DEVXED is a well-established product company with a proven track record in crafting user-centric e-commerce solutions. They have a team of over 80 passionate ...
Security System Engineer
Описание вакансии
компания "аксис кор тех"
we are looking for a security system engineer to join our team.
requirements
- minimum 5 years of experience in cybersecurity
- hands-on experience with edr solutions (sentinelone, crowdstrike, microsoft defender for endpoint, or similar)
- experience working with microsoft azure and microsoft entra id
- experience working with siem solutions (splunk, elk, microsoft sentinel, wazuh, or similar)
- experience working with waf, ids/ips, and network security solutions
- understanding of endpoint hardening principles and baseline configurations (cis benchmarks or similar)
- experience with patch management processes and compliance tracking
- hands-on experience in incident investigation
- understanding of incident response processes and basic forensic practices
- understanding of the modern threat landscape, including malware, phishing, privilege escalation, persistence techniques, lateral movement, and web-based attacks
- experience conducting risk assessments and security gap analysis
- experience developing, maintaining, or supporting information security policies and procedures
- administrative-level experience with windows and macos
- strong understanding of security best practices and defense-in-depth principles
will be a plus
- experience with mdm solutions (intune, jamf, manageengine, or similar)
- experience participating in threat hunting activities
- experience with devsecops practices and security integration within ci/cd pipelines
- experience with vulnerability management processes and remediation tracking
- experience with vulnerability scanning and security tooling integration
- basic scripting skills (python, bash, or powershell) for automation
- experience with vulnerability management processes and security tooling integration
- understanding of security standards and frameworks (iso 27001, pci dss, soc 2, cis controls)
- cybersecurity-related certifications
responsibilities
- ensure proper deployment and maintenance of security controls across the infrastructure
- manage and optimize edr, siem, waf, ids/ips, and endpoint security configurations
- monitor security events and ensure reliable telemetry collection across systems
- support endpoint hardening and secure baseline configurations
- participate in incident response activities and forensic investigations
- conduct threat hunting and proactive security analysis
- support vulnerability management and remediation tracking
- participate in risk assessments and security reviews
- develop and maintain information security policies, procedures, and security standards
- ensure security controls align with company requirements and industry standards
- participate in security audits and remediation activities
- work closely with it, devops, and engineering teams
- support continuous improvement of the company’s security posture
- participate in post-incident analysis and corrective action planning




