StubHub is looking to enhance its security posture within cloud and infrastructure domains by hiring a senior engineer.
Requirements
- Expert level experience in AWS cloud account architecture.
- Expert level knowledge in Network Security, including experience with AWS networking primitives: Security Groups, Network Access Control Lists (NACLS), Subnetting, Routing, and egress traffic filtering mechanisms.
- Expert level proficiency in Identity & Access Management (IAM) Security, including experience with architecting AWS IAM roles & policy architectures for both human and machine access.
- Expert level experience deploying and maintaining configurations and infrastructure using Terraform.
- Expert level experience with modern CSPM and CWPP tools (e.g., Wiz, Orca, Prisma, or Rapid7).
- Intermediate level experience with Secrets / key Management Platforms (e.g., AWS KMS, AWS Secrets Manager, Hashicorp Vault).
- Intermediate level proficiency in Python or Go, and Bash scripting.
Responsibilities
- Develop secure Cloud Account Architectures, focusing primarily on AWS, while understanding and navigating the trade-offs of various cloud architectures.
- Design and implement network security strategies that leverage security groups, NACLS, routing domains, and multi-tiered subnet architectures to ensure a defense-in-depth approach.
- Manage critical security logging and monitoring infrastructure for cloud-native and third-party data sources, ensuring their efficient shipping to Data Lakes and integration with visualization platforms.
- Operate and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), such as Wiz, Orca, Palo Alto Networks Prisma, and Rapid7 ICS.
- Deploy configurations and infrastructure using Infrastructure as Code (IaC) frameworks, such as Terraform, Cloud Formation, and Pulumi.
- Develop and implement governance strategies for infrastructure deployment that integrate security best practices and enhance developer productivity.
- Architect and implement workload identity services, such as SPIRE (Spiffe), in a heterogeneous multi-cloud environment.
Other
- Hybrid (3 days in office/2 days remote) – New York, NY or Santa Monica, CA or Aliso Viejo, CA
- Expert level communication skills and the ability to work effectively across teams.
- An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale.
- Competitive base, equity, and upside that tracks with your impact.
- Unlimited Flex Time Off, providing you the flexibility to manage your schedule and recharge as needed.