MacPaw logo

MacPaw

Senior Infrastructure Security Engineer

Work from home

Remote role where the employee must remain based in a particular country.

Ukraine only

Employer listed it 5 weeks ago · Found 7h ago

Been open since 5 weeks ago, still being checked, but it has been live a while.

Salary

Not stated

Location

Ukraine only

Timezone

Not stated

Contract

Full-time

Experience

Senior

Category

Software

This employer didn't state pay. Jobs like this usually pay around $165k–$225k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Work from home

This is a remote role, but the employee must be based in Ukraine. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote job, Kyiv, Ukraine, Remote"

What Nomaders makes of it

  • Residency required in Ukraine
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Jira ticket

We’re looking for a Senior Infrastructure Security Engineer to join our Information Security Team, supporting MacPaw’s product ecosystem as we transition to our next-generation setup.

Our Security and Infrastructure teams ensure that all MacPaw products run on a highly resilient, compliant, and rock-solid foundation, protecting user data and business operations at scale.

As a Senior Infrastructure Security Engineer, you will take dedicated ownership of securing our production infrastructure, establishing compliance control baselines, and maintaining a strong security posture. You’ll define, test, and coordinate security frameworks across bare-metal environments and GCP, working hand-in-hand with our SRE team as a technical peer and security partner.

If you’re excited to take ownership of MacPaw’s infrastructure security, reduce automated evidence coverage gaps, and collaborate on advanced CNAPP tools and agentic AI automation, we’d love to hear from you!

In this role, you will:

Participate in Wiz CNAPP service adoption.

Drive Kubernetes and cloud posture hardening across GCP, including RBAC reviews, admission control, network policies, and runtime threat detection.

Take ownership of the infrastructure vulnerability backlog, driving remediation down against severity-based SLAs in close collaboration with SRE.

Build and ship agentic AI security automation into code-reviewed repositories to streamline vulnerability management and operational security workflows.

Collaborate closely with the SRE team to embed security controls into CI/CD pipelines and Infrastructure-as-Code without adding unnecessary friction.

Skills you’ll need to bring:

Strong expertise in Infrastructure-as-Code and automation using Terraform.

Python or Go skills to build security tooling rather than just filing tickets.

Hands-on experience with incident management, threat containment, and root cause analysis (RCA) for infrastructure security incidents.

Demonstrated ability to work with Service Reliability Engineers (SRE) team as a technical peer, driving security engineering through influence and shared goals.

Hands-on production cloud security experience at scale on GCP (IAM least privilege, network segmentation, runtime detection, and posture hardening).

In-depth Kubernetes security experience in production: RBAC, admission control (OPA/Kyverno), network policies, runtime detection, and image provenance.

Proven experience in bare-metal and self-hosted Linux infrastructure security (host-based controls, Linux hardening, and multi-tenancy risk mitigation outside managed cloud).

Experience in infrastructure vulnerability management: triage, SLA management, and driving remediation through engineering teams.

Ability to write and ship agentic AI automation into production repositories to enhance security operations.

At least an Upper-Intermediate level of English and fluent Ukrainian.

As a plus:

Experience securing agentic AI systems in production (prompt injection, tool poisoning across MCP, human-in-the-loop approval flows, and kill switches).

Requirements

  • ·Strong expertise in Infrastructure-as-Code and automation using Terraform.
  • ·Python or Go skills to build security tooling rather than just filing tickets.
  • ·Hands-on experience with incident management, threat containment, and root cause analysis (RCA) for infrastructure security incidents.
  • ·Demonstrated ability to work with Service Reliability Engineers (SRE) team as a technical peer, driving security engineering through influence and shared goals.
  • ·Hands-on production cloud security experience at scale on GCP (IAM least privilege, network segmentation, runtime detection, and posture hardening).

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at MacPaw, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 8h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $165k to $225k per year · You'll be taken to the employer's careers page.