Security Engineer (Infrastructure) - Esk Agency

Hiring
Málaga, Spain
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Málaga, Spain

Tech stack

Microsoft Windows
ARM
Bash
CompTIA Security+
Computer Security
Disaster Recovery
Networking Hardware
Intrusion Detection Systems
Python
Linux Servers
Network Segmentation
Powershell
Ansible
Security Information and Event Management
Systems Integration
Software Vulnerability Management
Data Logging
System Availability
QRadar
Firewalls (Computer Science)
Information Technology
Patch Management
Fortinet
Hardware Infrastructure
CIS Benchmarks
Software Coding
Terraform
Splunk
Vulnerability Analysis

Job description

Your missionAs anInfrastructure Security Engineer, you will join our global information security team todesign, deploy, and maintain security controlsfor ourprivate cloud and on-premises infrastructure.Your role is critical in protecting ourservers, networks, and data centersfrom internal and external threats, ensuring operational resilience while enabling the organization to function securely.You will have full responsibility for theengineering, maintenance, and day-to-day operationsof security systems that protect ourdata and IT assets, with a focus onpractical, hands-on implementationand continuous improvement.What You Will DoDesign, Deployment, and Maintenance of Security Controls in a hybrid environmentEngineer, deploy, maintain and improvesecurity technologies, including:WAF ,IDS/IPS, andendpoint protection platforms(e.G., Crowd Strike, Cortex, Sentinel One).SIEM solutions(e.G., Splunk, QRadar, ELK) for log aggregation, correlation, and alerting.Vulnerability management platformsfor scanning, patching, and remediation.Automate routine security tasks (e.G., vulnerability scanning, patch management, configuration compliance) usingscripting (Python, Bash, Power Shell)andinfrastructure-as-code tools (Ansible, Terraform).Improve infrastructure fornew vulnerability scanning capabilities, ensuring comprehensive coverage of on-premises assets.Operational Security and Incident ResponseLead theoperational managementof security systems, ensuring high availability and rapid response tosecurity product malfunctions(e.G., WAF latency, SIEM failures).Act as theSecurity Subject Matter Expert (SME)in infrastructure projects, identifying security requirements, reviewing low-level designs, and shaping secure solutions.Also to provide support on all the different products and tools managed by the team for internal and external clients.Provideon-call supportexclusively for security product outages, including troubleshooting analysis and remediation for infrastructure-related issues.Security Posture ImprovementDrive thesecurity roadmapfor infrastructure, identifying gaps, proposing improvements, and implementing controls to mitigate llaborate with IT and operations teams to integrate security intochange management, support cycles, and disaster recovery planning.Deploy and configurenew security products(e.G., SOAR, HSM) from initial setup to knowledge transfer for theSecurity Operations team.Documentation and Knowledge SharingMaintaindetailed documentationfor security systems, policies, and procedures.Stay current withemerging threats and vulnerabilitiesrelevant to infrastructure and share knowledge within the team.What you'll bringMinimum 3 years of hands-on experienceinon-premises/hybrid infrastructure security, with a focus on:Design, deployment, and supportof security technologies: Firewalls (e.G., Palo Alto, Fortinet), IDS/IPS, EPP/EDR (e.G., Crowd Strike, Sentinel One), SIEM (e.G., Splunk, QRadar), and vulnerability management platforms.Hardening and securingWindows/Linux servers, network devices, and physical data centers.Automation and scriptingfor security operations (Python, Bash, Power Shell, Ansible, Terraform).Hybrid environment security : Applying security controls to infrastructure and integrating with private/public cloud services.Practical knowledgeof:Security controls : Network segmentation, access control, logging/monitoring, and incident response.Industry standards : NIST, MITRE, CIS benchmarks, ISO *****, and ITIL change management processes.Security appliance management : Configuration, troubleshooting, and lifecycle management of physical/virtual security appliances, Windows and Linux server administration.Required personal skillsTeam player : Reliable, collaborative, and supportive in a global team environment.Passion for learning : Committed to staying ahead ofsecurity threatsand evolving technologies.Self-organized : Ability to manage multiple tasks, prioritize effectively, and meet deadlines in a fast-paced nfidentiality : Strict adherence to handling sensitive company and personnel data.Strong communication : Excellent technical writing and verbal skills in English; ability to explain complex security concepts to non-technical stakeholders.Education/Certifications:Non-essential but an assetDegree in Computer Science, Cybersecurity, or related field (or equivalent experience).Security certifications: Comptia Security +, CCNA Cyber Ops, Vendor related certifications.

Requirements

Hybrid environment security : Applying security controls to infrastructure and integrating with private/public cloud services.Practical knowledgeof:Security controls : Network segmentation, access control, logging/monitoring, and incident response.Industry standards : NIST, MITRE, CIS benchmarks, ISO *****, and ITIL change management processes.Security appliance management : Configuration, troubleshooting, and lifecycle management of physical/virtual security appliances, Windows and Linux server administration.Required personal skillsTeam player : Reliable, collaborative, and supportive in a global team environment.Passion for learning : Committed to staying ahead ofsecurity threatsand evolving technologies.Self-organized : Ability to manage multiple tasks, prioritize effectively, and meet deadlines in a fast-paced nfidentiality : Strict adherence to handling sensitive company and personnel data.Strong communication : Excellent technical writing and verbal skills in English; ability to explain complex security concepts to non-technical stakeholders.Education/Certifications:Non-essential but an assetDegree in Computer Science, Cybersecurity, or related field (or equivalent experience). Security certifications: Comptia Security +, CCNA Cyber Ops, Vendor related certifications.

Apply for this position