
Security Engineer – Mid-Level
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Bulgaria, +2 more states.
• Safeguard Virtuozzo’s networks, systems, and data against cyber threats.
• Enhance vulnerability management by conducting and fine-tuning scans, addressing findings, tracking remediation efforts, and preserving scan evidence.
• Oversee SIEM and EDR systems and logs to identify, investigate, and respond to security incidents.
• Configure and maintain EDR, SIEM, firewalls, IDS/IPS, MFA, and SSO policies.
• Assist with identity and access management, which includes provisioning, managing privileged access, and conducting periodic access reviews.
• Contribute to ISO/IEC 27001 operations, implement controls, gather evidence, provide inputs for the risk register, and participate in audits.
• Support security assessments, coordinate penetration testing, and follow up on remediation efforts.
• Promote application security throughout the SDLC via SAST, DAST, dependency scanning, and container scanning in CI/CD pipelines.
• Collaborate with R&D teams to triage application security findings and monitor remediation progress.
• Help secure build and release procedures, including repository access, secrets management, artifact signing, and pipeline hardening.
• Maintain security policies, procedures, standards, and track exceptions.
• Monitor the security posture of endpoints across Windows, macOS, and Linux platforms.
• Engage in security awareness training and educate end users accordingly.
• Resolve security outages and incidents, producing documentation on root causes or post-incident analyses.
• Develop, document, and implement internal IT and Security processes and workflows.
• Keep abreast of security threats, trends, and technologies.
• A minimum of three years of experience in security engineering, security operations, or systems administration with a strong emphasis on security.
• Proficient understanding of firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanning tools.
• Solid grasp of networking principles, including TCP/IP, VLANs, routing, VPNs, and firewall configurations.
• Experience in identity and access management, Active Directory or Microsoft Entra ID, and SSO/MFA platforms like Okta or similar.
• Familiarity with Microsoft 365 and Exchange Online.
• Comfortable working across Windows, macOS, and Linux environments.
• Knowledge of application security fundamentals, OWASP Top 10, secure coding practices, and vulnerability triage in code and dependencies.
• Understanding of ISO/IEC 27001, SOC 2, or similar frameworks, including appropriate audit evidence.
• Strong analytical skills and meticulous attention to detail.
• Ability to collaborate effectively within a team.
• Excellent written and verbal communication skills in English.
• Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or similar are advantageous.
• Experience with tools such as Qualys, Greenbone/OpenVAS, Wazuh, Splunk, MDM tools, endpoint hardening, Python, Bash, PowerShell, SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, Bitbucket Pipelines, Jenkins, secure SDLC practices, cloud platforms, virtualization platforms, or ISO/IEC 27001 certification programs would be beneficial.
• A position at the cutting edge of cloud technology with significant impact and growth prospects.
• A collaborative atmosphere where your ideas are appreciated and implemented.
• Additional perks and engagement opportunities.
• Share options.
• Referral bonuses.
• Opportunities for certifications and learning aligned with interests and role requirements.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.