
Security Engineer
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Costa Rica.
• Oversee, assess, investigate, and respond to security alerts across various platforms, including endpoint, network, identity, and cloud security.
• Evaluate the scope, severity, and potential impact of incidents; implement initial containment measures and escalate complex or high-impact incidents as needed.
• Review security telemetry, logs, endpoint activities, network traffic, and related data to detect anomalous behavior and potential threats.
• Perform targeted threat hunting in response to emerging threats, intelligence, and attacker behavior.
• Contribute to the development, testing, tuning, and maintenance of SIEM detection rules, correlation logic, and alerting capabilities.
• Aid in the configuration, integration, maintenance, and operational effectiveness of SIEM, EDR, IDS/IPS, endpoint, and network security controls.
• Assist with vulnerability scanning, analysis, prioritization, and tracking remediation efforts.
• Collaborate with technical teams to validate vulnerability findings and ensure timely remediation.
• Keep track of threat intelligence, vulnerabilities, attacker TTPs, and emerging security trends.
• Utilize threat intelligence in investigations, threat hunting, and enhancing detection capabilities.
• Create and maintain incident response procedures, playbooks, runbooks, investigation guides, and documentation of lessons learned.
• Enhance SOC processes, detection capabilities, and response protocols.
• Support cybersecurity awareness training, phishing simulations, and awareness-testing initiatives.
• Analyze results from awareness campaigns and identify areas for improving employee security awareness.
• Strong bilingual proficiency in both English and Spanish across written, virtual, and in-person communications.
• Bachelor’s degree in Information Technology, Computer Science, or a related discipline.
• 2-4 years of experience in roles related to information security.
• Familiarity with information security principles, tools, and technologies, including network security monitoring, incident-response triage, and identity management.
• Understanding of attacker tactics, techniques, procedures, and frameworks, such as MITRE ATT&CK.
• Proficient knowledge of TCP/IP, DNS, HTTP/S, firewalls, VPNs, and common networking protocols.
• Experience with Windows, macOS, and Linux systems, including command-line interface usage.
• Ability to explain complex technical issues to both technical and non-technical stakeholders.
• Strong analytical, time-management, and project-management abilities.
• Capability to juggle multiple priorities, resolve intricate technical problems, and function effectively in a fast-paced setting.
• Proactive mindset, enthusiasm for continuous learning, and readiness to take ownership of tasks.
• Preferred: Professional security certifications such as CompTIA Security+, GSEC, Associate of ISC2, or equivalent.
• Preferred: Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001, SOC 2, or similar frameworks.
• Preferred: Basic experience in scripting or automation with Python, PowerShell, Bash, or similar languages.
• Preferred: Understanding of AI applications in security operations, including experience in creating or managing AI agents.
• Preferred: Experience with AWS, Azure, or Google Cloud Platform.
• Must confirm identity and eligibility to work in the United States upon hiring.
• Comprehensive medical, dental, and vision insurance coverage.
• Company-sponsored counseling, coaching, and resources for you and your family through Spring Health.
• Paid parental leave policy.
• Equity stock options upon hiring, with annual performance-based grants.
• Membership to LinkedIn Learning.
• Monthly reimbursements for meaningful team interactions through the SocialSpace Community.
Cisco
Arctiq
Cotiviti
Twilio
Get handpicked remote jobs straight to your inbox weekly.