Virtuozzo

Security Engineer, Middle

Middle · Удалённо · Английский B2

Не указано: география

Навыки

  • Active Directory
  • Bash / shell
  • Bitbucket
  • CI/CD
  • EDR / антивирус
  • IAM / IDM
  • IDS / IPS
Ещё 17
  • Jenkins
  • Linux
  • macOS
  • OAuth / OIDC
  • OWASP
  • PowerShell
  • Python
  • Маршрутизация и NAT
  • SAST / DAST
  • SIEM
  • SOC
  • SOLID и паттерны
  • SonarQube
  • Splunk / ArcSight / QRadar
  • TCP/IP
  • Управление уязвимостями
  • Windows

О компании и продукте

  • Virtuozzo is a leader in infrastructure software and services for AI and the cloud. The company offers a next-generation OS, orchestration, management, automation, and protection for cloud service providers, SaaS, AI, and the enterprise. Virtuozzo provides mainframe-like efficiency, reliability, and versatility while dramatically lowering cost and complexity.
  • We are seeking a mid-level Security Engineer to help protect Virtuozzo’s networks, systems, and data from cyber threats. You will work with global Virtuozzo team members, physical infrastructure, and SaaS systems. You will also play a hands-on role in our ISO/IEC 27001 certification program by operating security controls and producing evidence that demonstrates they are working effectively. You will join an existing team, adding capacity to help us continue supporting the needs of our growing global organization.

Задачи

  • Operate and improve vulnerability management by running and tuning scans, triaging findings, tracking remediation with system owners, and maintaining scan evidence
  • Monitor security systems and logs, including SIEM and EDR platforms, to detect, investigate, and respond to security incidents
  • Maintain and configure security tooling, including EDR, SIEM, firewalls, intrusion detection and prevention systems, and MFA and SSO policies
  • Support identity and access management, including access provisioning, privileged access, and documented periodic access reviews
  • Contribute to ISO/IEC 27001 operations, including control implementation, evidence collection, risk register input, and support for internal and external audits
  • Assist with security assessments, penetration-test coordination, and remediation follow-up
  • Support application security across the software development lifecycle by integrating and operating SAST, DAST, dependency scanning, and container scanning within CI/CD pipelines
  • Triage application-security findings with R&D teams and track remediation
  • Help secure the build and release chain, including source-repository access, secrets management, artifact signing, and pipeline hardening
  • Help maintain security policies, procedures, and standards, and track exceptions
  • Track endpoint fleet security posture across Windows, macOS, and Linux, including MDM enrollment, EDR coverage, and disk encryption
  • Participate in security-awareness training and educate end users on security best practices
  • Troubleshoot security-related outages and incidents, producing root-cause or post-incident documentation where required
  • Work with the wider IT and Security team to build, document, and implement internal processes and workflows
  • Stay up to date with the latest security threats, trends, and technologies
  • Security Engineer
  • Mid-level
  • Type of work: Remote
  • Open for candidates contracting from Serbia, Bulgaria, Georgia, Armenia, Romania

Требования

  • At least three years of experience in security engineering, security operations, or systems administration with a strong security focus
  • Working knowledge of security concepts and tooling, including firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanners
  • Solid networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewalling, ideally with hands-on experience
  • Experience with identity and access management, including Active Directory or Microsoft Entra ID and SSO/MFA platforms such as Okta or similar
  • Working experience with Microsoft 365 and Exchange Online
  • Comfortable working with Windows, macOS, and Linux systems
  • Understanding of application-security fundamentals, including the OWASP Top 10, secure-coding practices, and vulnerability triage in code and dependencies
  • Understanding of security and compliance frameworks such as ISO/IEC 27001, SOC 2, or similar, including what constitutes suitable audit evidence
  • Strong problem-solving skills and attention to detail
  • Ability to work collaboratively within a team
  • Strong written and verbal communication skills in English
  • The Following Would Be an Advantage
  • Security certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or similar
  • Experience with Qualys, Greenbone/OpenVAS, Wazuh, Splunk, or similar tools
  • Experience with MDM tools such as Hexnode or similar, as well as endpoint hardening
  • Security automation experience using Python, Bash, or PowerShell
  • Hands-on experience with application-security tools such as SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, or similar
  • Experience with CI/CD security using Bitbucket Pipelines, Jenkins, or similar tools
  • Experience with secure-SDLC practices, including threat modelling, security code reviews, and secrets scanning
  • Exposure to cloud and virtualization platforms and their security models
  • Previous participation in an ISO/IEC 27001 certification program or customer security audits

Условия

  • A role at the forefront of cloud technology with real impact and growth opportunities
  • A collaborative environment where your ideas are valued and shipped
  • Other perks and engagement opportunities
  • Referral bonuses
  • Certifications and learning opportunities in line with interest and role requirements

Паспорт вакансии

История публикации

Появилась в Вакандии26 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели сегодня
Среди похожихНет данных26 из 30 · похожих вакансий слишком мало для сравнения

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдMiddleвычитано из текста вакансии
Формат работыУдалённовычитано из текста вакансии
Географияне указана
Зарплатане указана

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки502 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки нет вовсе

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • bamboohrОсновная публикация · дата неизвестна

Работодатель

Virtuozzo

11 активных вакансий · вилка работодателя указана в 0%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеvirtuozzo.bamboohr.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же грейд

    GRS Recruitment

    Cybersecurity Engineer

    • Middle
    • Удалённо
    • Никосия, Кипр
    Подробнее