התפקיד במילים פשוטות
תפקיד ארכיטקט אבטחת מידע במחלקת אבטחת המידע של החברה, העובד בצמוד לצוותי פיתוח, מוצר ו-DevOps. התפקיד כולל ביצוע סקירות ארכיטקטורת אבטחה, הובלת מודלי איומים, והגדרת תקני אבטחה בענן ובאפליקציות. כמו כן, בעל התפקיד יעבוד על אבטחת ענן ב-AWS ועל שמירת בטיחות המערכות של החברה.
למי זה מתאים
התפקיד מתאים לבעלי ניסיון של 5 שנים לפחות בארכיטקטורת אבטחה או בשילוב פיתוח ואבטחה, עם ניסיון מעשי באבטחת AWS ו-DevSecOps/אבטחת אפליקציות. התפקיד פחות מתאים למי שחסר ניסיון טכני מעשי בענן ובסקירת קוד ואוטומציות אבטחה.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןGlobal-e (Nasdaq: GLBE) is the world’s leading platform for global direct-to-consumer e-commerce, enabling brands and retailers to seamlessly sell worldwide, delivering localized experiences across markets. Trusted by some of the world’s most recognized brands including Adidas, Alo Yoga, Logitech, Hugo Boss, Marc Jacobs, and Victoria’s Secret, we operate on a massive global scale through dynamic teams across North America, EMEA, and APAC. Our technology-based end-to-end solution combines advanced localization capabilities, streamlined global operations and extensive big-data analytics, covering everything merchants need to scale worldwide. We’re a fast-moving, highly collaborative company where innovation, creativity, ownership, and impact are part of everyday work. We're looking for a Security Architect to join Global-e's Information Security department. You will work closely with the Product, R&D, DevOps and IT teams and serve as the focal point for identifying and resolving complex security challenges and owning the secure design of internal applications and cloud infrastructure from the ground up. This is a hands-on Architect position that ensures Global-e products and work environment adhere to the stringent security. Responsibilities • Own security architecture reviews for internal applications, new features, and 3rd party integrations • Lead threat modeling sessions with R&D and Product teams throughout the SDLC • Define and maintain security design standards across authentication, authorization, networking, and application layers • Be the go-to expert for cloud security on AWS, including IAM, network segmentation, and workload protection • Embed security gates into existing agile and DevOps workflows without killing velocity • Work closely with DevOps and IT on secure-by-default cloud and corporate environment configurations • Lead risk-based remediation programs across architecture findings • Advise the CISO on evolving threats relevant to our stack and business model • Identify and propose capability improvements across the security architecture
Requirements: • 5+ years in security architecture or a role combining development and security • Hands-on experience with AWS security (IAM, VPC, security groups, guardrails) • Strong understanding of security architecture best practices, standards, and frameworks • Including authentication/authorization (OAuth, OIDC, SAML, RBAC/ABAC), application security (OWASP Top 10), and network security • At least 2 years of Application security or DevSecOps experience • Familiarity with AI/LLM concepts from a security risk perspective • Certifications (CISSP, CISM, OSCP) - advantage
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי