
Security Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Serbia, +2 more states.
• Execute and enhance vulnerability management by conducting and fine-tuning scans, assessing findings, coordinating remediation with system owners, and preserving scan documentation.
• Oversee SIEM and EDR platforms to identify, investigate, and address security incidents.
• Configure and maintain EDR, SIEM, firewalls, intrusion detection and prevention systems, as well as MFA/SSO policies.
• Assist with identity and access management, covering access provisioning, privileged access, and routine access evaluations.
• Contribute to ISO/IEC 27001 operations through the implementation of controls, collection of evidence, input to the risk register, and support during audits.
• Aid in security assessments, coordinate penetration tests, and follow up on remediation efforts.
• Support application security throughout the software development lifecycle by managing SAST, DAST, dependency scanning, and container scanning within CI/CD pipelines.
• Evaluate application-security findings alongside R&D teams and oversee remediation tracking.
• Enhance the security of the build and release process, including repository access control, secrets management, artifact signing, and pipeline hardening.
• Develop and maintain security policies, procedures, standards, and track exceptions.
• Monitor endpoint security posture across Windows, macOS, and Linux, including MDM enrollment, EDR coverage, and disk encryption.
• Engage in security-awareness training and inform end users about security best practices.
• Diagnose security-related outages and incidents, producing root-cause or post-incident documentation.
• Create, document, and implement internal processes and workflows in collaboration with the IT and Security teams.
• Remain updated on security threats, trends, and technologies.
• A minimum of three years of experience in security engineering, security operations, or systems administration with a robust security focus.
• Practical knowledge of firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanning tools.
• Strong grounding in networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewall configurations.
• Familiarity with identity and access management systems, including Active Directory or Microsoft Entra ID and Okta or similar SSO/MFA platforms.
• Experience working with Microsoft 365 and Exchange Online.
• Proficient in managing Windows, macOS, and Linux systems.
• Understanding of application security principles, including the OWASP Top 10, secure coding practices, and vulnerability assessment in code and dependencies.
• Knowledge of ISO/IEC 27001, SOC 2, or comparable security and compliance frameworks, including appropriate audit evidence.
• Excellent problem-solving abilities and meticulous attention to detail.
• Capability to work collaboratively as part of a team.
• Strong written and verbal communication skills in English.
• Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or equivalent would be advantageous.
• Experience with tools like Qualys, Greenbone/OpenVAS, Wazuh, Splunk, or similar is a plus.
• Familiarity with MDM tools such as Hexnode or similar, as well as endpoint hardening, would be beneficial.
• Experience in security automation using Python, Bash, or PowerShell would be a plus.
• Hands-on experience with application security tools such as SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, or similar would be advantageous.
• Experience with CI/CD security practices using Bitbucket Pipelines, Jenkins, or similar tools would be beneficial.
• Acquaintance with secure SDLC practices, including threat modeling, security code reviews, and secrets scanning would be an advantage.
• Exposure to cloud and virtualization platforms and their associated security models would be a plus.
• Previous involvement in an ISO/IEC 27001 certification process or customer security audits would be advantageous.
• A position at the leading edge of cloud technology, offering significant impact and growth prospects.
• A collaborative workplace where your ideas are appreciated and implemented.
• Additional perks and opportunities for engagement.
• Share options.
• Referral bonuses.
• Opportunities for certifications and learning aligned with personal interests and role requirements.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.