Главная›Вакансии›IT и разработка›DevOps-инженер›Information Security Engineer (Websites, Email & Google Workspace)

VillaCarte Group · Владивосток

Information Security Engineer (Websites, Email & Google Workspace) — VillaCarte Group

This is a hands-on engineering role, not SOC monitoring and not GRC/compliance. You'll personally configure email authentication...

Опубликована сегодня

Коротко о вакансии

Зарплату работодатель не назвал — вилку обсуждают на собеседовании. В требованиях: английский язык. Компания нанимает активно — открытых позиций сейчас 13.

Описание вакансии

About the Role

This is a hands-on engineering role, not SOC monitoring and not GRC/compliance. You'll personally configure email authentication, Google Workspace security and website protections, and drive fixes through to production.

Priority #1 for this role: close the gaps our recent external audit found, then keep pushing our attack surface tighter from there, so our websites and client portals stay up and untampered, our email domains can't be used to scam people, and our data doesn't walk out the door. No security posture is ever fully "done", what we want is someone who keeps this at the top of their list, not squeezed in between other things.

We're hiring an Information Security Engineer to own the external security of our company websites and client-facing portals, our email domains, and our data. You'll work closely with our DevOps team (who own infrastructure execution) and our in-house developers (who own application code) to get fixes shipped, and you'll run our external pentest/audit program as the outside check that it's actually working.

There's a secondary layer of work too (access governance across our ~40-service SaaS portfolio, evaluating security tooling). You own that as far as your bandwidth allows. If it starts eating into the primary mission, that's your signal to make the case for hiring someone under you, not to let either side slip.

Reports to: CIO

Key Responsibilities

Priority #1: close and keep closing the external attack surface

  • Own the security and integrity of our public websites and client-facing portals: hardened access to DNS/CDN/hosting panels so changes can't happen outside a controlled process, removal of wildcard DNS records, closing of exposed admin/API endpoints
  • Stop email spoofing and account takeover: SPF and DMARC on every company domain, moved all the way from p=none to p=reject, with DKIM verified for every sending system (Google Workspace, Zoho, SendPulse, and others), plus enforced 2FA/phishing-resistant login and anomalous-login monitoring on Google Workspace, especially for sales staff. This is what actually stops the costliest scenario for a real estate business: someone hijacking a live deal thread to redirect a client's wire transfer
  • Prevent data theft: get secrets out of client-side code, add CAPTCHA and rate limiting on public forms, enforce HTTPS/HSTS and secure cookie flags, and lock down access to the systems that actually hold sensitive data (our CRM's client and deal records, HR data, financial systems, and our password vault): admin account audits and 2FA there are core to this mission, not an afterthought
  • Keep an eye out for signs that client or business data is being accessed or exfiltrated anywhere in the above
  • Partner with DevOps on CDN/WAF-level controls, and with developers on application-level fixes. You set the requirement and drive it to closure; they usually hold the keys to the actual change
  • Scope, select, and manage external pentest and security audit vendors: this is your outside check that the attack surface is actually closed, not just believed to be closed

Secondary scope (own it if you have the bandwidth; justify a hire if you don't)

  • Security governance of the rest of our third-party SaaS portfolio (~35 lower-sensitivity tools: Zoom, Miro, Figma, Adobe, Dropbox, and similar): who holds admin accounts, 2FA adoption, risky configurations
  • Assess whether we need additional security tooling, and build the business case if you think we should. We're not pre-committed to any tool; this is your call to make and defend when you have time for it

Requirements

  • 5+ years in information security or security engineering, with a track record of actually closing attack-surface issues (DNS/email spoofing, exposed secrets, unpatched perimeter gaps), not just reporting on them
  • Practical, hands-on experience with email/domain authentication (SPF/DMARC/DKIM), TLS/HSTS, and web security headers
  • Experience hardening Google Workspace (or similar) against account takeover: 2FA/phishing-resistant auth, anomalous-login monitoring, and locking down admin access to high-value systems (CRM, HR, finance)
  • Experience finding or driving remediation of real-world web application weaknesses: exposed secrets, missing CAPTCHA/rate limiting, CORS and header misconfigurations
  • Comfortable working cross-functionally with DevOps and developers to get fixes shipped, rather than operating in isolation
  • Experience scoping and managing external security audit or pentest vendors
  • Working knowledge of Linux and Windows, and core networking concepts

Nice to Have

  • Experience governing identity/access across a large portfolio of SaaS tools (2FA rollout, admin account audits)
  • Solid understanding of which security tooling actually solves which problems, and experience building a business case for (or against) adopting it
  • Experience with CDN/WAF platforms (Gcore, Cloudflare)
  • Awareness of data protection/privacy considerations relevant to handling client leads and personal data

What We Offer

  • Fully remote work, or based in Phuket
  • Flexible working hours (start between 8:00 and 11:00, Phuket time)
  • A tightly scoped mandate: reduce and keep closing our external attack surface, with real authority to drive that work through DevOps and development
  • Room to grow a team: if the secondary scope justifies it, make the case and we'll hire under you
  • International team and dynamic environment

How to Apply

To help us understand your experience quickly, please answer the two questions below when you apply. Specific details about what you configured, checked or decided yourself matter much more to us than general descriptions. Applications without answers will not be considered.

  1. Phishing emails are being sent to our clients from our domain, and one employee's Google Workspace account has been compromised. Describe step by step what you do in the first 24 hours and what you configure so it doesn't happen again. Which of these steps have you done personally, and what went wrong the last time you dealt with something similar? Please answer in English, 4–5 sentences.
  2. Overnight, our client portal received 50,000 login attempts from different IP addresses, and some client accounts have already been compromised through password guessing. At the same time, a developer has found an API key in the client-side JS code. Describe what you do immediately, what you change on the website side, and how you assign tasks to DevOps and developers. Which of these steps have you done personally, and what went wrong the last time you dealt with something similar? Please answer in English, 4–5 sentences.

Вакансия опубликована 5 октября, проверена 06.10.2026. Открыть оригинал.

Ключевые навыки

Английский язык

Как откликнуться

Отклик оформляется на странице работодателя — кнопка выше ведёт туда напрямую. Перед отправкой стоит подогнать резюме под текст вакансии: работодатели читают первые строки и ищут в них свои слова. Если рассылаете отклики десятками, посмотрите сервис автооткликов — он отправляет их за вас по заданным настройкам, до 50 в сутки. Про сам поиск работы есть разбор в статье как быстро найти работу.

Спросите нейросети о вакансии

Отвечает DeepSeek по данным этой страницы: зарплата против рынка, условия, работодатель

Вопросы по этой вакансии

Сколько платят на позиции «Information Security Engineer (Websites, Email & Google Workspace)»?

Вилку работодатель не назвал — обсуждать деньги придётся на собеседовании. Для ориентира: в среднем по направлению «DevOps-инженер» платят 174 000 ₽.

Какой опыт нужен?

В требованиях указано: от 3 до 6 лет. Формат работы удалённый, переезд не потребуется.

Вакансия ещё открыта?

Да, на 06.10.2026 она активна: каждую ночь каталог сверяется с источником, закрытые предложения помечаются и уходят из списков.

О компании

VillaCarte Group

VillaCarte Group was founded in 2012 and is a leading real estate developer on the picturesque island of Phuket. The company’s turnover in 2022 exceeded $100 million , and the total area of projects under development in Phuket is more than 300,000 sq. m . Our goal is to bring Phuket’s real estate market to a new global level. We are also proud to have set the trend for high-quality eco-friendly r…

Открытых вакансий: 13

Похожие вакансии

Соседи по направлению с близкими требованиями.

DevSecOps инженер

Зарплата не указана

Уральский центр систем безопасности · Екатеринбург

Участие в проектах хардеринга инфраструктуры внешних и внутренних заказчиков. Управление, поддержание развитие инфраструктуры продукта\сервиса Apsafe. Участие в проектах контейнерной...

От 3 до 6 летDevOps-инженерОпубликована 5 октября

Архитектор решений / Solution Architect

Зарплата не указана

SDI Research · Москва

Проектировать и управлять архитектурой платформы, улучшая её с учётом требований к надёжности, производительности и масштабируемости. Проводить анализ и подбор новых...

Можно удалённоОт 3 до 6 летDevOps-инженерОпубликована 3 октября

Руководитель группы по организации физической защиты

63 276 — 82 258 ₽-64% к среднему

«НК «Роснефть» - Ставрополье» · Ставрополь

1. Организация и координация деятельности группы по организации физической защиты. 2. Организация физической охраны объектов, имущества и персонала Общества. 3.

От 3 до 6 летDevOps-инженерОпубликована 10 сентября

Инженер виртуализации DevOps

Зарплата не указана

Платформа ОФД · Москва

Администрирование и поддержка распределенной среды виртуализации. Мониторинг производительности, поиск и устранение неисправностей (troubleshooting). Администрирование гостевых ОС Linux внутри виртуальных машин.

Более 6 летDevOps-инженерОпубликована 4 октября

DevOps-инженер

Зарплата не указана

ДЕКА · Казань

Готовые артефакты: ВМ или кластер «из коробки» с собственной оркестрацией - мы упаковали при помощи Packer в единую систему всё необходимое.

От 3 до 6 летDevOps-инженерОпубликована 5 октября

Devops-инженер (г.Иркутск)

Зарплата не указана

СберЛизинг · Иркутск

Осуществлять деплой, обновление и настройку кластеров k8s. Администрировать базовые инфраструктурные сервисы: Gitlab, Harbor, Nexus, Trivy, Ansible, Keycloak, s...

От 3 до 6 летDevOps-инженерОпубликована 5 октября

Другие вакансии компании

Расчёты по этой вакансии

Пригодится до собеседования: сколько останется на руки от названной суммы, как считаются отпускные и переработки.

Ещё по направлению

CI/CD, контейнеры, облака и мониторинг: доставка кода и стабильность сервисов.