Senior Security Infrastructure Engineer
Remote ✓Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work. Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You'll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we'd love to hear from you. Our vision: A world where everyone is free to focus on their most purposeful work, together. About the Role: You'll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Wrike is looking for a Sr. Security Infrastructure Engineer to own and evolve security for our production and cloud environments, with a strong focus on network and infrastructure security. You'll design and harden the controls that keep our world secure — and you'll be the person who spots the gap before it becomes an incident. Your Impact: • Own and evolve security for Wrike's production and cloud environments, with a strong focus on network and infrastructure security. • Design, implement, and improve network security controls, including: • Internal network segmentation and lateral-movement (east-west) restrictions • WAF operations and tuning • Egress filtering • Risk- and exposure-based sequencing of remediation work • Run structured first-pass security reviews of cloud environments, checking for: • Publicly exposed storage • Open management ports • Gaps in logging/audit trail coverage • Long-lived or stale credentials • Over-privileged principals and accounts • Maintain visibility into our external attack surface, including: • DNS enumeration and certificate transparency log monitoring • External scanning of IP ranges • Dedicated ASM tooling (e.g., Rapid7 Surface Command) • Continuous configuration drift detection tied to an asset inventory with clear ownership assignment • Partner with System & Data Engineering and other ops teams to embed security into architecture and change management (design reviews, sign-offs, "secure by default" patterns). • Educate and coach engineers and operations teams on security practices through reviews, consultations, and targeted training. • Identify, track, and determine mitigation strategies for security risks. Your Qualifications: • Proven track record as a security subject-matter expert, guiding engineering teams in end-to-end secure system design, with a focus on network architecture and cloud services. • Hands-on experience designing network segmentation/architecture and operating firewall / IDS-IPS platforms in production — you think in layers , not a checklist: internal zoning/segmentation to cut east-west movement and edge protection in front of public-facing apps (Cloudflare-style WAF managed + custom rules, rate limiting, bot/DDoS protection, TLS), sequenced by which assets are most exposed or highest-risk first. • Experience running structured, read-only-first reviews of cloud environments you've never seen before, working through identity and permissions (Azure RBAC/Entra or GCP IAM — over-privileged principals, standing admin, long-lived credentials), public exposure (open management ports, public storage/blob, public IPs), logging and visibility (activity/audit and flow logs), network rules (NSGs/firewall), and secrets handling — in that order of priority, before proposing changes. Primary focus on Azure permissions and configuration, with working knowledge of GCP and on-prem components. • Experience maintaining attack surface visibility on the assumption that the known asset inventory is incomplete — discovering unregistered/shadow assets via DNS enumeration, certificate transparency logs, IP-range/cloud enumeration, external scanning, and ASM tooling (e.g., Rapid7 Surface Command) — run as a continuous, monitored process with drift detection and alerting, not a one-time scan, with ownership assigned to whatever turns up. • Skilled at identifying gaps in existing network and cloud security architecture/configuration and recommending changes (authentication, authorization, network segmentation, bastion host setup, etc.). • Able to lead the technical direction and architecture of our cyber security defense capabilities, including enterprise security posture management. • Strong communicator, able to explain complex security concepts and risks to both technical and non-technical audiences. Standout Qualities: • Ability to balance security principles with business needs. • Security certifications (e.g., CISSP, GIAC, a network security certification such as CCNP Security, etc.). • Strong understanding of Microsoft Azure; working …