layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Wrike
Prague
Source: Wrike careers · View original posting
From Wrike's posting. “We” and “our” refer to the employer.
Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.
Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You'll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we'd love to hear from you.
A world where everyone is free to focus on their most purposeful work, together.
You'll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Wrike is looking for a Sr. Security Infrastructure Engineer to own and evolve security for our production and cloud environments, with a strong focus on network and infrastructure security. You'll design and harden the controls that keep our world secure — and you'll be the person who spots the gap before it becomes an incident.
Own and evolve security for Wrike's production and cloud environments, with a strong focus on network and infrastructure security.
Design, implement, and improve network security controls, including:
Experience running structured, read-only-first reviews of cloud environments you've never seen before, working through identity and permissions (Azure RBAC/Entra or GCP IAM — over-privileged principals, standing admin, long-lived credentials), public exposure (open management ports, public storage/blob, public IPs), logging and visibility (activity/audit and flow logs), network rules (NSGs/firewall), and secrets handling — in that order of priority, before proposing changes.
Primary focus on Azure permissions and configuration, with working knowledge of GCP and on-prem components.
Experience maintaining attack surface visibility on the assumption that the known asset inventory is incomplete
— discovering unregistered/shadow assets via DNS enumeration, certificate transparency logs, IP-range/cloud enumeration, external scanning, and ASM tooling (e.g., Rapid7 Surface Command) — run as a continuous, monitored process with drift detection and alerting, not a one-time scan, with ownership assigned to whatever turns up.
Skilled at identifying gaps in existing network and cloud security architecture/configuration and recommending changes (authentication, authorization, network segmentation, bastion host setup, etc.).
Able to lead the technical direction and architecture of our cyber security defense capabilities, including enterprise security posture management.
Strong communicator, able to explain complex security concepts and risks to both technical and non-technical audiences.
Ability to balance security principles with business needs.
Security certifications (e.g., CISSP, GIAC, a network security certification such as CCNP Security, etc.).
Strong understanding of Microsoft Azure; working knowledge of Google Cloud Platform is a plus.
Exposure to data security posture management (DSPM) or cloud-native data security controls — a strong plus.
Experience hardening and tuning WAF rules (Cloudflare WAF experience specifically is a strong plus).
Security isn't just a job for you — it's a hobby, and it shows in how you work.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: