Posted 7 months ago
To reinforce our commitment to customers’ privacy and security, for its PaaS solution, Platform.sh is looking for a Security Operations Manager with a taste for Python and Go, excellent Linux system understanding, outstanding written English skills, experience working on PCI and/or SOC compliance, line management experience, and a real hunger for the challenges of building compliant distributed systems. If you’re looking for an exciting, high-growth opportunity with an award-winning, cutting-edge company, this could be the job for you.
We are targeting managers that can function in a high performing, multithreaded environment. Management duties are expected to be about 25% of your time with the remaining 75% being hands on technical work.
Security, privacy, and compliance controls are at the heart of what we do as our mission is to simplify the cloud. The job is to transform what is often regarded as red-tape and constraints to a well-oiled machine where everything is automated and where every constraint becomes a feature making the product better.
This position reports directly to our Data Protection Officer, and in close interaction with our Chief Product Officer, CTO, VP of Infrastructure, and our Engineering and Customer Support teams.
In a given day you might be:
- Acting as a technical liaison between the Security & Compliance department and our product, engineering, and operations staff.
- Creating documentation and processes in English to help satisfy compliance requirements.
- Evaluating, deploying, and creating, systems and tools that will enhance our support and operations efficiency.
- Supporting our data protection officer and compliance team with information requests, pen testing, disaster recovery, and related activities.
- Executing our security incident management process.
- Working with appropriate teams to deploy and operate security tools and solutions.
- Ensuring all systems, security applications, and services in environment are securely configured and managed through operating system appropriate security platforms and tools.
- Ensuring optimal operation of all security solutions and tools.
- Management of the Security Team
- plan and report activity of the team
- define roles in the teams and communicate to other teams
- create and maintain processes on the team and communicate to other teams
- hire and on-board new staff
- team training and development
- evaluate team’s performance
- plan skills requirements in the team
- report on team performance, set up action plans when necessary
- Excellent written English skills
- 4+ years of line management experience
- CISSP, CISM, Security+, GCED, GICSP, GCIH, SSCP, or CASP Certification or similar
- Experience with Linux (preferably Debian-based)
- Familiar with markdown
- Experience implementing PCI, SOC, or related
- Operate largely independently (go take that hill) with management support
- Juggle several requests at the same time
- Proven successful experience in an operations role
- Exposure to cloud services (AWS in particular)
- Understands how an OS works, knows networking, how git works, and the constraints of a distributed system
- Proficient in Python or Golang
- Experience with containerization technologies (LXC/LXD, Docker)
- Has an understanding of
- Patch and Vulnerability Management process
- Principle of Least Privilege
- Incident response
- Identity and Access Management
- Experience with vendor management
- Experience with Puppet
- Demonstrated the ability to successfully manage cloud-based infrastructure for a fast growing organization
- Knowledge of Magento Ecommerce, Symfony, Drupal, eZ Platform, or Typo3
- Relational database skills
- Public speaking experience
- Ability to speak French or German a plus
- Ability to kick ass in Chess or beat Zork without using a map
- Can bravely take on new challenges like a Gryffindor, analyzes problems like Ravenclaw, protects our infrastructure and client data like a Slytherin, and talks with clients like a Hufflepuff.
Sound Like a Good Fit? We’d love to talk to you!
* This is a remote job.