16 ago
|
Preply
|
Barcelona
Se pueden requerir diversas habilidades interpersonales y experiencia para el siguiente puesto. Por favor, asegúrese de consultar la descripción a continuación con atención. and it’s creating real impact.As a category-defining company, we’re shaping what the future of learning looks like at global scale.Every Preply lesson sparks change, fuels ambition, and drives progress that matters.
Joining
Preply means helping define the future of education at general scale, and building something that truly matters for millions of people, every day.The Security team partners across the company to help Preply grow safely and sustainably. We are responsible for platform security, application and product security, security operations, and incident response. We work closely with SRE, Data teams, Engineering teams, and our GRC function to make security practical, measurable, and scalable.We’ve reached 90%+ adoption of AI coding tools across engineering, and we’re now moving towards more autonomous, AI-Augmented development at scale. sometimes we write about them in our Engineering Blog!
Please, also visit our Tech Radar and our YouTube channel to learn more about the technologies we use at Preply!Own platform security across AWS, Kubernetes, and GCP, with a strong focus on detection, alerting, and incident response readinessLead key platform security initiatives end-to-end, from problem definition through rollout and iterationAct as a strong technical voice in defining how platform security is designed, implemented, and operated at PreplyEvolve our monitoring from “we have a SIEM” to a detection and response capability that is effective, trusted, and actionableWork hands-on with our current tooling, including Datadog as our SIEM, Okta as our primary IdP, and a range of SaaS platformsDrive cross-functional platform security initiatives from problem definition to production rollout, partnering with SRE, Data, Engineering, and GRCStrengthen cloud and platform security across AWS and Kubernetes, with expanding scope in GCP,
through practical guardrails, secure patterns, and automationImprove the robustness of access to internal infrastructure, including identity, privileged access, and auditabilityImprove security of Kubernetes deployments, including cluster and workload security, policy enforcement, and secure workload identity patternsMature detection and response capability using DatadogImprove log coverage and data quality (cloud, Kubernetes, CI/CD, identity, and key SaaS)Build and tune actionable detections with clear severity, ownership, and expected frequencyReduce noise through correlation, deduplication, enrichment, and continuous tuningEstablish repeatable triage workflows and clear escalation paths, being part of the Security on-call rotationsCreate investigation playbooks and runbooks so alerts can be handled consistently and quicklyPartner with Data teams to improve monitoring for suspicious activity and sensitive access patterns, with an emphasis on practical, high-signal alertingImprove secrets management and reduce exposure risk across CI/CD and runtimeBuild security automation that makes the secure path the easy path for engineersWhat you need to succeed:Strong experience securing cloud and platform environments, especially AWS and Kubernetes, and the ability to extend that security approach into GCPHands-on experience driving and delivering technical security initiatives end-to-end in production environmentsStrong understanding of the software development lifecycle, and comfort working with CI/CD and infrastructure as codePractical experience improving identity and access security,
with strong familiarity with Okta event monitoring and identity-focused detection patternsExperience building or maturing security operations capability, especially turning SIEM inputs into reliable operational outcomes (triage, runbooks, tuning, and measurable improvement)Experience improving logging coverage and signal quality, and building detections that are actionable rather than noisy (experience with Datadog SIEM is a plus)Strong collaboration skills and the ability to influence decisions across SRE, Data, Engineering, and GRCBusiness-oriented mindset and comfort making cost-benefit tradeoffsStrong communication skills. Minimum C1 English level.Terraform and infrastructure as code at scaleJenkins hardening and CI/CD supply chain security controlsCloudflare security controls (WAF, bot mitigation, edge protections)Scripting or programming for automation and toolingIncident response experience in cloud-native environments (AWS and Kubernetes)Why you’ll love it at Preply:An open, collaborative, dynamic and diverse culture;A generous monthly allowance for lessons on , Learning & Development budget and time off for your self-development;A competitive financial package with equity, leave allowance and health insurance;We offer an attractive relocation package to join us in our Preply Barcelona HubAccess to free mental health support platforms;We do it for learners - To create an outstanding customer experience, we focus on simplicity, smoothness, and enjoyment, continually perfecting it as every detail matters.In a fast-paced world, it matters how quickly we act. We proactively seek growth opportunities and believe today's best performance becomes tomorrow's starting point.
Raise the bar - We raise our performance standards continuously, alongside each new hire and promotion. We value open and candid communication, even when we don’t fully agree. We believe that the presence of different opinions and viewpoints is a key ingredient for our success as a multicultural Ed-Tech company.
📌 Senior Security Engineer (Barcelona)
🏢 Preply
📍 Barcelona