Infrastructure Security Engineer ensuring security for Yelp’s AWS and Google Cloud environments. Collaborating with security engineers to enhance cloud and corporate security posture.
Responsibilities
Design, implement, operationalize and maintain systems that ensure the security of Yelp’s AWS and Google Cloud Platform (GCP) environments, focusing on least privilege, containerization, and developer efficiency
Develop and enforce data security controls to support privacy initiatives, including data mapping and data retention
Manage system-level access controls (such as Linux, Docker, Kubernetes), and tiered access for internal digital assets, balancing strict authentication/authorization with usability
Create, extend, and monitor company-wide security standards, proactively identifying and correcting insecure usage across Yelp
Develop and operationalize telemetry, reporting, and alerting systems to collect and analyze security-related data
Conduct timely vulnerability identification, assessment, and remediation across Yelp’s infrastructure, applications, and services
Participate in a robust on-call rotation, respond to security incidents, and contribute to proactive threat modeling and system reviews
Mentor other engineers passing on your skills, and serve as a resource in our #security Slack channel by promoting best practices and offering your expertise across the organization.
Requirements
Experience building secure, scalable, and distributed cloud environments (preferably on AWS and GCP)
Familiarity with modern access controls and authentication mechanisms (Linux, Docker, Kubernetes, IAM, etc.)
Proficient in at least one programming language (e.g., Python, Java, JavaScript, C) and in designing well-structured APIs
Passion for automation to streamline security policy enforcement, detection, and response
Strong analytical skills and a proactive approach to vulnerability assessment and threat modeling
Effective communicator, able to collaborate across diverse teams and provide security guidance in a constructive, approachable manner
Committed to continuous learning, knowledge sharing, and staying current with evolving security trends.
IT Security Specialist responsible for day - to - day support of Hudbay’s IT security program and monitoring security risks. Collaborating on various projects to ensure security best practices are followed across the organization.
Linux Engineer enhancing security technology for Canonical’s Ubuntu. Collaborating on FIPS and CC certification while implementing security frameworks and benchmarks.
Senior Security Officer managing security operations at Umicore to ensure safe and smooth business operations while leading the security staff and compliance.
Security GRC Specialist managing risk lifecycle and compliance at Aviso, a leading wealth management organization. Conducting assessments and supporting governance in a dynamic work environment.
ICRC Police and Gendarmerie Delegate focusing on dialogue with armed forces to enhance humanitarian efforts in various conflict situations. Coordination of strategies to prevent and respond to humanitarian consequences of armed conflict.
Senior Cybersecurity Advisor at Optiv designing advanced security solutions for clients. Collaborating with specialists to drive cybersecurity initiatives and meet strategic goals of client organizations.
Software Engineer II building scalable infrastructure for email security product at Abnormal AI. Collaborating with engineers and data scientists to ensure high - performance solutions.
Cybersecurity Officer ensuring end - to - end cybersecurity for Growe Talents in a leadership role. Overseeing security operations, defining strategies, and managing security teams in a dynamic environment.
Cybersecurity Officer managing end - to - end security across the company with a focus on compliance and risk management. Leading a large team in executing security strategies across the organization.
Global Security Architect at Colliers responsible for defining security solutions across global processes and technology. Leading cloud migrations and security strategies for GCP and Azure environments.