
Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Serbia.
• Take charge of the technical aspects of information security for both infrastructure and internal systems.
• Manage the lifecycle of vulnerability management, encompassing scanning, triage, prioritization, remediation, exceptions, and verification.
• Enhance and operate security monitoring and SIEM tools, focusing on alert quality, dashboards, detection rules, and integrations.
• Investigate security alerts and spearhead technical responses to security incidents.
• Strengthen security measures for Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services.
• Oversee technical controls related to identity and access management, least privilege, just-in-time access, secrets, and certificates.
• Automate processes for patching, evidence collection, recurring control checks, and various other security operations.
• Organize penetration tests and guide the remediation and verification of technical findings.
• Convert SOC 2 and ISO 27001 control requirements into efficient technical implementations.
• Generate technical evidence for both internal and external audits in collaboration with the Compliance Manager.
• Keep security runbooks, system documentation, risk-based priorities, and operational metrics up to date.
• Assist engineering teams in making informed security decisions without unnecessary bureaucratic hurdles.
• Provide clear direction to Engineering and Infrastructure teams and ensure the resolution of security issues.
• Demonstrated ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment.
• Strong foundational knowledge of Linux systems, networking, and cloud security.
• Hands-on experience with vulnerability management, patching, hardening, and remediation on a large scale.
• Experience in operating SIEM or security monitoring systems and investigating security incidents.
• Practical knowledge of IAM, privileged access, secrets management, certificates, and network controls.
• Proficiency in automating operational tasks using Python, Bash, infrastructure-as-code, or similar tools.
• Experience in incident response with a clear communication style during high-pressure situations.
• Familiarity with ISO 27001, SOC 2, or comparable security control frameworks.
• Excellent written and spoken English skills.
• Ability to work independently in a remote and asynchronous team environment.
• Sound risk judgment with the capability to differentiate between urgent security issues, acceptable exceptions, and low-impact processes.
• Experience with Wazuh or a similar SIEM/security-monitoring platform is a plus.
• Background with Teleport, PAM, or just-in-time access systems is advantageous.
• Experience in securing extensive Linux server fleets or hybrid cloud/on-premise environments is beneficial.
• Knowledge of CI/CD systems, build infrastructure, containers, and software supply chain security is a plus.
• Experience in supporting SOC 2 or ISO 27001 audits from a technical control perspective is a plus.
• Relevant certifications like Security+, CISSP, CISM, GIAC, or ISO 27001 are advantageous, but not mandatory.
• Competitive salary and performance-based bonuses.
• Flexible work arrangements, including remote work options.
• Opportunities for professional development and advancement.
• Comprehensive health and wellness benefits.
• Collaborative and inclusive work culture.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.