1 month ago
Remote, EMEAMid Level
Responsibilities
- Operate and improve vulnerability management, including scanning, finding triage, remediation tracking, and evidence maintenance.
- Monitor SIEM and EDR systems to detect, investigate, and respond to security incidents.
- Configure and maintain EDR, SIEM, firewalls, IDS/IPS, MFA, and SSO security tooling and policies.
- Support identity and access management, privileged access, provisioning, and periodic access reviews.
- Operate ISO/IEC 27001 controls, collect audit evidence, contribute to the risk register, and support internal and external audits.
- Coordinate security assessments and penetration tests and follow up on remediation.
- Integrate and operate SAST, DAST, dependency-scanning, and container-scanning tools within CI/CD pipelines.
- Triage application-security findings with R&D teams and track remediation.
- Secure source-repository access, secrets management, artifact signing, and build and release pipelines.
- Track endpoint security posture across Windows, macOS, and Linux, including MDM enrollment, EDR coverage, and disk encryption.
- Maintain security policies, procedures, standards, and exception tracking.
- Troubleshoot security incidents and outages and produce root-cause or post-incident documentation.
- Deliver security-awareness training and educate end users on security best practices.
- Build, document, and implement internal security processes and workflows with IT and Security teams.
Requirements
- At least three years of experience in security engineering, security operations, or systems administration with a strong security focus.
- Working knowledge of firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanners.
- Solid networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewalling, ideally with hands-on experience.
- Experience with identity and access management, Active Directory or Microsoft Entra ID, and SSO/MFA platforms such as Okta or similar.
- Working experience with Microsoft 365 and Exchange Online.
- Comfort working with Windows, macOS, and Linux systems.
- Understanding of OWASP Top 10, secure-coding practices, and vulnerability triage in code and dependencies.
- Understanding of ISO/IEC 27001, SOC 2, or similar compliance frameworks and suitable audit evidence.
- Strong problem-solving, attention to detail, collaboration, and written and verbal English communication skills.
- Preferred qualifications include security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor.
- Preferred experience includes Qualys, Greenbone/OpenVAS, Wazuh, Splunk, Hexnode, SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, Bitbucket Pipelines, Jenkins, security automation with Python, Bash, or PowerShell, secure-SDLC practices, cloud and virtualization security, and ISO/IEC 27001 certification or customer security audits.
Benefits
- Remote work open to candidates in Serbia, Bulgaria, Georgia, and Armenia.
- Share options and referral bonuses.
- Certifications and learning opportunities aligned with the employee’s interests and role requirements.
- Collaborative environment, growth opportunities, and additional perks and engagement opportunities.
