
Security Engineer
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Pakistan, +2 more countries.
• Act as a Tier 3 escalation point for ongoing security incidents, such as BEC, AiTM, ransomware, account compromises, identity-based attacks, and other security occurrences.
• Direct technical analysis during incident response and war room situations, which includes log examination, IOC hunting, attacker activity assessment, and lateral movement tracking.
• Implement containment and eradication measures like endpoint isolation, session termination, credential resets, and access limitations.
• Resolve incidents spanning identity, endpoints, servers, networking, cloud services, and security controls.
• Collaborate with SOC, infrastructure, and vendor threat intelligence teams throughout investigations and containment efforts.
• Clearly communicate incident status, actions taken, next steps, and support requirements.
• Generate incident timelines, technical findings, and evidence packages for vCISO review and subsequent client follow-up.
• Operate the gShield security toolset, which includes Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and associated technologies.
• Conduct alert triage, risk identification, issue resolution from scans, investigations, and follow-up actions.
• Assist SIEM operations with query development, alert assessment, log analysis, investigations, and rule tuning.
• Refine detection logic, scan configurations, and platform efficacy.
• Monitor security vulnerabilities, anomalous activity, configuration flaws, and control inadequacies.
• Correlate data from identity, endpoints, networks, servers, and cloud during investigations.
• Implement security principles across on-premises, cloud, and hybrid client environments.
• Troubleshoot issues related to Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
• Support security hardening, identity and access security, endpoint and server controls, patching, configuration enhancements, and remediation efforts.
• Investigate, test, validate, and document solutions for unfamiliar technologies.
• Carry out technical remediation based on MRMMs, preventative measures, vulnerability assessments, and security recommendations.
• Assist with gShield deliverables through technical validation, evidence collection, scan reviews, vulnerability analysis, and remediation confirmation.
• Evaluate vulnerabilities considering severity, asset importance, exposure, exploitability, existing controls, and business impact.
• Work alongside client and internal technical teams on vulnerability remediation and compensating controls.
• Ensure that identified risks have been effectively addressed.
• Provide quality assurance for client onboarding into the gShield toolset.
• Help with client hardening and security enhancement actions across various managed environments.
• Aid in the remediation of the internal GXA security backlog and POA&M-related tasks.
• Assist with phishing-resistant MFA, passkeys, and other internal security initiatives.
• Proven experience in security incident management and response.
• Strong technical understanding of security principles and best practices.
• Familiarity with security tools and technologies, including SIEM and endpoint protection solutions.
• Excellent communication skills for conveying complex technical information to both technical and non-technical stakeholders.
• Ability to work collaboratively with various teams and stakeholders.
• Strong analytical and problem-solving skills.
• Knowledge of cloud security practices and technologies.
• Competitive salary and comprehensive benefits package.
• Opportunities for professional development and growth.
• Flexible work environment and supportive team culture.
• Access to cutting-edge security technologies and tools.
GardaWorld Federal Services
Cherokee Federal
Foundant Technologies
FRSecure
Get handpicked remote jobs straight to your inbox weekly.