Senior Security Infrastructure Engineer
Wrike - Czech Republic - Remote - posted 4d ago
Skills: Azure, GCP, Networking, Coaching, DNS, Rbac, TLS, Authentication, Cloud infrastructure
Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.
Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You'll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we'd love to hear from you.
**Our vision: **A world where everyone is free to focus on their most purposeful work, together.
This remote position is open to residents of Czechia
About the Role:
You'll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Wrike is looking for a Sr. Security Infrastructure Engineer to own and evolve security for our production and cloud environments, with a strong focus on network and infrastructure security. You'll design and harden the controls that keep our world secure — and you'll be the person who spots the gap before it becomes an incident.
Your Impact:
- Own and evolve security for Wrike's production and cloud environments, with a strong focus on network and infrastructure security.
- Design, implement, and improve network security controls, including:
- Internal network segmentation and lateral-movement (east-west) restrictions
- WAF operations and tuning
- Egress filtering
- Risk- and exposure-based sequencing of remediation work
- Run structured first-pass security reviews of cloud environments, checking for:
- Publicly exposed storage
- Open management ports
- Gaps in logging/audit trail coverage
- Long-lived or stale credentials
- Over-privileged principals and accounts
- Maintain visibility into our external attack surface, including:
- DNS enumeration and certificate transparency log monitoring
- External scanning of IP ranges
- Dedicated ASM tooling (e.g., Rapid7 Surface Command)
- Continuous configuration drift detection tied to an asset inventory with clear ownership assignment
- Partner with System & Data Engineering and other ops teams to embed security into architecture and change management (design reviews, sign-offs, "secure by default" patterns).
- Educate and coach engineers and operations teams on security practices through reviews, consultations, and targeted training.
- Identify, track, and determine mitigation strategies for security risks.
Your Qualifications:
- Proven track record as a security subject-matter expert, guiding engineering teams in end-to-end secure system design, with a focus on network architecture and cloud services.
- Hands-on experience designing network segmentation/architecture and operating firewall / IDS-IPS platforms in production — you think in layers, not a checklist: internal zoning/segmentation to cut east-west movement and edge protection in front of public-facing apps (Cloudflare-style WAF managed + custom rules, rate limiting, bot/DDoS protection, TLS), sequenced by which assets are most exposed or highest-risk first.
- Experience running structured, read-only-first reviews of cloud environments you've never seen before, working through identity and permissions (Azure RBAC/Entra or GCP IAM — over-privileged principals, standing admin, long-lived credentials), public exposure (open management ports, public storage/blob, public IPs), logging and visibility (activity/audit and flow logs), network rules (NSGs/firewall), and secrets handling — in that order of priority, before proposing changes. Primary focus on Azure permissions and configuration, with working knowledge of GCP and on-prem components.
- Experience maintaining attack surface visibility on the assumption that the known asset inventory is incomplete — discovering unregistered/shadow assets via DNS enumeration, certificate transparency logs, IP-range/cloud enumeration, external scanning, and ASM tooling (e.g., Rapid7 Surface Command) — run as a continuous, monitored process with drift detection and alerting, not a one-time scan, with ownership assigned to whatever turns up.
- Skilled at identifying gaps in existing network and cloud security architecture/configuration and recommending changes (authentication, authorization, network segmentation, bastion host setup, etc.).
- Able to lead the technical direction and architecture of our cyber security defense capabilities, including enterprise security posture management.
- Strong communicator, able to explain complex security concepts and risks to both technical and non-technical audiences.
Standout Qualities:
- Ability to balance security principles with business needs.
- Security certifications (e.g., CISSP, GIAC, a network security certification such as CCNP Security, etc.).
- Strong understanding of Microsoft Azure; working knowledge of Google Cloud Platform is a plus.
- Exposure to data security posture management (DSPM) or cloud-native data security controls — a strong plus.
- Experience hardening and tuning WAF rules (Cloudflare WAF experience specifically is a strong plus).
- Security isn't just a job for you — it's a hobby, and it shows in how you work.
Benefits & Perks:
- 5 Weeks of paid vacation
- Sick Leave Compensation
- 5 Paid Uncertified Sick Days
- 2 weeks fully paid w/ medical certificate, additional
- 4 weeks paid at 80% salary rate
- Parental Leave (fully paid): 18 Weeks Maternity / 4 Week Paternity
- 2 Volunteer Days
- Meal Vouchers (CZK 220 per working day)
- Annual Prague Travel Card (Lítačka)
- Benefit budget with flexible options, including a MultiSport card, Canadian Medical membership, contributions to a pension savings plan and additional choices available through Benefit Plus
**What’s Next? **
- Intro call with a Recruiter
- Technical interview
- Cultural interview
Your recruitment buddy will be Aleksandar Chernev, Senior Technical Recruiter.
#LI-AC1
Who Is Wrike and Our Culture
We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.
Hybrid work mode
Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.
While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.
Our persona 💡 Smart: We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.
**💚 Dedicated: **We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!
🤗 Approachable: We're friendly, easy to get along with, considerate, and helpful.
**Our culture and Values 🤩 Customer-FocusedWe care about our customers. **We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.
**🤝 CollaborativeWe work as one and win together, **each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.
**🎨 CreativeWe strive to succeed through continuous innovation. **It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.
**💪 CommittedWe believe in ownership at all levels of the organization, **by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.
Check out our LinkedIn Life Page, Company culture page, Instagram, Wrike Engineering Team, Medium, Meetup.com, Youtube for a feel for what life is like at Wrike.