Security Engineer (Infrastructure) - Esk Agency

Hiring
Málaga, Spain
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows ARM Architecture Bash Shell CompTIA Security+ Cyber Security Disaster Recovery Networking Hardware Intrusion Detection Systems Python (Programming Language) Linux Servers Network Segmentation Windows PowerShell
+17 more
Ansible Security Information and Event Management Systems Integration Software Vulnerability Management Data Logging System Availability QRadar Firewalls (Computer Science) Information Technology Patch Management Fortinet Hardware Infrastructure CIS Benchmarks Software Coding Terraform Splunk Vulnerability Analysis

Job description

Your missionAs anInfrastructure Security Engineer, you will join our global information security team todesign, deploy, and maintain security controlsfor ourprivate cloud and on-premises infrastructure.Your role is critical in protecting ourservers, networks, and data centersfrom internal and external threats, ensuring operational resilience while enabling the organization to function securely.You will have full responsibility for theengineering, maintenance, and day-to-day operationsof security systems that protect ourdata and IT assets, with a focus onpractical, hands-on implementationand continuous improvement.What You Will DoDesign, Deployment, and Maintenance of Security Controls in a hybrid environmentEngineer, deploy, maintain and improvesecurity technologies, including:WAF ,IDS/IPS, andendpoint protection platforms(e.G., Crowd Strike, Cortex, Sentinel One).SIEM solutions(e.G., Splunk, QRadar, ELK) for log aggregation, correlation, and alerting.Vulnerability management platformsfor scanning, patching, and remediation.Automate routine security tasks (e.G., vulnerability scanning, patch management, configuration compliance) usingscripting (Python, Bash, Power Shell)andinfrastructure-as-code tools (Ansible, Terraform).Improve infrastructure fornew vulnerability scanning capabilities, ensuring comprehensive coverage of on-premises assets.Operational Security and Incident ResponseLead theoperational managementof security systems, ensuring high availability and rapid response tosecurity product malfunctions(e.G., WAF latency, SIEM failures).Act as theSecurity Subject Matter Expert (SME)in infrastructure projects, identifying security requirements, reviewing low-level designs, and shaping secure solutions.Also to provide support on all the different products and tools managed by the team for internal and external clients.Provideon-call supportexclusively for security product outages, including troubleshooting analysis and remediation for infrastructure-related issues.Security Posture ImprovementDrive thesecurity roadmapfor infrastructure, identifying gaps, proposing improvements, and implementing controls to mitigate llaborate with IT and operations teams to integrate security intochange management, support cycles, and disaster recovery planning.Deploy and configurenew security products(e.G., SOAR, HSM) from initial setup to knowledge transfer for theSecurity Operations team.Documentation and Knowledge SharingMaintaindetailed documentationfor security systems, policies, and procedures.Stay current withemerging threats and vulnerabilitiesrelevant to infrastructure and share knowledge within the team.What you’ll bringMinimum 3 years of hands-on experienceinon-premises/hybrid infrastructure security, with a focus on:Design, deployment, and supportof security technologies: Firewalls (e.G., Palo Alto, Fortinet), IDS/IPS, EPP/EDR (e.G., Crowd Strike, Sentinel One), SIEM (e.G., Splunk, QRadar), and vulnerability management platforms.Hardening and securingWindows/Linux servers, network devices, and physical data centers.Automation and scriptingfor security operations (Python, Bash, Power Shell, Ansible, Terraform).Hybrid environment security : Applying security controls to infrastructure and integrating with private/public cloud services.Practical knowledgeof:Security controls : Network segmentation, access control, logging/monitoring, and incident response.Industry standards : NIST, MITRE, CIS benchmarks, ISO *****, and ITIL change management processes.Security appliance management : Configuration, troubleshooting, and lifecycle management of physical/virtual security appliances, Windows and Linux server administration.Required personal skillsTeam player : Reliable, collaborative, and supportive in a global team environment.Passion for learning : Committed to staying ahead ofsecurity threatsand evolving technologies.Self-organized : Ability to manage multiple tasks, prioritize effectively, and meet deadlines in a fast-paced nfidentiality : Strict adherence to handling sensitive company and personnel data.Strong communication : Excellent technical writing and verbal skills in English; ability to explain complex security concepts to non-technical stakeholders.Education/Certifications:Non-essential but an assetDegree in Computer Science, Cybersecurity, or related field (or equivalent experience).Security certifications: Comptia Security +, CCNA Cyber Ops, Vendor related certifications.

Requirements

Hybrid environment security : Applying security controls to infrastructure and integrating with private/public cloud services.Practical knowledgeof:Security controls : Network segmentation, access control, logging/monitoring, and incident response.Industry standards : NIST, MITRE, CIS benchmarks, ISO *****, and ITIL change management processes.Security appliance management : Configuration, troubleshooting, and lifecycle management of physical/virtual security appliances, Windows and Linux server administration.Required personal skillsTeam player : Reliable, collaborative, and supportive in a global team environment.Passion for learning : Committed to staying ahead ofsecurity threatsand evolving technologies.Self-organized : Ability to manage multiple tasks, prioritize effectively, and meet deadlines in a fast-paced nfidentiality : Strict adherence to handling sensitive company and personnel data.Strong communication : Excellent technical writing and verbal skills in English; ability to explain complex security concepts to non-technical stakeholders.Education/Certifications:Non-essential but an assetDegree in Computer Science, Cybersecurity, or related field (or equivalent experience). Security certifications: Comptia Security +, CCNA Cyber Ops, Vendor related certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all