¡Activa las notificaciones laborales por email!

Vulnerability Management Security Engineer

eBay Inc

León

Híbrido

EUR 40.000 - 70.000

Jornada completa

Hace 7 días
Sé de los primeros/as/es en solicitar esta vacante

Mejora tus posibilidades de llegar a la entrevista

Elabora un currículum adaptado a la vacante para tener más posibilidades de triunfar.

Descripción de la vacante

A leading company in digital marketplaces is seeking a Secure Product Lifecycle Engineer to enhance their product security measures. This role involves collaborating with various teams to enforce industry-standard security protocols and automating security controls across cloud operations. The ideal candidate will possess strong analytical skills and a hacker mindset, with proficiency in cloud technologies like AWS. Joining this team means contributing to a more secure and sustainable future.

Servicios

Annual bonus
Work From Anywhere policy
24/7 Employee Assistance Program
Collaborative work environment

Formación

  • Proficient in cloud operations, particularly AWS.
  • Strong understanding of security capabilities.
  • Excellent knowledge of network, protocol, and application security.

Responsabilidades

  • Develop and maintain automation of security controls.
  • Advise stakeholders and support remediation of issues.
  • Ensure assets report events to the SIEM.

Conocimientos

Application Security
Network Security
Problem Solving
Cloud Operations
Automation

Educación

Degree in Computer Science or related field
Certifications in Security

Herramientas

AWS
GitHub Actions
Kubernetes

Descripción del empleo

We’re Adevinta , a global leader in digital marketplaces. Our household name brands, including Marktplaats in the Netherlands, mobile.de in Germany and leboncoin in France, reach hundreds of millions of people every month.

We’re all about matchmaking, and our sites help people find whatever they’re looking for in their local communities – whether it’s a car, an apartment, a sofa or a new job. Every connection made or item found makes a difference by creating a world where people share more and waste less.

Our brands are supported by global Tech Hubs in Barcelona, Amsterdam, Paris and Berlin. Their goal is to develop common global products and innovation platforms which all of our brands can use. This means using cutting edge technology to create highly scalable, customisable and secure products and components that free up development time and leverage our access to global data.

What you’ll do & Who you are

As a Secure Product Lifecycle engineer, you will be part of the company’s Product Security team. This role is crucial in that it conditions the security measures put in place on products that handle our data and provide our services to our clients. This position requires autonomy and pro-activeness, a deep understanding of application security, network security, as well as proficiency in development and operations in the cloud.

You will be instrumental in ensuring that Adevinta’s security strategy covers industry-relevant security standards, leaving no gaps open to be exploited. The Product Security team is part of the Information Security department, where your team will collaborate with other services such as Vulnerability Management, Bug Bounty, Incident Response, and Governance. You may also be called on to interact with product development teams to help them secure their products.

What you will do :

  • You will recommend and evaluate secure baselines and controls (guardrails, alerts, audit controls) to prevent or detect and remediate misconfigurations across our cloud runtimes, CI / CD pipelines, artifact repositories, code repositories, SSO systems, and IAM systems.
  • You will develop, deploy and maintain automation of such controls, using SCP, AWS Config, SCA, SBOM, Dependabot, GitHub Actions, as well as other commercial, open-source, or custom tools.
  • You will automate internal flows for security data aggregation.
  • You will integrate security tools by automated means.
  • You will automate the handling of threat intelligence and environment data in order to enhance security controls.
  • You will provide advice concerning your domains of expertise to internal stakeholders, by attending guilds, answering questions, writing documentation, supporting audits, and by supporting remediation of issues found by our tools or by external resources.
  • You will ensure our assets are properly reporting events to the SIEM, and support the definition of rules for generating alerts.
  • You will support the other Infosec teams as a subject-matter expert.
  • You will report to the Secure Product and Platform Lifecycle manager.
  • You will work in a hybrid remote / on-site environment, with the team physically spread across different geolocations (Adevinta’s hubs : Barcelona & Amsterdam).
  • You may be required to travel occasionally, mainly inside the EU, to our main hubs.
  • You may be asked to be on-call.

Who you are :

  • You have a hacker mindset, an open mindset, with technical skills and a passion for security.
  • You have strong analytical and problem-solving skills, with the ability to synthesise complex data into actionable insights.
  • You recognise the need for automation to handle problems at scale, and you can implement that automation.
  • You are proficient in cloud operations, particularly in AWS but ideally also in GCP.
  • You have an excellent understanding of security capabilities and controls such as GuardRails, SCPs, Security Groups, IAM, WAF, AntiBot, SSO, etc.
  • You can apply the Secure Development Lifecycle principles with modern tooling and ecosystems such as Github, Github Actions, Dependabot, Kubernetes, infrastructure as code, etc.
  • You have excellent fundamental knowledge of network, protocol, system and application security, as well as of the industry-standard strategies and frameworks that apply.
  • You have software development skills and database knowledge.
  • You have excellent communication and interpersonal skills, with the ability to build relationships and influence others.
  • You deal with problems by taking ownership and by collaborating with others.
  • You are fluent in English (spoken and written).
  • You are comfortable in a multicultural environment.

Nice to have :

  • Proficiency in threat modelling
  • Notions of incident response.
  • Public or private presentations.
  • Participation in conferences and training.
  • Certifications.
  • Membership in bug bounty programs, CTF player or member of ethical hacking communities, recognition in the Hall of Fame, CVE mentions or vulnerability reporter.

Life at Adevinta comes with its perks! Our Adevintans enjoy the following benefits :

  • Participation in our Short Term Incentive plan (annual bonus)
  • Work From Anywhere : Enjoy up to 20 days a year of working from anywhere! Maybe not from the moonwell why not! just make sure you have internet connection!
  • A 24 / 7 Employee Assistance Program for you and your family, because we care ️
  • Win together, lose together is one of our key behaviours. At Adevinta you will find a collaborative environment with an opportunity to explore your potential and grow
  • On top of these, we also provide a range of locally relevant benefits . Wanna know more? Apply and ask our recruiters!

Adevinta is an equal opportunity employer and we value diversity. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status or disability status.

If you feel like you don’t meet all of the requirements for this role but are interested, please consider applying anyway. Research suggests that women and individuals from underrepresented groups may self-select out of opportunities if they don’t meet 100% of the job requirements. We strongly encourage people from historically excluded groups to apply and look forward to speaking with you.

Be part of an organisation that is making a positive difference in the world. Together, we’re supporting the circular economy and creating a more sustainable future by helping millions of people find perfect matches on our trusted marketplaces.

Why Join Adevinta?

Our marketplaces support the circular economy, helping to reduce plastic waste, items sent to landfill and carbon footprints all around the world. By joining Adevinta, you’ll be helping to build a more sustainable future.

There are lots to find out about working at Adevinta, so here are our answers to the most popular questions.

J-18808-Ljbffr

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra un archivo en formato PDF, DOC, DOCX, ODT o PAGES de hasta 5 MB.