This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We're looking for a hands-on Senior Security Engineer who will be the driving force behind bsport's security transformation. This is not a purely strategic role - you'll be rolling up your sleeves to implement security controls, respond to incidents, and build our security program from fundamentals. We need someone who can immediately reduce our exposure to data leaks, phishing, and unauthorized access while building sustainable security practices that scale with our growth.
Job Responsibility:
Harden our AWS infrastructure and application security
Audit and improve IAM configurations and policies
Enhance WAF rules to block sophisticated attacks
Implement automated security scanning in CI/CD pipelines (SAST/DAST)
Work with the SRE team to secure our Kubernetes clusters and container images
Drive and maintain state-of-the-art security posture across backend, frontend, and user data management in collaboration with SWE teams, ensuring best-in-class protection for our systems and users
Strengthen authentication infrastructure and identity management
Deploy and configure email security solutions within existing Google Workspace
Deploy and enforce strong authentication methods across the organization's applications and services (SSO, MFA)
Create automated alerting for suspicious behaviors patterns using Grafana/ELK
Establish vulnerability management
Set up automated vulnerability scanning for infrastructure and applications (leveraging open-source tools as much as possible)
Create a prioritised remediation workflow integrated with the engineering team's sprint cycles
Implement dependency scanning for our Python/Django backend and React frontend
Expand secrets detection coverage
Incident response and monitoring
Design and implement security alerting using our existing Grafana/ELK stack
Create runbooks for common security incidents (data leaks, phishing, unauthorized access)
Respond to security incidents and conduct post-incident reviews
Handle customer security inquiries and support sales with security questionnaires
Build security awareness across 200 employees: Design and deliver security training programs
Create engaging, practical security training for all employees
Develop role-specific training (engineering, sales, customer success, operations)
Run simulated phishing campaigns and use results to improve training
Conduct quarterly security awareness sessions
Hardware and endpoint security management
Define and enforce security standards for employee devices (Mac, Linux, Windows)
Work with IT/HRs to ensure secure device provisioning using Primo
Implement endpoint protection and mobile device management policies
Create security baseline configurations for different roles