
Cybersecurity Engineer – Endpoint & Identity
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in Ukraine.
• Maintain hardening and configuration baselines for endpoints and servers, including encryption, security policies, and benchmarks.
• Deploy and oversee endpoint and server protection throughout the organization, incorporating EDR/NGAV, antivirus, device management, and ensuring compliance with security policy enforcement and configuration.
• Administer network security measures such as firewalls, VPNs, network segmentation, and access controls, while monitoring traffic for any suspicious activities.
• Evaluate infrastructure projects and architecture from a security standpoint to guarantee secure-by-default configurations.
• Conduct regular vulnerability scans across endpoints, servers, and the cloud, focusing on risk-based prioritization and tracking remediation efforts.
• Implement identity and access best practices, including role-based access, least privilege, MFA, and privileged access management, along with performing periodic access reviews.
• Monitor and analyze security events and logs to identify anomalies and potential threats.
• Detect, investigate, contain, and resolve security incidents, including documenting timelines, root causes, and lessons learned.
• Oversee cloud and SaaS security posture, rectify misconfigurations, and assess third-party integrations and access scopes.
• Establish and document technical security controls, such as runbooks and hardening guides, and assist with internal and external audits.
• 5+ years of practical experience in IT infrastructure or cybersecurity engineering, with a distinct focus on security.
• Proven experience in administering and hardening Linux, Windows, and macOS systems using MDM solutions.
• Familiarity with endpoint protection and device management platforms, including EDR/NGAV, MDM, and antivirus solutions.
• Strong knowledge of networking fundamentals such as TCP/IP, DNS, DHCP, and VPN, along with hands-on experience with firewalls and network security controls.
• Direct experience with identity and access management/SSO platforms, emphasizing a security-first approach.
• Proficient in using vulnerability management tools and handling SIEM/SOC monitoring and incident-response processes.
• Awareness of common attack types and the methods for detection and prevention.
• Practical familiarity with established security frameworks and standards.
• Analytical mindset capable of assessing risk and prioritizing effectively.
• Strong communication skills, able to convey technical issues to non-technical colleagues clearly.
• Proficiency in English for documentation, vendor interaction, and communication with external partners.
• Competitive salary alongside a comprehensive benefits package, including insurance, paid sick leave, and 20 days of paid time off per year.
• Advantages associated with the defense sector, such as reservation benefits, among others.
• Flexible remote work options where feasible.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.