Senior Security Engineer, Cloud Security & Vulnerability Management
Sofia, Bulgaria
Crypto.com
Over 140 million users buy, sell, and trade Bitcoin, Ethereum, NFTs and more on Crypto.com. Join the World's leading crypto trading platform.
We are looking for an intermediate level security specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI driven security automation workflows and contributing to security operations and vulnerability management.
We are building a modern, multi-cloud, intelligence driven security operations capability that will heavily involve AI and automation; and will require engineering and operational skills at all levels.
We are building a modern, multi-cloud, intelligence driven security operations capability that will heavily involve AI and automation; and will require engineering and operational skills at all levels.
Responsibilities
- Cloud & Container Security - Develop, deploy and maintain advanced cloud security controls to enable the prevention, detection and response to security threats in cloud and container environments. Configure and deploy cloud-native security controls (eg. AWS GuardDuty, Google SCC, Azure Security Centre, CSPM/KSPM, CNAPP solutions etc.)
- Cloud Investigation and incident response - Proficient in end-to-end Incident Response. Able to take the lead and provide guidance during investigations and incidents to pivot the investigation, drive containment, mitigation and other security outcomes. Proficient in performing investigations using open source and proprietary tools, including but not limited to - EPP/EDR/XDR software, Digital Forensics tools/software, SIEM platforms
- Configuration Management - Design, develop, and maintain Ansible playbooks for automating server configuration hardening in alignment with various compliance frameworks (e.g., CIS, PCI-DSS, NIST).
- Cloud Vulnerability Management - Configure, execute and maintain regular vulnerability scans on cloud environments using industry standard tools. Analyze scan results to assess the severity of the vulnerabilities, leveraging industry best practices and frameworks (eg. CVSS, etc); and prioritise remediation based on risk and business impact.
- Security Projects - Lead projects and initiatives that may involve - Cloud Security Posture Management (CSPM), Container Security, Native Cloud Security Enhancements (AWS, Azure, GCP), Runtime Vulnerability Management, Threat Hunting, Network/Endpoint/Cloud security reviews, etc.
- Leadership - Be comfortable with cross-functional leadership and stakeholder management. Be willing to lead and nurture a small team of junior security specialists.
- 5-7 years of experience in Information Security, with technical hands-on experience in Security Operations, Security Engineering, Digital Forensics, Incident Response, Endpoint Security or Cloud Security.
- Working Experience with SIEM, EPP/EDR/XDR, SOAR, Cloud Security (CSPM, Container Security, etc), Digital Forensics software & tools.
- Deep expertise in Cloud environments like AWS, Azure and GCP.
- Experience in Amazon EKS and Azure AKS for deploying, managing, and securing container orchestration platforms.
- Experience in applying AI/ML in cybersecurity use cases.
- Experience in using scripting languages to automate tasks and manipulate data or programming experience.
- Highly self-motivated, attention to detail and outcome driven.
- Proficiency in verbal and written English.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
3
0
0
Categories:
CloudSec Jobs
Security Engineering Jobs
Tags: Ansible Automation AWS Azure Cloud CNAPP Compliance CSPM CVSS EDR Endpoint security Forensics GCP Incident response NIST Open Source Scripting SIEM SOAR Vulnerabilities Vulnerability management Vulnerability scans XDR
Region:
Europe
Country:
Bulgaria
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Systems Administrator jobsIT Security Analyst jobsSenior Security Analyst jobsSenior Cybersecurity Engineer jobsSecurity Operations Engineer jobsSenior Cloud Security Engineer jobsCyber Security Specialist jobsSenior Information Security Analyst jobsInformation Security Manager jobsSenior Product Security Engineer jobsSenior Network Security Engineer jobsSecurity Consultant jobsChief Information Security Officer jobsSenior Information Security Engineer jobsInformation System Security Officer (ISSO) jobsSecurity Specialist jobsInformation Systems Security Engineer jobsSenior Cyber Security Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Software Engineer jobsSecurity Operations Analyst jobsSoftware Engineer jobsCybersecurity Specialist jobsNetwork Engineer jobs
Security assessment jobsGDPR jobsTS/SCI jobsEDR jobsEncryption jobsSDLC jobsThreat detection jobsSplunk jobsTerraform jobsMalware jobsRMF jobsSQL jobsIDS jobsFinance jobsITIL jobsCompTIA jobsTop Secret jobsIPS jobsSOC 2 jobsForensics jobsDocker jobsOWASP jobsActive Directory jobsClearance Required jobsGIAC jobs
CRISC jobsIntrusion detection jobsOSCP jobsTCP/IP jobsMITRE ATT&CK jobsDoDD 8570 jobsAnsible jobsHIPAA jobsVPN jobsZero Trust jobsData Analytics jobsJavaScript jobsSOAR jobsCCSP jobsIT infrastructure jobsJira jobsBanking jobsUNIX jobsSOX jobsDNS jobsIndustrial jobsNIST 800-53 jobsKPIs jobsCISO jobsSANS jobs