logo[мetahunt]
> Djinni

Security Engineer

format:Remote
tcp/ipnetworkinglinuxwindowsany one oflinuxfirewallszero trustsiemedrxdrany one ofedractive directorymicrosoft entra idcloud security
powershellpython
englishB1
domainCyberSec
> full description

The Role

The Security Engineer starts primarily in managed detection and response (MDR). On a normal day, the focus is detecting, investigating, and responding to security events. When project work requires additional engineering capacity, the engineer may be moved to support project work. When a significant cybersecurity incident occurs - whether for a client or internally - incident response becomes the priority and the broader security team participates as needed, regardless of normal schedules.

 

What You Will Do

  • Investigate security alerts and events and determine whether activity is benign, suspicious, or requires escalation.
  • Participate in detection and response operations, including guided containment and remediation decisions.
  • Analyze security issues and recommend remediation or configuration changes; early in the role, changes are performed under guidance rather than independently.
  • Work with logs and telemetry from endpoints, operating systems, networks, identity systems, cloud environments, and security platforms.
  • Participate in client and internal cybersecurity incidents as part of the incident response team.
  • Contribute to cybersecurity projects when assigned, learning the required technology as part of the project.
  • Analyze internal and client security environments and make practical security recommendations under guidance.
  • Grow into broader engineering responsibilities as your technical capability and interests develop.

 

Core Technical Foundation

We do not expect one person to know every security product. We care more about a strong technical foundation and the ability to understand how technologies fit together.

  • Strong understanding of TCP/IP and computer networking. Networking knowledge is fundamental to this role.
  • Intermediate knowledge of Windows and Linux administration and security, including how systems are secured and hardened without relying only on security tools.
  • Solid understanding of core cybersecurity concepts, threats, controls, detection, and response.
  • Working understanding of firewalls, network perimeter security, and modern security architecture concepts such as Zero Trust.
  • Ability to reason through unfamiliar technical problems and learn new technologies quickly.
  • Prior security operations, systems administration, network administration, or security engineering experience.
  • Experience with any SIEM, EDR/XDR, log collection, or security monitoring platform.
  • Active Directory, Microsoft Entra ID, identity management, or identity security experience.
  • Cloud infrastructure or cloud security experience.
  • Communication is in English – B1+ English level is required

 

Experience That Is a Plus

  • Scripting or automation experience, such as PowerShell, Python, or similar technologies.
  • Relevant technical certifications. Strong certifications in foundational technologies are valuable; we do not require a specific cybersecurity certification.

 

What Matters Most

  • Responsibility and ownership – you take ownership of assigned work, follow it through to completion, communicate when something is blocked or unclear, and make sure important issues do not fall through the cracks.
  • Curiosity - when something looks unusual, you want to understand why.
  • Creativity - you can think beyond a checklist when an investigation does not follow an obvious path.
  • Investigative mindset - you keep digging until the situation is understood and you are comfortable that the environment is secure.
  • Attention to detail - small technical details can change the meaning of a security event.
  • Learning ability - how quickly you comprehend new technologies and apply what you learn will directly influence how quickly you grow.
  • Initiative and engagement - you are interested in the technology and the problem, not simply completing a queue of assigned tasks.

 

Training and Career Growth

This is a growth-oriented position. The initial concentration is detection and response. From there, the career path is not predetermined. We want to develop each engineer around both capability and passion. Someone with strength in scripting and automation may grow in that direction; another engineer may become stronger in infrastructure, cloud, incident response, security engineering, projects, or client-facing work. With sufficient growth, the path can lead to senior engineering, project leadership, client management, and potentially virtual CISO responsibilities.

 

Working Model

  • Fully remote position.
  • Aligned with U.S. working core hours (9 am to 5 pm EST/EDT).
  • Detection and response is a 24x7 company function; over time, shifts may become more flexible based on team coverage and what works for the engineer.
  • Significant cybersecurity incidents are treated as team events and may require participation outside the normal schedule.
  • Client communication is not expected from day one; it can become part of the role as the engineer develops.
  • No travel requirement.