Title: Senior Cyber Security Engineer
Company Name: Dakpeon24 IT
Vacancy: 1
Age: 30 to 40 years
Job Location: Anywhere in Bangladesh
Salary: Tk. 80000 - 130000 (Monthly)
Experience:
Experience with supply-chain security / SLSA, artifact signing (cosign), and Infrastructure-as-Code security (Terraform, tfsec).• Exposure to Kubernetes and future GitOps / Policy-as-Code (OPA/Conftest).• Prior experience preparing an organization for a SOC 2 Type II audit.• Contributions to security tooling, CVEs, or the security community.
CISSP (Certified Information Systems Security Professional) certification or equivalent.
Security analysis across all projects & applications
• Perform end-to-end security assessments of every application, service, and repository — reviewing architecture, source code, APIs, authentication/authorization (RBAC, JWT), data handling, and third-party dependencies.
• Conduct and oversee threat modeling (e.g. STRIDE) for each service and rank findings by risk; maintain a prioritized remediation backlog with clear owners.
• Run and interpret SAST, DAST, SCA/dependency, secret, and container scans; triage results, remove false positives, and track High/Critical issues to closure.
• Lead penetration testing / red-team exercises (internal or with vendors) and validate remediations.
DevSecOps & pipeline security
• Embed security gates into CI/CD pipelines (GitHub Actions) so scans run as blocking controls, and help maintain reusable, org-wide secure workflows.
• Harden container images and build/supply chain — non-root images, image scanning, SBOM generation, artifact signing, and dependency pinning.
• Design and enforce secrets management, least-privilege access, and Zero-Trust principles across repositories and infrastructure.
Cloud & infrastructure security
• Review and harden cloud infrastructure (GCP) — IAM/least privilege, network segmentation, workload identity/keyless auth, logging and monitoring.
• Establish and monitor security observability (metrics, logs, alerting) and respond to anomalies.
Compliance, governance & response
• Map controls to SOC 2 Trust Services Criteria (CC6, CC7, CC8, A1), author security policies and procedures, and ensure audit evidence is captured and retained.
• Lead PCI DSS compliance for CashApp and any payment/cardholder-data workloads — scoping the cardholder data environment (CDE), enforcing the applicable PCI DSS requirements, coordinating with the QSA, and maintaining evidence for assessment.
• Own incident response — detection, containment, eradication, recovery, and post-incident review — and run readiness drills.
• Define security standards and guardrails and mentor engineers on secure coding and secure SDLC practices.
• 10+ years of professional experience in cyber security, with strong depth in application security and cloud/infrastructure security.
• Proven track record of securing production systems across multiple applications and technology stacks.
• Strong knowledge of CI/CD security and GitHub Actions, plus containers (Docker / Docker Compose).
• Solid understanding of at least one cloud platform (GCP preferred; AWS/Azure acceptable) and IAM / least-privilege / Zero-Trust design.
• Experience with threat modeling, vulnerability management, and incident response.
• Strong working knowledge of SOC 2 (or ISO 27001 / equivalent) control frameworks and audit evidence practices.
• Demonstrable experience with PCI DSS compliance for payment / cardholder-data systems — CDE scoping, control implementation, and QSA-ready evidence (directly relevant to CashApp).
• Excellent analytical, documentation, and communication skills; able to explain risk clearly to both engineers and leadership.
Candidates must hold one or more of the following (at least one of CISSP or OSCP strongly preferred):
• OSCP — Offensive Security Certified Professional
• CISSP — Certified Information Systems Security Professional
• CISA — Certified Information Systems Auditor
• Equivalent senior-level security certifications (e.g. CISM, CCSP, GIAC GWAPT/GPEN) will also be considered.
A PCI DSS credential — PCIP (PCI Professional), ISA, or QSA — is required or must be obtained within the first 6 months, given CashApp's payment scope.
• Experience with supply-chain security / SLSA, artifact signing (cosign), and Infrastructure-as-Code security (Terraform, tfsec).
• Exposure to Kubernetes and future GitOps / Policy-as-Code (OPA/Conftest).
• Prior experience preparing an organization for a SOC 2 Type II audit.
• Contributions to security tooling, CVEs, or the security community.