Security Engineer

Client of 6 Pence

نشرت في 23 فبراير

الخبرة

2 - 7 سنوات

موقع العمل

Manama - Bahrain

التعليم

بكالوريوس في العلوم(أجهزة الكمبيوتر)

الجنسية

أي جنسية

جنس

غير مذكور

عدد الشواغر

1 عدد الشواغر

الوصف الوظيفي

الأدوار والمسؤوليات

Role Overview:

  • We are looking for a skilled and proactive Security Engineer to design, implement, and maintain security systems and controls across our infrastructure, applications, and cloud environments.
  • You will work cross-functionally with engineering, DevOps, and compliance teams to embed security into every layer of the organization.

Duties & Responsibilities:

Application Security:

  • Perform secure code reviews and static/dynamic application security testing (SAST/DAST)
  • Integrate security testing into CI/CD pipelines (shift-left security)
  • Identify and remediate OWASP Top 10 vulnerabilities
  • Conduct threat modeling for new features and architectures
  • Work with developers to establish secure coding standards and guidelines

Cloud & Infrastructure Security:

  • Design and enforce security controls across AWS environments
  • Implement and monitor Cloud Security Posture Management (CSPM) using tools like Prowler, Wiz, or Prisma Cloud
  • Manage IAM policies, least privilege access, and role-based access control (RBAC)
  • Harden OS, container, and Kubernetes configurations
  • Perform vulnerability scanning of cloud workloads and container images (Trivy, Qualys etc.)

Detection & Response:

  • Build and tune detection rules in SIEM platforms (Splunk, Elastic, LogRhythm)
  • Investigate security alerts, triage incidents, and lead incident response activities
  • Conduct forensic analysis on endpoints, logs, and cloud resources
  • Develop and maintain incident response playbooks.

Network Security:

  • Design and maintain firewall rules, VPC security groups, and network segmentation
  • Monitor network traffic for anomalies and potential threats
  • Implement and manage VPN, zero trust network access (ZTNA), and WAF solutions

Vulnerability Management:

  • Run regular vulnerability assessments across infrastructure and applications
  • Prioritize and track remediation of findings in collaboration with engineering teams
  • Manage and report on the organization's attack surface
  • Coordinate penetration testing with internal red teams or external vendors

Security Automation & Tooling:

  • Build security automation scripts and tooling (Python, Bash, Go)
  • Integrate security tools into DevSecOps workflows
  • Manage security tool stack including EDR, SIEM, SOAR, secrets management (HashiCorp Vault, AWS Secrets Manager)
  • Develop dashboards and metrics for security visibility

Governance, Risk & Compliance (GRC) Support:

  • Support compliance audits (SOC 2, ISO 27001, PCI-DSS,)
  • Assist in developing and maintaining security policies and procedures
  • Contribute to risk assessments and security awareness programs

الملف الشخصي المطلوب للمرشحين

Qualifications, Experience & Skills

  • Bachelor's degree in Computer Science, Information Security, or related field
  • Minimum 2-3 years Experience

Technical Skills:

  • Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, TLS, firewalls)
  • Proficiency in at least one cloud platform AWS
  • Experience with container security Docker, Kubernetes, image scanning
  • Hands-on experience with SIEM platforms and log analysis
  • Scripting/automation skills Python, Bash, or similar
  • Familiarity with IaC security Terraform, CloudFormation, Helm
  • Knowledge of identity and access management (IAM, OAuth, SAML, OIDC)
  • Understanding of cryptography fundamentals and PKI

Security Tools Experience:

  • Vulnerability scanners Trivy, Qualys, Nessus, or Tenable
  • CSPM tools Prowler, Wiz, Prisma Cloud, or Security Hub
  • SIEM Splunk, Elastic Security, or Chronicle
  • EDR CrowdStrike, SentinelOne, or Carbon Black
  • Secrets management HashiCorp Vault, AWS Secrets Manager
  • Penetration testing tools Burp Suite, Metasploit, Nmap

Soft Skills:

  • Strong analytical and problem-solving mindset
  • Clear communication able to explain technical risks to non-technical stakeholders
  • Ability to work independently and collaboratively in a fast-paced environment
  • Detail-oriented with strong documentation habits

القطاع المهني للشركة

المجال الوظيفي / القسم

الكلمات الرئيسية

  • Security Engineer

تنويه: نوكري غلف هو مجرد منصة لجمع الباحثين عن عمل وأصحاب العمل معا. وينصح المتقدمون بالبحث في حسن نية صاحب العمل المحتمل بشكل مستقل. نحن لا نؤيد أي طلبات لدفع الأموال وننصح بشدة ضد تبادل المعلومات الشخصية أو المصرفية ذات الصلة. نوصي أيضا زيارة نصائح أمنية للمزيد من المعلومات. إذا كنت تشك في أي احتيال أو سوء تصرف ، راسلنا عبر البريد الإلكتروني abuse@naukrigulf.com

وظائف مماثلة

مهندس أمن المعلومات

SOC L1 أو SOC L2

أخصائي الأمن

Senior Cybersecurity Specialist

عرض الكل