
Security Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Serbia, +2 more states.
• Manage and enhance vulnerability management by executing and optimizing scans, assessing findings, coordinating remediation with system owners, and preserving scan documentation.
• Oversee SIEM and EDR platforms to identify, investigate, and respond to security incidents.
• Configure and maintain EDR, SIEM, firewalls, intrusion detection and prevention systems, as well as MFA and SSO policies.
• Assist with identity and access management, which includes access provisioning, privileged access, and regular access reviews.
• Support ISO/IEC 27001 operations through control implementation, evidence collection, risk register contributions, and audit assistance.
• Aid in security assessments, coordinate penetration testing, and follow up on remediation efforts.
• Facilitate application security throughout the software development lifecycle by managing SAST, DAST, dependency scanning, and container scanning within CI/CD pipelines.
• Assess application-security findings in collaboration with R&D teams and monitor remediation progress.
• Help secure the build and release pipeline, including access to source repositories, secrets management, artifact signing, and pipeline hardening.
• Maintain security policies, procedures, and standards while tracking exceptions.
• Monitor the security posture of the endpoint fleet across Windows, macOS, and Linux, focusing on MDM enrollment, EDR coverage, and disk encryption.
• Engage in security-awareness training, educating end users about security best practices.
• Resolve security-related outages and incidents, generating root-cause or post-incident documentation as necessary.
• Develop, document, and implement internal processes and workflows in collaboration with the broader IT and Security teams.
• Stay current on security threats, trends, and technologies.
• Minimum of three years of experience in security engineering, security operations, or systems administration with a strong security emphasis.
• Proficient knowledge of firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanning tools.
• Strong foundation in networking principles, including TCP/IP, VLANs, routing, VPNs, and firewalls.
• Experience with identity and access management systems, including Active Directory or Microsoft Entra ID, and SSO/MFA platforms like Okta or similar.
• Familiarity with Microsoft 365 and Exchange Online.
• Comfortable working across Windows, macOS, and Linux environments.
• Understanding of application-security basics, including the OWASP Top 10, secure coding practices, and vulnerability assessment in code and dependencies.
• Knowledge of security and compliance frameworks such as ISO/IEC 27001, SOC 2, or similar, along with relevant audit evidence.
• Excellent problem-solving abilities and meticulous attention to detail.
• Capacity to collaborate effectively within a team setting.
• Strong written and verbal communication skills in English.
• Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or similar are advantageous.
• Familiarity with tools like Qualys, Greenbone/OpenVAS, Wazuh, Splunk, or similar would be beneficial.
• Experience with MDM solutions like Hexnode or similar, as well as endpoint hardening, would be an asset.
• Experience in security automation using Python, Bash, or PowerShell is a plus.
• Hands-on experience with tools like SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, or similar would be advantageous.
• Experience with CI/CD security using Bitbucket Pipelines, Jenkins, or similar tools would be beneficial.
• Familiarity with secure SDLC practices, including threat modeling, security code reviews, and secrets scanning, would be advantageous.
• Exposure to cloud and virtualization platforms and their security models would be a plus.
• Previous involvement in an ISO/IEC 27001 certification program or customer security audits would be an advantage.
• A position at the cutting edge of cloud technology with significant impact and growth potential.
• A collaborative workplace where your ideas are appreciated and implemented.
• Additional perks and engagement opportunities.
• Share options.
• Referral bonuses.
• Opportunities for certifications and learning tailored to your interests and role requirements.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.