindset.
  • You enjoy diving in and figuring the crux of a problem quickly and helping provide a pragmatic solution to the team, whilst efficiently communicating the outcome to techies and managers alike.
  • You are comfortable with mentoring others and taking a lead role for an initiative to help deliver the intended outcomes.

Professional Requirements:

  • Degree in software development, or other relevant experience.
  • 10+ years of experience as a software developer or DevOps professional.
  • Ability to manage, prioritize, remediate vulnerabilities like those on the OWASP Top10 list.
  • Excellent knowledge in at least one of the object-orientated programming languages like Java, .NET, and scripting languages like Python, JavaScript, etc.
  • Experience with AWS cloud services, especially their security products.
  • Experience with modern technologies like Kubernetes, Protobuf, gRPC, and GraphQL.
  • Experience with automated deployments and containerized application management.
  • Experience with message brokers (e.g. Kafka), and relational databases (e.g. MySQL.
  • A keen interest in continuous professional learning across software engineering, cloud, and application security domains.
  • Working in agile development teams in a fast-paced environment.
  • Excellent inter-personal and communication skills with fluency in English (written & spoken).
  • Ability to take a lead role in the team, supervising and/or mentoring others.

Desirable requirements:

  • Cloud-native development and/or experience with other public & hybrid cloud services (GCP, OCI, etc).
  • Hands-on experience with Cloud & Software Security and DevSecOps tooling such as CNAPP, SAST and SCA.
  • Experience with maintaining large-scale and fault-tolerant distributed systems in production.
  • Experience with test-driven development.

 

OUR OFFER:

  • The opportunity to work and develop within an inspiring and fast-growing company, with different teams working on different products in different locations.
  • The possibility to directly contribute to the security of products used by our clients in the global sports business.
  • Consultative role with multiple teams across different geographies and product lines, where no one problem is the same.
  • A collaborative environment with colleagues from all over the world (engineering offices across Europe, in Asia and the US).
  • Competitive salary and benefits (e.g. retirement pension and insurance plan).

 


Additional Information

Sportradar is an Equal Opportunity Employer. We are committed to encourage diversity within our teams. All qualified applicants will receive consideration without regard to among other things, your background, status, or personal preferences 



  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionSenior Cloud Application Security EngineerSportradar is the leading global provider of sports data and entertainment products and services. Since 2001, we have occupied a unique position at the intersection of the sports, media and betting industries; providing sports federations, news media, consumer platforms and sports betting operators...


  • Warsaw, Polska Sportradar Polska Sp. z o.o. Pełny etat

    About the RoleWe are seeking a highly skilled Senior Cloud Application Security Engineer to join our team at Sportradar Polska Sp. z o.o. The successful candidate will be responsible for ensuring the security of our cloud-based applications and infrastructure.Key ResponsibilitiesRespond to identified vulnerabilities in our applications and cloud environments...


  • Warsaw, Polska Sportradar Polska Sp. z o.o. Pełny etat

    technologies-expected : Java .NET Python JavaScript AWS Kubernetes Protobuf gRPC GraphQL MySQL Kafka technologies-optional : Google Cloud Platform about-project : The Senior Cloud Application Security Development professional will be part of the Secure Software Development team within Product Security, dedicated to fixing identified application-level...


  • Warsaw, Polska XPERI Poland Pełny etat

    technologies-expected : C Java responsibilities : Collaborate with Development and Operation Teams to build and operate secure products. Maintain the trust of Customers by protecting sensitive data and protecting the Organization from breaches. Conduct Security reviews and Threat Modeling. Help integrate security tools and processes. Respond to Security...


  • Warsaw, Polska The Stepstone Group Polska sp. z o.o. Pełny etat

    technologies-expected : Python Bash AWS Microsoft Azure Google Cloud Platform about-project : As an Application Security Engineer, you will play a pivotal role in safeguarding our organization's applications and data. You will work closely with development teams to integrate security tools into our CI/CD pipelines, ensuring that security is baked into the...

  • Cloud Security Engineer

    3 miesięcy temu


    Warsaw, Polska Sii Sp. z o.o. Pełny etat

    technologies-expected : SAST DAST Container Scanning Cloud Apps Security DevOps/SecOps technologies-optional : Tanable about-project : We are seeking a skilled and motivated Cloud Security Engineer to join our dynamic Cybersecurity team. This role requires a deep understanding of solutions within the Container Security, and the openness to share knowledge...


  • Warsaw, Polska myGwork Pełny etat

    This job is with Box, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. WHAT IS BOX? Box is the world's leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders...


  • Warsaw, Polska myGwork Pełny etat

    About BoxBox is the world's leading Content Cloud, trusted by more than 115,000 organizations worldwide, including nearly 70% of the Fortune 500. We empower our customers to transform workflows across their organizations by bringing intelligence to the world of content management.Job DescriptionWe are seeking an Application Security Engineer with a strong...


  • Warsaw, Polska capital.com Pełny etat

    We are a leading trading platform that is ambitiously expanding to the four corners of the globe. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talent team. We are currently looking...


  • Warsaw, Polska myGwork Pełny etat

    Job DescriptionThis role is with Box, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.What is Box?Box is the world's leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500...

  • Application Security Expert

    4 miesięcy temu


    Warsaw, Polska T-Mobile Polska S.A. Pełny etat

    Opis stanowiska: ·        Identify opportunities to automate and standardize application security controls and cooperate with the CICD team ·        Analyze source code to mitigate identified weaknesses and vulnerabilities ·        Create guidelines and application security standards ·        Review and check...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...


  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the world’s leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.By...

  • Application Security Expert

    4 miesięcy temu


    Warsaw, Polska T-Mobile Pełny etat

    technologies-expected : AWS HTTP HTML5 AJAX REST Kubernetes about-project : T-Mobile Poland is a leader in telecommunication, dedicated to providing innovative solutions that drive growth and efficiency for our clients. Our commitment to security and integrity is at the forefront of our operations, and we are seeking a talented Application Security Expert...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team.The Anti-abuse team at Snowflake is responsible for protecting Snowflake and our customers from abuse on the Snowflake platform. You will have the opportunity to help set the direction for the anti-abuse roadmap and technical direction at Snowflake. We’re at the forefront of the data revolution,...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team. The Anti-abuse team at Snowflake is responsible for protecting Snowflake and our customers from abuse on the Snowflake platform. You will have the opportunity to help set the direction for the anti-abuse roadmap and technical direction at Snowflake. We’re at the forefront of the data revolution,...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team. Senior Cloud Support Engineer - Database Security and Authentication Management Snowflake Support is committed to providing high-quality resolutions to help deliver data-driven business insights and results. We are a team of subject matter experts collectively working toward our customers’...


  • Warsaw, Polska Robert Bosch Sp. z o.o. Pełny etat

    Job Title: Senior Network Security EngineerRobert Bosch Sp. z o.o. is seeking a highly skilled Senior Network Security Engineer to join our team.Job Summary:We are looking for a seasoned Network Security Engineer to implement and operate solutions that meet our internal customers' needs. The ideal candidate will have a strong background in network...


  • Warsaw, Polska Mindbox S.A. Pełny etat

    Creating an inspiring place to thrive for the talented, we use their expertise and courage to introduce the technology of the future into your business. - This is the foundation of  Mindbox  and the goal of our business and technology journey. We operate and develop in four areas: Autonomous Enterprise  - automation of business processes using RPA, OCR,...


  • Warsaw, Polska SIMCORP SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ Pełny etat

    technologies-expected : PowerShell C# Azure DevOps about-project : SimCorp is building a new team, who will be responsible for developing and maintaining a new landing zone deployment, where eventually all of our corporate IT and development infrastructure will live. The new team will handle administration and deployment in the Azure environment, with...