Responsibilities
- Evaluate and categorize findings from automated vulnerability scans, documenting false positives to reduce unnecessary fixes and support risk-based decision-making.
- Take part in reviewing internal network vulnerability reports and work with infrastructure teams to prioritize and resolve security issues, escalating critical findings when necessary.
- Perform independent security evaluations of products using both automated tools and manual techniques, following recognized testing standards to meet audit requirements.
- Assess security reports from internal teams, clients, and external sources to confirm validity and document confirmed vulnerabilities.
- Verify that code changes effectively resolve known security flaws and perform gap analyses when remediation is incomplete.
- Support compliance frameworks such as PCI DSS, ISO 27001, and SOC 2 by preparing documentation on scanning activities, validating controls, and recording exceptions.
- Improve the effectiveness of vulnerability scanning by identifying coverage gaps, ensuring all systems are included, and recommending configuration enhancements.
- Support third-party audits and penetration testing efforts by providing technical input and coordination.
- Help automate processes and reporting related to identity and access management.
- Evaluate the security posture of artificial intelligence components within product offerings.
Benefits
- Eligibility to participate in the company's equity program.
- Flexible work-life balance enabled by a hybrid working model.
- Freedom to select work equipment that best supports individual productivity.
- Access to a professional development budget for training and learning initiatives.
- Comprehensive wellbeing resources through a global Employee Assistance Program.
- Information available on global time-off policies including parental leave, sick leave, and personal days.
- Additional benefits tailored to local regions for international employees.
Work Arrangement
Hybrid
How to Recognize and Avoid Employment Scams
Be cautious of fraudulent job postings aiming to collect personal data. Official recruitment communications from this company only come from domains @aiven.io, @greenhouse.io, or @eu.greenhouse.io. Interviews are conducted via video call or in person, never through text or chat. If uncertain about a job offer's authenticity, contact recruitment@aiven.io for verification.
Equal Opportunities
The company upholds equal employment practices, prohibiting discrimination based on age, gender identity, ethnicity, religion, sexual orientation, disability, marital status, or other personal characteristics. This policy covers all employment stages, including hiring, promotion, compensation, and training. The organization complies with local non-discrimination laws and provides reasonable accommodations for individuals with disabilities during the application process and employment. Candidates may request accommodations during application or contact recruitment@aiven.io with questions.