13 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Security Operations Engineer
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Security Operations Engineer (Incident Response/Cloud Security): Strengthening security operations through incident response, detection engineering, and automation across cloud and endpoint environments with an accent on SIEM/XDR/EDR tooling, scripting, and security compliance. Focus on investigating incidents, developing detection rules and playbooks, hardening Windows, macOS, and Linux systems, and maintaining alignment with ISO 27001, SOC 2, and DORA.
Location: Romania; remote
Company
develops innovative software solutions and platforms for banking and insurance processes, helping financial services organizations improve speed, scalability, and cost-efficiency through digital business innovation and cloud technology.
What you will do
- Investigate and respond to security incidents through the incident response function.
- Automate incident response and defense center activities using playbooks, automation rules, and scripts.
- Develop and tune detection rules to improve coverage and true-positive rates.
- Collaborate with IT on laptop and server hardening configurations.
- Partner with Privacy on notifications related to data disclosures.
- Maintain compliance with ISO 27001, SOC 2, DORA, and other relevant frameworks.
Requirements
- At least 3 years of experience in defense engineering or incident response.
- Hands-on experience configuring detection mechanisms and using SIEM, XDR, or EDR platforms such as Microsoft Sentinel and Defender.
- Strong knowledge of cloud environments, attacker methodologies, TTPs, and attack paths across Windows, macOS, and Linux.
- Proficiency in scripting and KQL or similar query languages.
- Working knowledge of security tooling APIs, including Microsoft Graph, Defender, or Purview.
- Proficient English, written and verbal.
Nice to have
- Knowledge of Azure.
Culture & Benefits
- Flexible remote work setting that supports creativity and new ideas.
- Collaboration within a diverse, globally connected team.
- Career development and advancement opportunities based on performance.
- Competitive compensation package.
- Startup-style agility combined with the expertise and market presence of an established organization.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β
ΠΠΎΡ ΠΎΠΆΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
14 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Senior DevSecOps Engineer (Infrastructure & Cloud Security)
4 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Lead/Senior Security Engineer (Incident Response)
136Β 500 - 214Β 500$
13 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Security Operations Analyst (Cybersecurity)
110Β 000 - 140Β 000AUD
14 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Security Operations Analyst (Hybrid)
NDA
10 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄