Freelance Senior DevSecOps Engineer

Toloka

United States

Remote

USD 140,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Toloka AI is hiring a senior hands-on security engineer to own infrastructure security and vulnerability management across cloud environments and Kubernetes/service-mesh security. You will drive remediation, tooling, and policy enforcement from day one.

The role focuses on owning vulnerability-management, cloud hardening, and secure production deployments while coordinating with AI teams on security risk and architecture reviews.

Qualifications

  • Experience hardening cloud infrastructure (IAM, logging, service accounts, network security).
  • Kubernetes security, service mesh, and policy-as-code experience.
  • Vulnerability-management and SLA-driven remediation.
  • Fluency with coding agents or agentic tools for IaC review.

Responsibilities

  • Own vulnerability-management platform; ensure container images are scanned and patched regularly.
  • Own cloud security across AWS, GCP, and Azure hardening, logging, and governance.
  • Own Kubernetes security; manage service-mesh security and policy-as-code rollout.
  • Review security for new environments and AI production integrations; remediate findings.

Skills

Kubernetes security
Cloud security
Vulnerability management
Policy-as-code
Multi-cloud (AWS/GCP/Azure)
CI/CD security

Tools

Kyverno
OPA (Open Policy Agent)
Terraform
Cilium/Istio

Job description

Company Intro

At Toloka AI we create data that powers leading GenAI models and innovations. We work with frontier labs, big tech, renowned AI startups, enterprises and non-profit research organizations worldwide. We use a combination of Experts + Crowd + Tech Platform to teach AI models to reason and evaluate their efficacy and safety. We have experts in more than 50 different domains—from doctors and lawyers to physicists and engineers—and boast one of the most diverse global crowds, representing over 100 countries and speaking 40+ languages . We are a well-funded startup with an enviable portfolio of clients including Anthropic , Amazon , Microsoft , poolside , Recraft , and Shopify .

Recently, we secured strategic investment led by Bezos Expeditions with participation from Mikhail Parakhin , CTO of Shopify and board advisor to leading GenAI companies, who now serves as our Chairman of the Board. Our remote-first team is globally distributed around the world: USA , UK , the Netherlands , Serbia , and more. We are headquartered in Amsterdam.

About the Position

Toloka is growing rapidly, adding new platforms and infrastructure across multiple cloud environments. We are hiring a senior, hands-on security engineer to own infrastructure security and vulnerability management: Kubernetes and service-mesh security, cloud hardening, and vulnerability remediation.

This is a senior, self-directed role. It requires the ability to define scope and drive execution independently, with ownership of core security tooling and processes from day one.

What you'll actually do
  • Own vulnerability management. Operate and maintain the vulnerability-management platform. Ensure container images are scanned and patched on a defined cadence. Maintain supply-chain scanning tooling and its severity-classification configuration. Define and enforce remediation SLAs.
  • Own cloud security across multiple providers. AWS, GCP, and Azure hardening, logging, and service-account governance.
  • Own Kubernetes and service-mesh security. Operate the service mesh and maintain the policy-as-code rollout so that policy is enforced automatically.
  • Audit and secure infrastructure in newly added environments. Review build pipelines and infrastructure in newer parts of the business as they come online, and remediate findings.
  • Contribute to security architecture and design review. Review new integrations and internal systems, including AI agents running in production, for security risk.
  • Support workforce and endpoint security. Contribute to VDI and browser-isolation initiatives as the program matures.
  • Use agentic tooling in your workflow. Use coding agents for first-pass review of infrastructure-as-code, container configuration, and cloud policy, verifying findings against source configuration before acting on them.
Key Priorities for the First 6 Months

The first six months focus on establishing full ownership of infrastructure and vulnerability management.

  • Weeks 1–2 - Onboard to the cloud environment, Kubernetes architecture, and existing security tooling.
  • Month 1 - Establish ownership of the vulnerability-management process; findings triaged and remediated on a defined cadence.
  • Month 2 - Complete configuration of supply-chain scanning tooling; implement automated image scanning and patching; deploy initial policy-as-code rules.
  • Month 3 - Complete policy-as-code rollout in at least one environment; begin infrastructure audits in newly added environments.
  • Month 4 - Close outstanding cloud logging and service-account gaps; establish and enforce a documented multi-cloud hardening baseline.
  • Months 5–6 - Full ownership of infrastructure and cloud security as a domain; independently deliver security-architecture design reviews.
Core Tech Stack

Kubernetes and service mesh, policy-as-code tooling (Kyverno/OPA), Terraform, AWS/GCP/Azure, vulnerability-management and supply-chain scanning platforms, container tooling, CI/CD, and Git. Detections and access rules are managed as code through pull requests. Familiarity with coding/agentic tools for infrastructure review is expected.

What We Evaluate
  • Production experience hardening cloud infrastructure - IAM, logging, service accounts, network security, on at least one major cloud provider (multi-cloud experience is a plus).
  • Kubernetes and container security - service mesh (Cilium, Istio, or similar) and policy-as-code (Kyverno, OPA, or similar).
  • Vulnerability-management experience - SCA/SAST tooling and SLA-driven remediation practice.
  • Fluency with coding agents - experience using agentic tools for infrastructure-as-code review or investigation work, and verifying their output.
  • Ability to work independently at a senior level - defining scope and priorities without detailed direction.
  • Clear written and verbal communication - able to run design reviews and communicate risk to engineers and leadership.
Nice to Have, None Required

Experience securing …

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

kestra • United States

Remote
USD 140,000 - 190,000
Health coverage
Home office equipment
Fully remote
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Senior Infrastructure Engineer
Senior Infrastructure Engineer

CyberCoders • United States

On-site
USD 120,000 - 150,000
Senior Cloud & Security Infrastructure Engineer
Senior Cloud & Security Infrastructure Engineer

CyberCoders • United States

On-site
USD 120,000 - 150,000
Remote Senior DevSecOps Engineer: Cloud & Kubernetes
Remote Senior DevSecOps Engineer: Cloud & Kubernetes

Toloka • United States

Remote
USD 140,000 - 210,000
Senior Security Engineer — Remote Health-Tech Security
Senior Security Engineer — Remote Health-Tech Security

Sequencing • Davenport (IA)

On-site
USD 150,000 - 230,000
Staff Platform Engineer, Security
Staff Platform Engineer, Security

Engg • Denver (CO), Long Beach (CA), San Francisco (CA)

On-site
USD 160,000 - 250,000
Senior Full Stack Developer
Senior Full Stack Developer

SherlockTalent • Dallas (TX), Town of Florida (NY)

Hybrid
USD 124,000 - 193,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Triwill Group • United States

On-site
USD 120,000 - 190,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare