TL;DR
Junior Information Security Engineer: Supporting the implementation and maintenance of open-source security stacks and ingestion pipelines, with an accent on vulnerability management and log analysis. Focus on tuning detections, prioritizing vulnerabilities, and coordinating security tasks with engineering teams.
Location: Remote from Ukraine
Company
hirify.global is a custom product engineering company with over 4,000 skilled professionals, delivering impactful tech solutions for multinational organizations and scaling startups.
What you will do
- Support the implementation of open-source security tools (Wazuh, OpenSearch, Suricata, Zeek).
- Help set up ingestion pipelines from various sources (GCP, Vision One, Entra/M365, servers, network sensors).
- Assist in tuning security detections, Sigma rules, dashboards, and alert workflows.
- Perform CVE analysis, prioritize vulnerabilities, and manage remediation efforts.
- Run scans using vulnerability scanners like OpenVAS, Trivy, and OpenSCAP.
- Support automation tasks, ticket creation, and enrichment steps.
Requirements
- 3+ years experience in cybersecurity, cloud security, or SOC work.
- Familiarity with open-source security tools (Wazuh, Suricata, Zeek, OpenSearch).
- Good understanding of CVEs, CVSS, EPSS, and vulnerability management processes.
- Hands-on experience with GCP basics (IAM, Compute, VPC, Logging).
- Experience with EDR/XDR platforms (Trend Micro Vision One preferred).
- Able to interpret logs/alerts and summarise actionable information.
- English: Good communication skills required.
Nice to have
- Python/Bash scripting basics.
- Terraform basics.
- BigQuery familiarity.
- Knowledge of German.
Culture & Benefits
- Work in a strong community with top professionals in a friendly, open-door environment.
- Opportunity to work on large-scale projects with global impact.
- Access to tailored learning resources including internal events, Udemy, language courses, and company-paid certifications.
- Flexibility to work remotely or from an office.
- Company-paid medical insurance, mental health support, and financial & legal consultations.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →