Matomo

Infrastructure Support Engineer / SRE | Cossack Labs

đŸ‡ș🇩 We bring our capabilities to all institutions that help protect Ukraine across critical infrastructure, defence, and government.

Back to the list

Infrastructure Support Engineer / SRE

Kyiv, Lviv, Ukraine・Flexible Remote・Full time // Build, secure and scale the complex security‑sensitive system that safeguards critical infrastructure.

The opportunity: #

This position is open exclusively for Ukrainian residents within Ukraine (preferably Kyiv or Lviv). We welcome candidates at all experience levels — from junior to senior.

Cossack Labs is a British cybersecurity firm with R&D centres in Ukraine. We solve security challenges in complex security-sensitive systems end-to-end: we deliver R&D, services, developer tools and bespoke solutions addressing practical risks in high-stakes scenarios.

Our Infrastructure & Hardware department is looking for an infrastructure geek as we continue our purposeful, long-term growth, built on a stable and dedicated team.

We take on mission‑critical projects and prioritise building for decades, rather than just until the next release. We put strong emphasis on developing our new team members, offering an extended onboarding period, a clear PDP, and direct involvement from the Department Head from day one. Tell us where you can add value, and we will provide the tools, knowledge, and support for you to succeed.

Markets: EU, UK, USA, UA.

Sounds interesting?

What makes you a great match: #

  • Curiosity: In addition to knowing how things work, you also want to know why they work that way
  • Solid communication skills are a must — because mind-reading isn’t part of the job
  • A natural inclination to keep everything around you organised, design conventions and follow them
  • Strong logical thinking (by the third page of the detective story, you already know who the killer is)
  • You’d rather automate it all, instead of doing it each time by hand
  • You have the persistence to complete the “boring” parts of the job, like writing technical documentation or running tests

You will: #

  • Maintain the infrastructure of commercial projects with huge social impact, as well as internal — for development and R&D purposes
  • Design and implement HA systems
  • Learn what “proper security” means and participate in security assessments
  • Experiment with unconventional tasks
  • Enhance SDLC for our products
  • Participate in formulating internal procedures, standards, and workflows
  • Collaborate with a team of talented engineers when doing everything above

We would expect you to have: #

  • Good knowledge of Linux systems and networking
  • Understanding of the main Internet systems and services
  • Good skills in programming in at least two scripting languages: Bash && (Python || Ruby)
  • Familiarity with Docker and KVM
  • Basic familiarity with IaC tools (at least one of Ansible/Chef/Puppet/Salt) and IaC approaches
  • Troubleshooting skills
  • Familiarity with monitoring tools and basic principles
  • Sufficient knowledge of English to read this entire job posting and understand everything

As a plus you’d have: #

  • Knowledge of main cryptography and security protocols, algorithms, approaches and instruments
  • Experience of PostgreSQL/MySQL and other database systems
  • Understanding of and hands-on experience with computer hardware and networking equipment (servers, embedded systems, routers, switches)
  • Experience in at least one of the non-scripting languages: C/C++/Go/Rust
  • Understanding of key software development principles and lifecycle

Hiring Process: #

  • Resume review — 5-7 business days
  • Questionnaire and your answers review — 3-4 business days
  • Introduction call with the Head of Infrastructure & Hardware Engineering
  • Test task — 2 hours working with a virtual machine
  • Technical interview with several team members
  • Offer discussion
  • Years of fantastic collaboration :)

Please note that you can be a perfect fit even if not everything we’ve outlined above applies to you. If you have any questions, please don’t hesitate to ask – everyone is unique.

We offer: #

Unique area of expertise: #

  • Interesting and challenging work in applied security engineering: from building to breaking. Working at the intersection of different areas: designing ML security controls, supporting cryptographic protocols with security controls, protecting hardware, building reverse-resilient mobile apps, securing web apps for million of users, etc.
  • Public track record in the open source part of our products, sharing your work as blogs posts, research papers and conference talks. We work with innovative companies all over the world, move quickly and dive into technologies others just hear about.
  • Combining technologies: cryptography, software engineering, information security. You won’t be bored :)
  • A sense of meaning and responsibility for those who seek purpose — we’re building “invisible texture of modern civilization” — bits of infrastructure finance, power grids, healthcare rely on, and we are trusted with very challenging aspects of it.

Environment: #

  • Friendly and experienced team: smart people to learn from, great people to build with. Each of us is unique, we value and support each other.
  • An atmosphere that motivates you to grow and get smarter every month, a healthy ratio of routine / experimentation.
  • Trust: schedule, reporting, bureaucracy is kept at reasonable minimum. We hire smart people and trust them to do the right thing. When things go wrong, we help rather than punish.
  • Shared decision making: this business is driven by engineering excellence, so engineers are important part of tactical and strategical business decisions.
  • Friendly to humans: not just a formal vacation and sick leave quota. Feel like your mental or physical wellbeing needs care? Take some time off. Feel like working a few days from home? Sure. As long as you’re in line, we are here to support you when you’re not.

Growth: #

  • Team that facilitates internal learning and growth all the time.
  • Interesting technologies to work with — sometimes, even unique ones (we design applied cryptography schemes and techniques and novel ways to use them).
  • Interesting engineering challenges across the board, ability to hop from high-level system design to protocol reverse engineering and clever data modelling hacks.
  • Management attention to help you improve upon your personal goals (through 1:1s and mentoring).

Benefits: #

  • Competitive compensation with flexible bonus scheme.
  • Sick leaves, 21 business days for vacation per year, extra days off — according to the agreements and laws.
  • Conferences, books, courses — we encourage learning and sharing with the community. Our team members share a lot in talks, workshops and blog posts.

Not sure but considering? Talk to us. #

If you see yourself fit but a few things are off — don’t hesitate to talk anyway. It might be that your unique combination of skills and knowledge would be perfectly fitting for our environment, but we both just don’t know it yet.

Why work at Cossack Labs? #

Some companies prioritise talent and value proposition, while others understand business and would take any job that pays well. However, only few companies choose to specialise in difficult tasks as their primary competency.

We take on difficult jobs, we take mission-critical software and make it mission-secure.

  • Virtualise OT infrastructure securely in the presence of active adversaries, preventing them from accessing the susceptible nation-wide network? ✓ Check.
  • Provide immediate application security and infrastructure security guidance for mission-critical application that will be deployed on thousands of devices on the front-line tomorrow? ✓ Check.
  • Validate counter-reverse engineering protections for power grid hardware to ensure that previously air-gapped environments were safe to open up to the outside world? ✓ Check.
  • Ensure that software platforms for exchange of sensitive documents actually have a top-tier SSDLC programme that supplements missing capabilities and builds out processes? ✓ Check.

We operate as a lean core team and a diverse network of experts. The finest people you may work with include PhDs in information security and cryptography, infosec community standard contributors, in-depth experts in rare security topics, and business-centric security engineers with broad experiences. Some of your teammates have worked in infosec since the 1990s and saw the industry grow from nothing. Some of them helped write standards that govern security around you. Maybe someone’s work actually keeps the lights up while you’re reading this?

Our core engineers go through extensive indoctrination and training to become disciplined, stringent, self-sufficient field unit who owns the outcomes rather than just showing up for work.

As you grow into the Cossack Labs engineer, you’ll work on slow-paced projects to learn and improve, internal projects to innovate and build tools, and of course a few fires, because no smooth sea can make a skilled sailor. You’ll discover what works for you and what you need to learn.

We help innovators who are launching new venues of civilisation while facing significant security risks in becoming more secure and resilient. Customers trust us to achieve their business goals, not merely address gaps someone else has to identify first.

If this is a challenge you’re up to, let's talk!

How to apply?

We'd like to get your CV to start a conversation. A supporting letter explaining your story and experience in application security, what you have done in the past and what kind of work you find interesting would help, but is not necessary.

Contact us

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days