This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
About Airalo: Alo! Airalo is the world’s first eSIM store that helps people connect in over 200+ countries and regions across the globe. We are building the next digital service that revolutionizes the telecom industry. We are a travel-tech company and an equal-opportunity environment that values and executes diversity, inclusion, and equity. Our team is spread across 50+ countries and six continents. What glues us together is our commitment to changing the way you connect.
Job Responsibility:
Design, implement, and manage security solutions across the entire software development lifecycle (SDLC), with a focus on automation and continuous integration/continuous delivery (CI/CD) pipelines, including robust API security measures and authentication protocols
Champion security best practices within engineering, DevOps, SRE, and IT teams, fostering a culture of shared responsibility for security
Proactively identify and remediate security vulnerabilities in applications, mitigating OWASP Top 10 vulnerabilities, infrastructure, and cloud services through threat modeling, vulnerability assessments, and penetration testing
Develop and maintain security monitoring and alerting solutions to detect and respond to potential security incidents in real-time and prevent common cyber attacks such as DDoS, injection attacks, and credential stuffing
Define and enforce secure coding standards and provide training and mentorship to development teams on DevSecOps principles
Lead compliance initiatives by contributing to security policies, controls, and audit readiness for SOC 2, ISO 27001, GDPR, and other relevant regulations
Participating in our on-call rotation
Requirements:
Bachelor's degree in Computer Science, Cybersecurity, or a related field
5+ years of experience in DevSecOps, Security Engineering, or a similar role with a strong focus on cloud security
3+ years of hands-on experience with AWS services, including expertise in container orchestration, IAM, and security best practices
2+ years of experience with Kubernetes, including securing Kubernetes clusters and deployments
Deep understanding of SAST, DAST, and container security solutions, API security testing tools, with experience implementing and managing these tools
Proven experience in vulnerability assessment, threat modeling, and remediation techniques
Experience with security incident response, including developing incident response plans and conducting post-mortems
Proficiency in at least one programming language (Python, Go, Java, etc.) for automation and tooling
Proficiency in infrastructure-as-code tools (e.g., Terraform) and CI/CD platforms (e.g., GitHub Actions, Jenkins)
Excellent communication and collaboration skills with the ability to work effectively in a fast-paced environment
Candidates will need to reside in countries with the same time zone or similar to CET
Candidates will need to already have permit to work in the country where they are based