We are seeking a highly skilled Security Engineer to join our team and help safeguard our cloud products. The ideal candidate will have hands-on experience in vulnerability assessment, vulnerability scanning, Image scanning, CVE analysis, and Center for Internet Security (CIS) benchmark analysis.
Bachelor’s degree in cyber security, Computer Science, or a related field (or equivalent experience). 3+ years of professional experience in cyber security, specifically in vulnerability assessment and scanning. Strong experience with a broad range of vulnerability scanning tools, including Nessus, Tenable, Burp Suite, Nmap. Hands-on experience with container image scanning tools such as Trivy, Anchore. In-depth knowledge of CVE analysis and vulnerability management processes. Proficiency in scripting languages such as Python, Bash to automate tasks. In-depth knowledge of CIS benchmarks and their application in real-world environments. Experience with security information and event management (SIEM) tools. Excellent problem-solving skills and attention to detail. Strong communication and documentation skills. Key Responsibilities:Conduct regular vulnerability assessments to identify potential risks across systems, applications, and networks. Utilize a variety of vulnerability scanning tools (e.g., Nessus, Burp Suite, and Tenable) to discover, analyze, and prioritize security flaws. Perform detailed analysis and remediation based on CIS benchmarks and ensure compliance with industry standards. Implement and manage container image scanning solutions to identify and mitigate vulnerabilities in containerized environments using tools like Trivy, Anchore. Conduct CVE analysis to assess the impact of vulnerabilities on the organization's infrastructure and prioritize remediation efforts. Work closely with IT and DevOps teams to develop and implement strategies for patch management, system hardening, and secure software deployment. Develop and maintain scripts and automation tools for efficient vulnerability detection and mitigation. Provide recommendations and technical guidance for improving the organization's security posture. Stay updated on the latest security threats, vulnerabilities, and best practices. Preferred Qualifications: Hands-on experience with CI Tools and Piplines. Hands-on experience with cloud security tools and platforms (AWS, Azure, or GCP). Familiarity with container orchestration platforms like Kubernetes and their associated security controls. What do we offer? Limitless career development opportunities with global clients on cutting-edge technologies.Being part of a dynamic and collaborative team while fostering open communication and continuous learning.Flexible work hours.Access to LinkedIn and Udemy learning courses.Hybrid working mode.Private Health Insurance Coverage.