Responsibilities: • Develop, tune, and automate detection and alerting pipelines; support incident response investigations and root-cause analysis;
• Lead endpoint and server hardening efforts across Windows, macOS, and Linux systems, ensuring secure configurations and continuous compliance ;
• Mature and maintain enterprise detection and response capabilities; drive toward 100% visibility and monitoring coverage across all assets;
• Oversee vulnerability management lifecycle — from scanning and triage to remediation tracking and executive reporting;
• Design and implement security automation to streamline access management, alert triage, and compliance evidence collection;
• Develop, enforce, and continuously refine Zero Trust Network Access (ZTNA) policies for both on-premises and cloud environments;
• Collaborate with engineering teams to support threat modeling, application security reviews, and secure-by-design architecture decisions.
Requirements: • 5+ years of experience in security engineering, cloud security, or incident response, ideally within a SaaS or cloud-native company operating at scale;
• Deep understanding of AWS security services (GuardDuty, IAM, KMS, CloudTrail, etc.) and best practices for securing multi-account environments;
• Hands-on experience with endpoint and server monitoring using CrowdStrike, including API integrations and telemetry enrichment across the monitoring stackExpertise designing, tuning, and maintaining SIEM and detection pipelines in Datadog, including custom metrics, dashboards, and automated alert workflows;
• Strong proficiency with Terraform, including secure IaC design, module development, and policy-as-code implementations;
• Familiarity with operational technology (OT) security, including segmentation, asset discovery, and threat detection in industrial or lab environments;
• Experience automating security operations using Python, PowerShell, or Bash for orchestration and response workflows;
• Strong understanding of vulnerability management, patch governance, and remediation prioritization strategies;
• Experience implementing Zero Trust Network Access (ZTNA) and securing hybrid cloud/on-prem environments.
⚡
Показать контакты
#Гибрид #ИБ
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Текст вакансии взят без изменений
Источник - Telegram канал. Название доступно после авторизации