Описание
Solvd Inc. is an AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. Following the acquisition of Tooploox, it provides end-to-end delivery from strategic advisory and solution design to custom AI development and enterprise-scale implementation.
Задачи
- Define and validate application and platform security controls across all delivery phases;
- Perform architecture and threat-model reviews at the design stage and as the platform evolves;
- Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services;
- Validate API and integration security across a composable, multi-vendor platform architecture;
- Review secrets, credentials, and token-management practices across the full stack;
- Support vulnerability scanning and penetration-testing activities by coordinating findings and remediation;
- Validate encryption and secure data handling across storage, transit, and third-party integrations;
- Review security logging, monitoring, and incident-response requirements;
- Support GDPR and privacy engineering requirements throughout delivery;
- Conduct third-party security assessments for integrated services and vendors;
- Provide remediation guidance and produce security acceptance evidence ahead of launch.
Требования
- 5+ Years of experience in application security, security engineering, or a closely related role;
- Experience performing threat modelling and architecture security reviews on complex, multi-component platforms;
- Strong knowledge of authentication and authorization patterns, including OAuth, OIDC, RBAC, and privileged access management;
- Hands-on experience validating API security and reviewing integration patterns across third-party services;
- Solid understanding of secrets management, credential handling, and token lifecycle best practices;
- Experience supporting or coordinating vulnerability scanning and penetration testing programmes;
- Knowledge of encryption standards and secure data handling practices across storage and transit;
- Familiarity with GDPR and privacy-by-design engineering requirements;
- Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams;
- Nice to have: experience securing composable CMS or media platform architectures such as AEM or Amplience, experience with high-traffic public-facing platforms, security logging and monitoring tooling including SIEM and incident response playbooks, third-party vendor security assessment processes, CISSP/OSCP/CEH or equivalent certification, experience working within a phased full-lifecycle delivery programme alongside engineering and architecture teams.
Условия
No conditions specified.