logo[мetahunt]
> Djinni
middle

Security Engineer

RedCore
linuxnetwork securityawskubernetessiemvulnerability managementincident responsecloud security
openstackpythonbashci/cd
experience2+ years
> full description

RedCore is an international business group that creates technological solutions for digital markets. Our products and services cover fintech, marketing, e-commerce, customer service, communications, and regulatory technologies.


We are looking for a Middle SecOps Engineer!  

Requirements: 
- 2+ years of professional experience in Security Engineering, Infrastructure Security, Cloud Security, DevSecOps, or a related role.
- Strong understanding of infrastructure and network security principles, including network segmentation, firewalls, access control, TLS, secure network configuration, and service-to-service
communication.
- Practical experience with Linux systems security and hardening.
- Experience conducting security audits, configuration reviews, vulnerability assessments, or compliance assessments.
- Good understanding of CIS Benchmarks and security hardening principles.
- Experience with vulnerability management, including vulnerability validation, prioritization, remediation tracking, and risk-based decision making.
- Experience with security monitoring / SIEM / security analytics tools.
- Understanding of security incident response processes and basic incident investigation techniques.
- Understanding of patch management and operating system vulnerability remediation processes.
- Experience with cloud infrastructure security, preferably AWS.
- Understanding of Kubernetes security and container security principles.
- Ability to read and understand infrastructure configurations, logs, security findings, and network flows.
- Basic understanding of Infrastructure as Code and security implications of infrastructure changes.
- Good understanding of security controls and their practical implementation rather than purely theoretical knowledge.
- English sufficient for reading technical documentation and communicating with international teams. 

Will be a plus:
- Experience with OpenStack security.
- Experience automating security checks and operational processes using Python, Bash, or similar scripting languages.
- Experience integrating security controls into CI/CD pipelines. 

Responsibilities: 
- Infrastructure Security Monitoring — continuously monitor infrastructure for security events, anomalies, misconfigurations, and potential threats.
- Infrastructure Security Audits — plan and conduct regular security audits of infrastructure, cloud environments, operating systems, networks, and security controls.
- CIS Compliance & Hardening Assessment — assess infrastructure against CIS Benchmarks and internal security baselines, identify gaps, and drive remediation.
- Vulnerability Management — monitor infrastructure vulnerabilities, validate findings, prioritize remediation based on risk, and track remediation progress.
- Security Findings Triage & Escalation — triage findings from security tools, audits, and monitoring systems; validate their severity and escalate critical issues according to defined SLAs.
- Security Posture Management — continuously assess and improve the security posture of infrastructure and track security improvement initiatives.
- Security Standards & Baseline Compliance — ensure infrastructure complies with approved security standards, baselines, and security requirements.
- Security Control Validation — verify that implemented security controls are properly configured and effectively mitigate the intended risks. 
- Security Risk Identification & Reporting — identify infrastructure security risks, assess their potential impact, and provide clear reports and recommendations to stakeholders.
- Data Security — ensure appropriate infrastructure-level controls are implemented to protect sensitive and business-critical data.
- Patch Management Monitoring & Compliance — monitor patch management processes, identify overdue or missing security updates, and work with infrastructure teams to ensure
timely remediation.

Our benefits to you:

☘️An exciting and challenging job in a fast-growing business group, the opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance, and more

🤝🏻Great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset is guaranteed

🧑🏻‍💻Modern corporate equipment based on macOS or Windows and additional equipment are provided

🏖Paid vacations, sick leave, personal events days, days off

💵Referral program — enjoy cooperation with your colleagues and get the bonus

📚Educational programs: regular internal training sessions, compensation for external education, attendance of specialized global conferences

🎯Rewards program for mentoring and coaching colleagues

✈️In-house Travel Service

🦄Multiple internal activities: online platform for employees with quests, gamification, presents and news, clubs for movie / book / pets lovers and more

🎳Other benefits could be added based on your location