136 karma · joined October 10, 2013
Forter's fraud prevention decision as a service technology is way ahead of the competition. And we are investing in automation, infrastructure and security to keep it that way. For example, Forter requires data to be synced in multiple AWS regions in real-time while staying compliant with SOC2 and GDPR.
We are looking for an Infrastructure Engineering Manager that will lead a team of 3 additional Infrastructure Engineers (1 AWS expert, 1 security/infosec expert, a new hire and yourself). Your job would be to make sure we keep winning new customers by delivering our new cross-region solution, chaos monkey automation, negotiate technical RFPs and present our strong technical capabilities to customers, deliver secure microservice and data pipeline infrastructure. We expect this job to be 50% hands-on.
To learn more about our strong engineering team, check out our engineering blog: https://tech.forter.com
To learn more about your new manager, here is Oren's readme: https://managerreadme.com/readme/orenellenbogen
Our Tech Stack: AWS, Docker, Chef, Java, Python, Nodejs, ElasticSearch, Couchbase, MySQL, Redis ...
For any questions you might have contact itai(at)forter.com
This job requires an Israeli job permit.
Doing it without server support is tricky.
Have you considered adding a semantic layer inside streams that allows each client to consume a substream? In effect the stream becomes multiplexed substreams.
If substreams makes the design too complex... have you considered server side stream 403 semantics? When a stream is manually deprecated it enters an immutable state and provides a redirect response with a link to another stream. This would allow multiplexing and demultiplexing streams without changing the client implementations too much.
For completeness I would state the obvious when fifo grouping is needed: 1. Scaling stateful event processing by splitting streams and adding more clients (CPU limit) 2. Scaling cross region replication by splitting streams and adding more tcp connections (network limit) 3. Handling more throughput by splitting a stream into two redis nodes (disk I/O limit)
1. Consider adding an example for a stateful event stream processor client that saves the last read stream offset in redis, together with its current state and continues reading from that offset as an atomic operation. For example, a client that sums a stream of numbers, in order to have effectively once semantics would need to persist to redis the sum and offset together.
2. Consider adding a stream read deduplication example to mitigate clients that reinserted the same event twice. It is not clear how the client should behave if it didn't get an ack and it resents an event. What is the correct resending semantics so the reader would effectively dedup? What is the right data structure used to dedup message ids without consuming too much memory, etc...?
I am not sure configuring these settings are trivial, and VPN clients provide that out-of-the-box.
One example if you have an internal web service, how would you restrict access only to employees (without having it open to the internet?). SSO is not enough since you want the ports closed to non employees.
Another example is accessing a database that is not configured with SSL. You don't want your info travelling in plaintext on the internet.
I would have used s3 for that.
I need to rearrange that paragraph and add the 2 other reasons you mentioned, and you are right that outgoing emails are better sent from subdomains.
I do wonder though if a spam filter blocks x.d.com would it also block emails from d.com?
us-west - perhaps I should change it to don't use us-east-1, since it fails much more often and is more crowded.
I'll rephrase the git and 2fa.
Endpoint Security - you gotta have it. I understand the natural objections, but there is no certification that doesn't ask about it. There are the more expensive ones like cyberreason or carbonblack.
I need to research more the domains issue. I suppose it's more prevalent in Israel since some devops in Israel worked for gaming (gambling) companies where they definitely use multiple domains for multiple purposes. But I think the main reason is allowing devs more management access to internal subdomains and disallowing management access to the API endpoint domains that customers use, to reduce attack surface.
Thanks for your comments. Keep them coming