Senior Security Infrastructure Engineer

Prague·Posted 5mo ago
cybersecuritygcp
<div class="content-intro"><div>Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.</div> <div>&nbsp;</div> <div>Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You'll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we'd love to hear from you.</div> <div>&nbsp;</div> <div><strong>Our vision:&nbsp; </strong>A world where everyone is free to focus on their most purposeful work, together.&nbsp;</div> <div>&nbsp;</div></div><h3>About the Role:</h3> <p>You'll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Wrike is looking for a Sr. Security Infrastructure Engineer to own and evolve security for our production and cloud environments, with a strong focus on network and infrastructure security. You'll design and harden the controls that keep our world secure — and you'll be the person who spots the gap before it becomes an incident.</p> <h3>Your Impact:</h3> <ul> <li>Own and evolve security for Wrike's production and cloud environments, with a strong focus on network and infrastructure security.</li> <li>Design, implement, and improve network security controls, including:</li> <li>Internal network segmentation and lateral-movement (east-west) restrictions</li> <li>WAF operations and tuning</li> <li>Egress filtering</li> <li>Risk- and exposure-based sequencing of remediation work</li> <li>Run structured first-pass security reviews of cloud environments, checking for:</li> <li>Publicly exposed storage</li> <li>Open management ports</li> <li>Gaps in logging/audit trail coverage</li> <li>Long-lived or stale credentials</li> <li>Over-privileged principals and accounts</li> <li>Maintain visibility into our external attack surface, including:</li> <li>DNS enumeration and certificate transparency log monitoring</li> <li>External scanning of IP ranges</li> <li>Dedicated ASM tooling (e.g., Rapid7 Surface Command)</li> <li>Continuous configuration drift detection tied to an asset inventory with clear ownership assignment</li> <li>Partner with System &amp; Data Engineering and other ops teams to embed security into architecture and change management (design reviews, sign-offs, "secure by default" patterns).</li> <li>Educate and coach engineers and operations teams on security practices through reviews, consultations, and targeted training.</li> <li>Identify, track, and determine mitigation strategies for security risks.</li> </ul> <h3>Your Qualifications:</h3> <ul> <li>Proven track record as a security subject-matter expert, guiding engineering teams in end-to-end secure system design, with a focus on network architecture and cloud services.</li> <li>Hands-on experience designing network segmentation/architecture and operating firewall / IDS-IPS platforms in production — you think in <strong>layers</strong>, not a checklist: internal zoning/segmentation to cut east-west movement <em>and</em> edge protection in front of public-facing apps (Cloudflare-style WAF managed + custom rules, rate limiting, bot/DDoS protection, TLS), sequenced by which assets are most exposed or highest-risk first.</li> <li>Experience running structured, <strong>read-only-first</strong> reviews of cloud environments you've never seen before, working through identity and permissions (Azure RBAC/Entra or GCP IAM — over-privileged principals, standing admin, long-lived credentials), public exposure (open management ports, public storage/blob, public IPs), logging and visibility (activity/audit and flow logs), network rules (NSGs/firewall), and secrets handling — in that order of priority, before proposing changes. Primary focus on Azure permissions and configuration, with working knowledge of GCP and on-prem components.</li> <li>Experience maintaining attack surface visibility on the assumption that the known asset inventory is <strong>incomplete</strong> — discovering unregistered/shadow assets via DNS enumeration, certificate transparency logs, IP-range/cloud enumeration, external scanning, and ASM tooling (e.g., Rapid7 Surface Command) — run as a continuous, monitored process with drift detection and alerting, not a one-time scan, with ownership assigned to whatever turns up.</li> <li>Skilled at identifying gaps in existing network and cloud security architecture/configuration and recommending changes (authentication, authorization, network segmentation, bastion host setup, etc.).</li> <li>Able to lead the technical direction and architecture of our cyber security defense capabilities, including enterprise security posture management.</li> <li>Strong communicator, able to explain complex security concepts and risks to both technical and non-technical audiences.</li> </ul> <h3>Standout Qualities:</h3> <ul> <li>Ability to balance security principles with business needs.</li> <li>Security certifications (e.g., CISSP, GIAC, a network security certification such as CCNP Security, etc.).</li> <li>Strong understanding of Microsoft Azure; working knowledge of Google Cloud Platform is a plus.</li> <li>Exposure to data security posture management (DSPM) or cloud-native data security controls — a strong plus.</li> <li>Experience hardening and tuning WAF rules (Cloudflare WAF experience specifically is a strong plus).</li> <li>Security isn't just a job for you — it's a hobby, and it shows in how you work.</li> </ul> <h3><strong>Benefits &amp; Perks:</strong></h3> <ul> <li>5 Weeks of paid vacation</li> <li>Sick Leave Compensation&nbsp; <ul> <li>5 Paid Uncertified Sick Days</li> <li>2 weeks fully paid w/ medical certificate, additional&nbsp;</li> <li>4 weeks paid at 80% salary rate</li> </ul> </li> <li>Parental Leave (fully paid): 18 Weeks Maternity / 4 Week Paternity&nbsp;</li> <li>2 Volunteer Days</li> <li>Meal Vouchers (CZK 220 per working day)</li> <li>Annual Prague Travel Card (Lítačka)</li> <li>Hybrid Working Model</li> <li>Benefit budget with flexible options, including a MultiSport card, Canadian Medical membership, contributions to a pension savings plan and additional choices available through Benefit Plus</li> </ul> <div> <h3><strong>What’s Next?&nbsp;</strong></h3> <ul> <li>Intro call with a Recruiter</li> <li>Technical interview</li> <li>Cultural interview</li> </ul> <p class="p1">Your recruitment buddy will be&nbsp;<a href="https://www.linkedin.com/in/aleksandar-chernev-479785214/">Aleksandar Chernev</a>, Senior Technical Recruiter.<br><br></p> <p>#LI-AC1</p> </div><div class="content-conclusion"><h3><strong>Who Is Wrike and Our Culture</strong></h3> <div>We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.</div> <div>&nbsp;</div> <div> <div><strong>Hybrid work mode</strong></div> <div><br> <div> <div>Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.</div> <div>&nbsp;</div> <div>While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.</div> </div> </div> </div> <h4><strong>Our persona&nbsp;</strong></h4> <div><strong>💡&nbsp; Smart:</strong> We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.</div> <div><strong>💚&nbsp; Dedicated: </strong>We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!</div> <div><strong>🤗&nbsp; Approachable:</strong> We're friendly, easy to get along with, considerate, and helpful.&nbsp;</div> <h4><strong>Our culture and Values&nbsp;</strong></h4> <p><strong>🤩 Customer-Focused</strong></p> <p><strong>We care about our customers. </strong>We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.</p> <p><strong>🤝 Collaborative</strong></p> <p><strong>We work as one and win together, </strong>each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.</p> <p><strong>🎨 Creative</strong></p> <p><strong>We strive to succeed through continuous innovation. </strong>It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.&nbsp;</p> <p><strong>💪 Committed</strong></p> <p><strong>We believe in ownership at all levels of the organization, </strong>by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.</p> <div>&nbsp;</div> <div> <div>Check out our&nbsp;<a href="https://www.linkedin.com/company/wrike/life/3fd588bf-73e8-47be-9b0a-1933d404ea88/" target="_blank">LinkedIn Life Page</a>, <a href="https://www.wrike.com/wrike-company-culture/">Company culture page</a>, <a href="https://www.instagram.com/wriketeam" target="_blank">Instagram</a>, <a href="https://www.wrike.com/wrike-engineering/" target="_blank">Wrike Engineering Team</a>,&nbsp;<a href="https://medium.com/wriketechclub" target="_blank">Medium</a>, <a href="https://www.meetup.com/WrikeTechClub/?_cookie-check=wtgfN9ARYGPSGd3e" target="_blank">Meetup.com</a>, <a href="https://www.youtube.com/c/wriketechclub" target="_blank">Youtube</a> for a feel for what life is like at Wrike.&nbsp;</div> </div> <p><a href="https://www.glassdoor.com/Overview/Working-at-Wrike-EI_IE420969.11,16.htm"><img style="max-width: 100%;" src="https://www.glassdoor.com/pc-app/static/img/partnerCenter/badges/eng_CHECK_US_273x90.png" alt="Check us out on Glassdoor."></a></p></div>