Назад

Не получаете ответ?

Вакансия опубликована 9 дн. назад - шансы на ответ снижаются.

обновлено 10 дней назад

Information Security Engineer (Fintech)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
junior
Английский
b2
RUВакансия из Hirify RU, списка российских tech-компаний

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

Текст:
/
TL;DR
Information Security Engineer (Fintech): Operating vulnerability management and security monitoring functions for a proprietary algorithmic trading firm with an accent on vulnerability triage, remediation tracking, log pipelines, and detection engineering. Focus on tuning security alerts, supporting incident response, reconstructing event timelines, and automating security operations with Python or Bash.

Location: Fully remote from anywhere in the world

Company

Proprietary algorithmic trading firm managing the full trading cycle across equities, derivatives, options, futures, rates, and other financial markets.

What you will do

  • Operate and maintain vulnerability scanners, scan schedules, coverage, agents, and scanning engines.
  • Triage vulnerability findings, assess severity and exposure, assign issues, track remediation SLAs, verify fixes, and maintain vulnerability metrics.
  • Monitor vulnerability feeds and vendor advisories, identifying time-critical patches.
  • Operate the central log pipeline, onboard log sources, monitor shipper health, and manage retention.
  • Maintain and tune detection rules for authentication anomalies, firewall changes, privileged actions, and exchange-account events.
  • Triage alerts, participate in on-call rotations, and support incident response through evidence collection, timeline reconstruction, and post-incident follow-up.

Requirements

  • 1–3 years of experience in security, DevOps, or systems administration.
  • Strong Linux fundamentals, including processes, permissions, logs, systemd, and SSH.
  • Understanding of networking basics, including TCP/IP, DNS, firewalls, and VPN concepts.
  • Understanding of the vulnerability lifecycle, including CVE, CVSS, patching, and mitigation.
  • Scripting ability in Python or Bash and familiarity with Git and merge-request workflows.

Nice to have

  • Experience with vulnerability scanners such as Rapid7, Nessus, OpenVAS, or Qualys.
  • Experience with log or SIEM platforms such as Graylog, ELK, Wazuh, or Splunk.
  • Experience with Ansible, configuration management, containers, or Kubernetes.

Culture & Benefits

  • Flexible remote work from anywhere in the world.
  • Flexible schedule within a globally distributed team.
  • Technology-focused environment without bureaucracy or legacy systems.
  • Compensation for health insurance, sports, and professional development.
  • Opportunities for professional growth and ownership of impactful security operations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →