Security Engineer
Job Overview
Needed Competencies Technical expertise integrating and tuning security scanners in CI/CD pipelines (Azure DevOps ideal): SAST, DAST, SCA, secrets, IaC. Technical expertise in DAST (OWASP ZAP or equivalent) and semantic SAST engines (Semgrep / CodeQL) on TypeScript / React / Node codebases. Technical expertise in SIEM detection engineering (Microsoft Sentinel and/or Wazuh / Elastic): writing detections, correlation, alert tuning, and playbooks. Technical expertise in Kubernetes / AKS security and runtime detection (Falco / Defender for Containers), network policies, and Pod Security Standards. Technical expertise in vulnerability management: aggregation / dedup, risk-based SLAs, and triage (DefectDojo or equivalent). Technical expertise in Azure security fundamentals: Defender for Cloud, Entra ID / RBAC, Key Vault, and edge WAF (OWASP ruleset). Solid grounding in OWASP Top 10, TLS / PKI, authentication protocols, and API security. Strong decision-making capabilities to weigh the relative costs and benefits of controls and prioritize risk-based remediation. Ability to produce clean, audit-ready evidence for SOC 2 and/or PCI DSS control requirements (supporting, not running, the audit). Builderu2019s mindset: OSS-first, iterating toward managed services. Clear communicator: able to translate risk for engineers and executives, with strong written English and documentation. Collaborative: drives secure-by-default practices through the DevOps and engineering teams rather than owning infrastructure directly. Education Bacheloru2019s on Computer Science, Information Technology, or a related field is recommended as a reasonable default, to be confirmed. Experience 4u20137 years in security engineering, DevSecOps, or application security, with hands-on experience building and tuning security controls. Comfortable partnering with DevOps / platform teams rather than owning infrastructure directly. Knowledge, Skills and Abilities Excellent written and spoken English; able to translate risk clearly for both engineers and executives. Experience preparing an organization for a first SOC 2 Type II or PCI DSS assessment (nice-to-have). Familiarity with GRC / continuous-compliance platforms (Vanta, Drata); policy-as-code (OPA / Conftest); threat modeling (nice-to-have). Preference for OSS-first security tooling with a managed Azure-native upgrade path. Effective listening and multi-tasking capabilities across concurrent security workstreams. Preferences Certified Kubernetes Security Specialist (CKS) Microsoft SC-200 Microsoft AZ-500 OSCP CEH PCI ISA / PCIP CISSP / CISM Travel Up to 15% Work Schedule Mondayu2013Friday, 10:00 AM u2013 7:00 PM (or as agreed). Hybrid work model, demand-based.
Desired Candidate Profile
Technical expertise integrating and tuning security scanners in CI/CD pipelines (Azure DevOps ideal): SAST, DAST, SCA, secrets, IaC. Technical expertise in DAST (OWASP ZAP or equivalent) and semantic SAST engines (Semgrep / CodeQL) on TypeScript / React / Node codebases. Technical expertise in SIEM detection engineering (Microsoft Sentinel and/or Wazuh / Elastic): writing detections, correlation, alert tuning, and playbooks. Technical expertise in Kubernetes / AKS security and runtime detection (Falco / Defender for Containers), network policies, and Pod Security Standards. Technical expertise in vulnerability management: aggregation / dedup, risk-based SLAs, and triage (DefectDojo or equivalent). Technical expertise in Azure security fundamentals: Defender for Cloud, Entra ID / RBAC, Key Vault, and edge WAF (OWASP ruleset). Solid grounding in OWASP Top 10, TLS / PKI, authentication protocols, and API security. Strong decision-making capabilities to weigh the relative costs and benefits of controls and prioritize risk-based remediation. Ability to produce clean, audit-ready evidence for SOC 2 and/or PCI DSS control requirements (supporting, not running, the audit). Builderu2019s mindset: OSS-first, iterating toward managed services. Clear communicator: able to translate risk for engineers and executives, with strong written English and documentation. Collaborative: drives secure-by-default practices through the DevOps and engineering teams rather than owning infrastructure directly. Education Bacheloru2019s on Computer Science, Information Technology, or a related field is recommended as a reasonable default, to be confirmed. Experience 4u20137 years in security engineering, DevSecOps, or application security, with hands-on experience building and tuning security controls. Comfortable partnering with DevOps / platform teams rather than owning infrastructure directly. Knowledge, Skills and Abilities Excellent written and spoken English; able to translate risk clearly for both engineers and executives. Experience preparing an organization for a first SOC 2 Type II or PCI DSS assessment (nice-to-have). Familiarity with GRC / continuous-compliance platforms (Vanta, Drata); policy-as-code (OPA / Conftest); threat modeling (nice-to-have). Preference for OSS-first security tooling with a managed Azure-native upgrade path. Effective listening and multi-tasking capabilities across concurrent security workstreams. Preferences Certified Kubernetes Security Specialist (CKS) Microsoft SC-200 Microsoft AZ-500 OSCP CEH PCI ISA / PCIP CISSP / CISM
Ready to apply?
You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.
Apply NowOpens the employer's site in a new tab
- CompanyAvertra
- LocationJordan
- CategoryFull Stack
- SourceNaukrigulf
- Listed2 months ago
Related Full Stack jobs
Android Developer
Develop, maintain, and enhance native Android SDKs using Kotlin. Implement Android components, libraries, and API integrations. Integrate SDKs with payment…
Senior iOS Developer
Design, develop, maintain, and enhance native iOS SDKs using Swift. Design and implement scalable iOS architectures and technical solutions. Develop reusable…
PHP Developer
What You ll Be Doing Maintain, troubleshoot, and enhance production applications built on PHP 7.x within a fully governed environment Own MySQL database health…
Senior Software Developer
Design and ship features end to end across our Node.js services and React front ends, from data model to deployed and monitored. Write specifications precise…