Descrição do trabalho
Job Title:
">
Protecting Digital Assets
">
About the Role:
">
As a Security Engineer, you will be responsible for safeguarding applications, infrastructure, and data from threats and vulnerabilities.
">
You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure systems remain resilient against cyber threats.
">
- Responsibilities:
- ">
- ">
- Develop and implement threat modeling to identify security risks across applications and infrastructure.">
- Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.">
- Define and enforce secure coding practices in collaboration with development teams.">
- Work with DevOps to integrate security into CI/CD pipelines and automate security testing.">
- Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.">
- Ensure compliance with security standards and regulations (e.g. ISO 27001, GDPR, SOC 2).">
- Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.">
- Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations.">
- Develop incident response plans, security documentation, and best practices.">
- Stay ahead of emerging threats, vulnerabilities, and security technologies.">
- ">
- Requirements:
- ">What We're Looking For:">
- ">
- Around 4+ years of experience in cybersecurity, application security, or security engineering.">
- Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.">
- Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.">
- Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.">
- Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.">
- Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.">
- Knowledge of encryption protocols, network security, and API security best practices.">
- Experience working with DevSecOps, integrating security into CI/CD pipelines.">
- Ability to analyze security logs, detect anomalies, and mitigate potential threats.">
- Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.">
- "],