Virtuozzo logo
VirtuozzoPosted 2 weeks ago

Security Engineer, Middle

RemoteSerbia or Bulgaria

Full TimeMid LevelMedium

Job Summary

Operate vulnerability management by running scans, triaging findings, and tracking remediation with system owners. Monitor SIEM and EDR platforms to detect and respond to security incidents, while maintaining configurations for firewalls, intrusion detection systems, and MFA policies. Support ISO/IEC 27001 certification through control implementation, evidence collection, and audit support. Assist with security assessments, penetration-test coordination, and application security by integrating SAST, DAST, and container scanning within CI/CD pipelines. Troubleshoot outages, produce incident documentation, and educate end users on best practices. Join the global team to help secure the build and release chain, including secrets management and pipeline hardening.

Required Qualifications

  • At least three years of experience in security engineering, security operations, or systems administration with a strong security focus
  • Working knowledge of security concepts and tooling, including firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanners
  • Solid networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewalling, ideally with hands-on experience
  • Experience with identity and access management, including Active Directory or Microsoft Entra ID and SSO/MFA platforms such as Okta or similar
  • Working experience with Microsoft 365 and Exchange Online
  • Comfortable working with Windows, macOS, and Linux systems
  • Understanding of application-security fundamentals, including the OWASP Top 10, secure-coding practices, and vulnerability triage in code and dependencies
  • Understanding of security and compliance frameworks such as ISO/IEC 27001, SOC 2, or similar, including what constitutes suitable audit evidence
  • Strong problem-solving skills and attention to detail
  • Ability to work collaboratively within a team
  • Strong written and verbal communication skills in English

Desired Qualifications

  • Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or similar
  • Experience with Qualys, Greenbone/OpenVAS, Wazuh, Splunk, or similar tools
  • Experience with MDM tools such as Hexnode or similar, as well as endpoint hardening
  • Security automation experience using Python, Bash, or PowerShell
  • Hands-on experience with application-security tools such as SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, or similar
  • Experience with CI/CD security using Bitbucket Pipelines, Jenkins, or similar tools
  • Experience with secure-SDLC practices, including threat modelling, security code reviews, and secrets scanning
  • Exposure to cloud and virtualization platforms and their security models
  • Previous participation in an ISO/IEC 27001 certification program or customer security audits

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce