Vulnerability Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Vulnerability Security Engineer (Cybersecurity): Managing and optimizing the global vulnerability management ecosystem using Qualys, Twistlock, and Nuclei with an accent on exploitability analysis and data engineering. Focus on automating vulnerability pipelines via BigQuery and Splunk and providing technical remediation support to over 200 engineering teams.
Location: On-site presence required 4 days a week
Company
is a leader in the UCaaS segment providing cloud-based communications including PBX, call centers, video, and messaging services.
What you will do
- Own and maintain scanning infrastructure using Qualys, Twistlock, and Nuclei across thousands of micro-services.
- Perform manual exploitability analysis on critical vulnerabilities to prioritize remediation efforts.
- Develop and tune data pipelines using BigQuery, Splunk, and Looker to visualize vulnerability data.
- Provide technical guidance to developers and SREs to help them understand and resolve security Jira tickets.
- Participate in on-call rotations to ensure consistent security visibility and resolve scan failures.
- Create and maintain technical playbooks and documentation in both English and Russian.
Requirements
- 3+ years of experience in Cybersecurity.
- Hands-on experience configuring and troubleshooting Qualys and Twistlock/Prisma Cloud.
- Experience running and tuning Nuclei templates.
- Strong proficiency in Linux/Unix/Windows CLI, networking, and OS configuration.
- Ability to write SQL queries for BigQuery and use Splunk for log analysis.
- Must be able to work on-site 4 days a week.
Nice to have
- Experience in a leadership or program management role focused on Vulnerability Management.
- Proficiency in Python or Bash for automation tasks.
Culture & Benefits
- Additional Health and Life Insurance Package.
- Employee Assistance Program.
- 25 vacation days.
- Opportunities for professional and career growth within a dynamic project.
- Work with cutting-edge technologies in a well-coordinated professional team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →