Virtuozzo

Security Engineer

Virtuozzo
Apply
1 month ago
Remote, EMEAMid Level

Responsibilities

  • Run and tune vulnerability scans, triage findings, track remediation, and maintain scan evidence.
  • Monitor SIEM and EDR platforms to detect, investigate, and respond to security incidents.
  • Configure and maintain EDR, SIEM, firewalls, IDS/IPS, MFA, and SSO policies.
  • Support identity and access management, including provisioning, privileged access, and periodic access reviews.
  • Operate ISO/IEC 27001 controls, collect evidence, contribute to the risk register, and support internal and external audits.
  • Coordinate security assessments and penetration tests and follow up on remediation.
  • Integrate and operate SAST, DAST, dependency-scanning, and container-scanning tools in CI/CD pipelines.
  • Triage application-security findings with R&D teams and track remediation.
  • Secure source-repository access, secrets management, artifact signing, and build and release pipelines.
  • Track endpoint security posture across Windows, macOS, and Linux, including MDM enrollment, EDR coverage, and disk encryption.
  • Maintain security policies, procedures, standards, and exceptions; support security awareness and internal security processes.
  • Troubleshoot security outages and incidents and produce root-cause or post-incident documentation.

Requirements

  • At least three years of experience in security engineering, security operations, or systems administration with a strong security focus.
  • Working knowledge of firewalls, IDS/IPS, SIEM, EDR, vulnerability scanners, and core security concepts.
  • Solid networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewalling, preferably with hands-on experience.
  • Experience with identity and access management, Active Directory or Microsoft Entra ID, and SSO/MFA platforms such as Okta or similar.
  • Working experience with Microsoft 365 and Exchange Online.
  • Comfort working with Windows, macOS, and Linux systems.
  • Understanding of application-security fundamentals, the OWASP Top 10, secure coding, and vulnerability triage in code and dependencies.
  • Understanding of ISO/IEC 27001, SOC 2, or similar frameworks and appropriate audit evidence.
  • Strong problem-solving, attention to detail, collaboration, and English written and verbal communication skills.
  • Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are advantageous.
  • Experience with Qualys, Greenbone/OpenVAS, Wazuh, Splunk, Hexnode, SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, Bitbucket Pipelines, or Jenkins is advantageous.
  • Security automation experience with Python, Bash, or PowerShell and exposure to cloud and virtualization security are advantageous.
  • Experience with threat modeling, security code reviews, secrets scanning, ISO/IEC 27001 certification programs, or customer security audits is advantageous.

Benefits

  • Remote role open to candidates in Serbia, Bulgaria, Georgia, and Armenia.
  • Share options and referral bonuses.
  • Certifications and learning opportunities aligned with the candidate’s interests and role requirements.
  • Collaborative environment, growth opportunities, and additional perks and engagement opportunities.

Tech Stack

BashJenkinsLinuxmacOSPowerShellPythonSonarQubeSplunkWindows

Categories

Virtuozzo

About Virtuozzo

201-500 employees
Contact me