Overview
Head of Cyber Security Jobs in Ukraine at TunlyVPN
Title: Head of Cyber Security
Company: TunlyVPN
Location: Ukraine
About TunlyVPN
TunlyVPN is a modern privacy-focused VPN service built around speed, reliability, and security.
We believe infrastructure should be trusted by design — without invasive telemetry, unnecessary tracking, or marketing nonsense.
We are looking for a Head of CyberSecurity who will lead and strengthen the company’s security across infrastructure, internal systems, operational processes, and incident response.
Responsibilities
- Design and implement the company-wide cybersecurity strategy;
- Audit and secure VPN infrastructure and internal services;
- Build and maintain a secure-by-default environment;
- Manage access control, secrets, keys, and infrastructure policies;
- Develop monitoring, logging, and anomaly detection systems;
- Perform security reviews of infrastructure and applications;
- Lead incident response and post-incident analysis;
- Work closely with DevOps and backend engineering teams;
- Conduct internal security audits and penetration testing;
- Research emerging threats and implement modern security practices.
Requirements
- Strong understanding of Linux systems and networking;
- Practical experience with WireGuard, firewalls, IDS/IPS, and infrastructure hardening;
- Solid understanding of Zero Trust architecture principles;
- Experience with Docker, Kubernetes, and cloud environments;
- Knowledge of modern attack vectors and defensive techniques;
- Experience with SIEM and monitoring systems;
- Understanding of cryptography and secure data handling;
- Ability to think both like a defender and, occasionally, like an attacker.
Nice to Have
- Experience working on privacy-focused products;
- Participation in bug bounty, CTF, or pentest projects;
- Experience automating security checks and workflows;
- Open-source contributions;
- Ability to remain calm while looking at Grafana at 3 AM.
What We Offer
- Work on real-world high-load infrastructure;
- Direct impact on the platform’s security architecture;
- Modern technology stack and engineering freedom;
- Fully remote work environment;
- Healthy engineering culture;
- Opportunity to build security properly — not just for compliance checkboxes.