Senior Infrasructure Security Engineer

$$$$
🇺🇦 Ukrainian Product

At MacPaw, we craft software that makes everyday tech life simpler, cleaner, and more enjoyable. From globally loved products like CleanMyMac and Setapp to emerging cybersecurity tools like ClearVPN and Moonlock, we are building a product ecosystem that reaches millions of people worldwide.

 

We’re looking for a Senior Infrastructure Security Engineer to join our Information Security Team, supporting MacPaw’s product ecosystem as we transition to our next-generation setup.

 

Our Security and Infrastructure teams ensure that all MacPaw products run on a highly resilient, compliant, and rock-solid foundation, protecting user data and business operations at scale.

 

As a Senior Infrastructure Security Engineer, you will take dedicated ownership of securing our production infrastructure, establishing compliance control baselines, and maintaining a strong security posture. You’ll define, test, and coordinate security frameworks across bare-metal environments and GCP, working hand-in-hand with our SRE team as a technical peer and security partner.

 

If you’re excited to take ownership of MacPaw’s infrastructure security, reduce automated evidence coverage gaps, and collaborate on advanced CNAPP tools and agentic AI automation, we’d love to hear from you!

 

In this role, you will:

 

  • Participate in Wiz CNAPP service adoption.
  • Drive Kubernetes and cloud posture hardening across GCP, including RBAC reviews, admission control, network policies, and runtime threat detection.
  • Take ownership of the infrastructure vulnerability backlog, driving remediation down against severity-based SLAs in close collaboration with SRE.
  • Build and ship agentic AI security automation into code-reviewed repositories to streamline vulnerability management and operational security workflows. 
  • Collaborate closely with the SRE team to embed security controls into CI/CD pipelines and Infrastructure-as-Code without adding unnecessary friction.

 

Skills you’ll need to bring:

 

  • Strong expertise in Infrastructure-as-Code and automation using Terraform.
  • Python or Go skills to build security tooling rather than just filing tickets.
  • Hands-on experience with incident management, threat containment, and root cause analysis (RCA) for infrastructure security incidents.
  • Demonstrated ability to work with Service Reliability Engineers (SRE) team as a technical peer, driving security engineering through influence and shared goals.
  • Hands-on production cloud security experience at scale on GCP (IAM least privilege, network segmentation, runtime detection, and posture hardening).
  • In-depth Kubernetes security experience in production: RBAC, admission control (OPA/Kyverno), network policies, runtime detection, and image provenance.
  • Proven experience in bare-metal and self-hosted Linux infrastructure security (host-based controls, Linux hardening, and multi-tenancy risk mitigation outside managed cloud).
  • Experience in infrastructure vulnerability management: triage, SLA management, and driving remediation through engineering teams.
  • Ability to write and ship agentic AI automation into production repositories to enhance security operations.
  • At least an Upper-Intermediate level of English and fluent Ukrainian.

 

As a plus:

 

  • Experience securing agentic AI systems in production (prompt injection, tool poisoning across MCP, human-in-the-loop approval flows, and kill switches).
  • Experience with CNAPP/CSPM platform migrations or ownership (Wiz, Sysdig, Orca, or Prisma Cloud).
  • Experience with NixOS or other immutable Linux distributions.
  • Familiarity with Cloudflare edge security controls.
  • Experience operating within environments under active ISO 27001 or SOC 2 Type II compliance frameworks.
  • Relevant security certifications as signal (CKS, OSCP, GCP Professional Cloud Security).

 

What we offer:

 

  • We are a Ukrainian company, and we stand with Ukraine against the russian aggression
    We maintain workplaces for the mobilized Macpawians and provide financial support to colleagues or their families affected by the war. Here, you can also read about the MacPaw Foundation, which intends to help save the lives of Ukrainian defenders and provide relief to as many civilians as possible.
  • We are committed to our veterans
    Our Veteran Career and Empowerment Program is designed to ensure our veterans and active military personnel receive the recognition, support, and opportunities they deserve.
  • Hybrid work model
    Whether to work remotely or at the hub is entirely up to you. If you decide to mix it, our Kyiv office, which works as a coworking space, is open around the clock. The office is supplied with UPS and Starlink for an uninterrupted work process.
  • Your health always comes first
    We guarantee medical insurance starting on your first working month. For those abroad, you can receive a yearly Medical insurance allowance as compensation for managing your medical expenses.
  • Flexible working hours
    You can choose a schedule that is comfortable for you. No one here tracks your clock in/out because MacPaw is built on trust and cooperation.
  • Space to grow both professionally and personally
    Education opportunities to grow both hard and soft skills, annual development reviews, and internal community.
  • Teams we are proud of
    We build honest, transparent, and reliable relationships within teams. Every Macpawian can improve processes and implement their ideas. We encourage open and constructive feedback and provide training for Macpawians on giving and receiving feedback.
  • Office designed for people (and pets)
    Our office has it all: a spacious workplace with enough room for sitting up, lying down, and running around; a gym for recreation; cozy kitchens; a sleeping/meditation room; and a terrace with a view where we throw summer parties. Also, we have two cats living in the office, and you are welcome to bring your pets to the office (we have separate floors for cats and dogs).
  • Time-off policy that covers life’s needs
    Convenient personal time-off policy to help you take care of essential matters in your personal life, and parental leaves. On top of all that, sabbaticals are open after 5 years of being with MacPaw.
  • Join social initiatives with MacPawCares
    MacPaw participates in numerous humanitarian aid and charity projects across many fields, and you are welcome to jump in to make the world a better place.
  • We’re an equal-opportunity employer. Here is a safe place for applicants of all backgrounds
    We are hiring talented humans. Meaning with all our variety of backgrounds and identities, including service members and veterans, women, members of the LGBTQIA+ community, individuals with disabilities, and other often underrepresented groups. MacPaw does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

    *Some benefits are under development, and new adjustments are possible.

Required skills experience

Terraform 4.5 years
IaC 4.5 years
Kubernetes 4.5 years
Python 4.5 years
RCA 4.5 years
Linux 4.5 years

Required languages

English B2 - Upper Intermediate
Ukrainian Native
Golang
Published 19 August
17 views
·
1 application
To apply for this and other jobs on Djinni login or signup.
Loading...