UNjobs Все вакансии →

Information Security Engineer II

Candescent · Belgrade Metropolitan Area, Сербия · по договорённости

Компания
Candescent
Город
Belgrade Metropolitan Area, Сербия
Зарплата
по договорённости
Уровень
middle
Формат
full_time
Иностранная компания
нанимает русскоязычных

Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels. Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection. Candescent is seeking a motivated and technically skilled Information Security Engineer II to help strengthen and scale our application and edge security capabilities, with a focus on Cloudflare-based controls. This role is responsible for designing, implementing, and maintaining security solutions that protect customer-facing applications and distributed systems. The ideal candidate will bring hands-on experience in web application security, DNS security, and firewall protection, along with a strong understanding of modern threat vectors including credential stuffing and distributed attacks. You will partner closely with engineering, infrastructure, and incident response teams to proactively identify vulnerabilities, respond to threats, and enhance the organization’s overall security posture in a cloud-first, FinTech environment. Key Responsibilities And Deliverables Design, implement, and manage Cloudflare security controls, including WAF, bot mitigation, rate limiting, and DNS protection
Strengthen web application security by identifying and mitigating common threats (e.g., OWASP Top 10 vulnerabilities)
Configure and maintain firewalls and network protection mechanisms to safeguard external and internal systems
Lead and support vulnerability remediation efforts, working cross-functionally to prioritize and resolve identified risks
Protect distributed, cloud-based platforms through strong distributed systems security practices
Develop detection and mitigation strategies for credential stuffing prevention and bot-based attacks
Support incident response activities, including triage, investigation, containment, and post-incident reviews
Monitor and analyze security events using Cloudflare and other telemetry sources to identify threats and anomalies
Maintain and optimize DNS (Domain Name System) security configurations, including traffic routing and protection against DNS-based attacks
Collaborate with engineering teams to embed secure design principles into application development and deployment lifecycles
Qualifications And Experience Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience)
3–5 years of experience in information security engineering or application security roles
Hands-on experience with Cloudflare (WAF, Bot Management, DNS, CDN security) or similar edge security platforms
Strong knowledge of:
Web application security
Firewalls and network protection
Vulnerability management and remediation
Distributed systems and cloud security architectures
Experience managing or responding to incident response scenarios
Familiarity with credential stuffing detection/prevention techniques and bot management tools
Working knowledge of DNS protocols and security considerations
Experience in cloud environments (AWS, Azure, or GCP preferred)
Strong analytical, problem-solving, and communication skills
Preferred Distinctions Experience in FinTech, SaaS, or regulated financial environments
Relevant certifications (e.g., CISSP, CEH, Security+, GIAC, Cloudflare certifications)
Experience implementing zero trust architectures
Familiarity with DevSecOps practices and CI/CD security integrations
Exposure to fraud prevention or digital banking security

Открыть и откликнуться →

Отклик ведёт на сайт работодателя. Бесплатная регистрация открывает отклик и разбор резюме.