Senior Full Stack Security Engineer
Descrição da Vaga
You'll join a high\-octane security team tackling offensive and defensive challenges. Whether diving into intricate web application pentesting or running purple team simulations, you'll collaborate with detection engineers, craft internal tools, challenge assumptions, and execute threat scenarios to fortify SOC operations. **Key Responsibilities** DevSecOps * Operate as a SOC Tier 2 or Tier 3 engineer, swiftly triaging and resolving security incidents. * Configure and harden security systems (antivirus, firewalls, OS security) * Develop zero\-day mitigation strategies when patches are unavailable * Troubleshoot issues with tools like Antivirus, Qualys, or DNS filtering etc. * Build automation scripts for deploying agents, policy cleanup, or custom security scanners. Web Application Pentesting * Execute precise manual and automated tests on web apps and APIs. * Uncover OWASP Top 10 and elusive business logic vulnerabilities. * Deliver clear, actionable PoCs and remediation guidance. * Work closely with developers to guide secure coding and implement effective fixes. Purple Team / Detection Engineering * Participate in adversary simulations to test and enhance SOC defenses, conducted at least twice per quarter. * Fine\-tune detection rules across EDR and SIEM for maximum precision. * Design and run internal threat scenarios to stress\-test response capabilities. * Enhance defender workflows through close collaboration and visibility improvements. **Requirements** * Deep system administration skills in Windows and Linux, with a security\-first approach, adept at solving multi\-layered OS, network, and configuration issues. * Experience in incident response, threat hunting, or SOC Tier 2\+ roles * Proficiency with tools like Burp Suite, Nmap, SQLmap, or custom scripts * Strong scripting skills in Python, Bash, or PowerShell for automation. * Excellent written and verbal communication in English. * Experience with vulnerability management platforms like DefectDojo for tracking and prioritizing security findings is a plus. * A profile on platforms like Hack The Box, TryHackMe, or similar (please provide your profile link). * Fluent in English. **Bonus Points For** * Proven success in bug bounty programs with documented cases. * Experience in purple team operations or red\-blue collaboration. * Familiarity with C2 frameworks, payload development, or adversary emulation * Knowledge of cloud security (AWS, Azure, GCP). * Certifications like OSCP, OSWE, CRTO, or equivalent. **Benefits** **Salary Range:** $4500\-$6000 USD \+ Holidays **PTO:** Unlimited
Vaga originalmente publicada em: linkedin
Receba vagas como esta no seu email
Crie um alerta gratuito e seja o primeiro a saber de novas oportunidades
Alertas que entendem o que você quer
Não receba qualquer vaga. Receba apenas as que combinam exatamente com o que você busca.
Filtro:
Você recebe tudo isso:
Filtro:
Você recebe apenas:
Zero ruído. Só vagas relevantes para você.
Outros exemplos de filtros precisos:
Filtros Combinados
Combine linguagem + framework + nível + localização. Seja tão específico quanto quiser.
Email Diário
Receba um resumo diário apenas com vagas que passam nos seus filtros. Sem spam.
Kanban Visual
Organize suas candidaturas em um quadro Kanban. Acompanhe cada processo seletivo.
Planos simples, sem surpresas
Comece grátis e faça upgrade quando quiser
Premium
- Tudo do plano gratuito
- Vagas salvas ilimitadas
- Quadros Kanban ilimitados
- Alertas de vagas por email
- Suporte prioritário
Pronto para encontrar sua vaga ideal?
Junte-se a milhares de desenvolvedores que já usam o Job For Dev
Encontre as melhores oportunidades para desenvolvedores no Job For Dev