Information Security Engineer
GLOBAL REMOTE
Sporty Group
In this role, you will Engineer, implement and monitor security measures for the protection of our computer systems, applications and infrastructure, such as, WAF, DDoS, DNS, Networking, VPN etc. We are looking for a capable team member who enjoys security work and possesses both deep and wide expertise in the security space.
Our Stack
Languages: Python, AWS LambdaNetworking: AWS Cloud, AWS Global Accelerator, PFSense, OpenWRTVPN: IPSec, L2TP, OpenVPN, Wireguard, ZerotierComputing & Storage: AWS EC2, AWS VPC, AWS EBS, S3Monitoring: AWS CloudwatchLogging: ELK, OpenSearchCDN: CloudFront, CloudflareWAF: AWS WAF, CloudflareDDoS Protection: AWS Shield, CloudflareTools: Kali Linux, MobSF, Frida, Metasploit, WireShark, BurpSuite, NMAP etc
Responsibilities
Work directly with the project teams to facilitate building secure workflows, processes, systems, and servicesDevelop best practices and security standards for the organisationUnderstand software, infrastructure and internet needs and adjust them according to the business environmentDevelop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasksEnsure the organisation knows as much as possible, as quickly as possible about security incidentsWrite comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancementFind cost-effective solutions to cybersecurity problemsConduct the internal/external security test/audit on our service, application, and infrastructureAssist fellow Team Members with cybersecurity, software, hardware or infrastructure needs
Requirements
3+ years' experience of working as a Security Engineer or other relevant positionBasic coding skills such as HTML, CSS, Shell Script, Python and other languagesIn-depth knowledge of database and operating system securityAbility to discover and identify SQLi, XSS, CSRF, SSRF, authentication and authorisation flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond)Knowledge of common authentication technologies including OAuth, SAML, CAs, OTP/TOTPKnowledge of browser-based security controls such as CSP, HSTS, XFOExperience with standard web application security tools (Arachni, BurpSuite)An understanding of best practices and how to implement them at a business-wide levelHands-on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filteringHands-on experience in network security and networking technologies and with system٫ security, and network monitoring toolsFluency in English written and spoken
Beneficial
CyberSecurity certifications such as CISSP, CISA/CISM, CompTIA Security+, CEH, or GSEC would be beneficial Certifications such as PMP, ISO 27001 LA would be beneficial Benefits
Quarterly bonusesWe have core hours of 10am-3pm in a local timezone, but flexible hours outside of thisTop-of-the-line equipmentReferral bonuses28 days paid annual leaveAnnual company retreatHighly talented, dependable co-workers in a global, multicultural organisationPayment via DEEL, a world class online wallet system Our teams are small enough for you to be impactfulOur business is globally established and successful, offering stability and security to our Team Members
Our Mission
Our mission is to be an everyday entertainment platform for everyone
Our Operating Principles
1. Create Value for Users2. Act in the Long-Term Interests of Sporty 3. Focus on Product Improvements & Innovation 4. Be Responsible 5. Preserve Integrity & Honesty 6. Respect Confidentiality & Privacy 7. Ensure Stability, Security & Scalability 8. Work Hard with Passion & Pride
Interview Process
Online HackerRank Test (Max time of 90 Minutes)Remote video screening with our Talent Acquisition Team Remote video interview with 3 x Team Members (45 mins each, not separate days)24-72 hour feedback loops throughout process
Post Interview Process
Feedback call on successful interviewOffer released followed by contractID Check Via Zinc & 2 references from previous employers
Working at Sporty
The top-down mentality at Sporty is high performance based, meaning we trust you to do your job with an emphasis on support to help you achieve, grow and de-block any issues when they're in your way.Generally employees can choose their own hours, as long as they are collaborating and doing stand-ups etc. The emphasis is really on results.
As we are a highly structured and established company we are able to offer the security and support of a global business with the allure of a startup environment. Sporty is independently managed and financed, meaning we don’t have arbitrary shareholder or VC targets to cater to.
We literally build, spend and make decisions based on the ethos of building THE best platform of its kind. We are truly a tech company to the core and take excellent care of our Team Members.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security AWS Burp Suite CEH CISA CISM CISSP Cloud CloudFront CompTIA CSRF DDoS DNS EC2 ELK Firewalls GSEC Intrusion detection ISO 27001 Kali Linux Metasploit Monitoring Network security Nmap OWASP pfSense Privacy Python SAML SQL injection SSRF VPN Vulnerabilities XSS
Perks/benefits: Career development Flex hours Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.