See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewUpload your resume and we draft a letter for this exact role, tailored to what it asks for.
The engineer will own infrastructure security, vulnerability management, and cloud hardening across multiple providers. They will also maintain service mesh security, implement policy-as-code, and conduct security architecture reviews.
Company Intro
At Toloka AI we create data that powers leading GenAI models and innovations. We work with frontier labs, big tech, renowned AI startups, enterprises and non-profit research organizations worldwide. We use a combination of Experts + Crowd + Tech Platform to teach AI models to reason and evaluate their efficacy and safety. We have experts in more than 50 different domains—from doctors and lawyers to physicists and engineers—and boast one of the most diverse global crowds, representing over 100 countries and speaking 40+ languages. We are a well-funded startup with an enviable portfolio of clients including Anthropic, Amazon, Microsoft, poolside, Recraft, and Shopify.
Recently, we secured strategic investment led by Bezos Expeditions with participation from Mikhail Parakhin, CTO of Shopify and board advisor to leading GenAI companies, who now serves as our Chairman of the Board. Our remote-first team is globally distributed around the world: USA, UK, the Netherlands, Serbia, and more. We are headquartered in Amsterdam.
About the Position
Toloka is growing rapidly, adding new platforms and infrastructure across multiple cloud environments. We are hiring a senior, hands-on security engineer to own infrastructure security and vulnerability management: Kubernetes and service-mesh security, cloud hardening, and vulnerability remediation.
This is a senior, self-directed role. It requires the ability to define scope and drive execution independently, with ownership of core security tooling and processes from day one.
What you'll actually do
Key Priorities for the First 6 Months
The first six months focus on establishing full ownership of infrastructure and vulnerability management.
Core Tech Stack
Kubernetes and service mesh, policy-as-code tooling (Kyverno/OPA), Terraform, AWS/GCP/Azure, vulnerability-management and supply-chain scanning platforms, container tooling, CI/CD, and Git. Detections and access rules are managed as code through pull requests. Familiarity with coding/agentic tools for infrastructure review is expected.
What We Evaluate
Nice to Have, None Required
Experience securing multi-tenant or multi-identity-domain environments; supply-chain security tooling (SBOM, Socket, JFrog, or similar); secure-SDLC or AppSec experience; Terraform/IaC at scale; relevant certifications (e.g. AWS/GCP/Azure security specialties, CKS).
What We Can Offer
[Important Notice] Scam Alert Regarding Fake Job Postings
It has come to our attention that an individual or group is fraudulently impersonating Toloka to post fake jobs and solicit personal information from applicants.Please be aware:
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 219,812+ Jobs in Software Development
Answer easy questions
219,812+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”