Security Engineer
We are looking for a Middle SecOps Engineer to join our Security Operations team. The candidate will have hands-on experience in monitoring, detecting, and responding to security threats across multiple environments, including endpoints, networks, and cloud platforms.
This role requires strong practical knowledge of SIEM and EDR/XDR systems, data loss prevention technologies, and vulnerability management, combined with the ability to follow and improve incident response playbooks. The engineer will collaborate closely with SOC analysts, DevOps, and IT teams to ensure effective threat detection, containment, and remediation.
Responsibilities:
-
Monitor security alerts from different systems, triage and investigate potential threats.
-
Perform end-to-end incident response: detection, analysis, containment, eradication, and recovery.
-
Identify false positives, escalate real threats, and provide actionable remediation guidance.
-
Analyze logs from multiple systems (OS, applications, network, cloud) to support investigations.
-
Collaborate with DevOps, IT, and development teams to remediate vulnerabilities and misconfigurations.
-
Participate in vulnerability management activities: scanning, prioritization, coordination with relevant teams.
-
Follow and contribute to improvement of SOC playbooks and standard operating procedures.
-
Provide documentation and reporting for incidents, investigations, and security events.
-
Stay updated on emerging threats, vulnerabilities, and security technologies.
Requirements:
-
Experience working with SIEM platforms: writing and tuning detection rules, log ingestion, and investigation workflows.
-
Experience working in a Security Operations Center (SOC) environment.
-
Strong experience with EDR/XDR solutions: alert triage, investigation, scoping, and remediation of incidents.
-
Experience with Data Loss Prevention (DLP) technologies and their operational use.
-
Practical experience in triaging security alerts, identifying false positives, escalating or resolving real threats.
-
Involvement in end-to-end incident response: detection, analysis, containment, eradication, and recovery.
-
Understanding of incident response processes and ability to follow or improve playbooks.
-
Experience with vulnerability management: scanning, prioritization, and coordination of remediation efforts.
-
Ability to read and analyze logs from various systems.
Nice to have:
-
Experience with cloud environments.
-
Knowledge of Kubernetes environment and containerized applications.
-
Familiarity with the fintech domain.
