04 ago
|
Everseen
|
Barcelona
04 ago
Everseen
Barcelona
The Role
As a Security Engineer with Everseen’s Security team, you will work closely with Infrastructure and Security teams, build, automate, and operate across a modern cloud, network, and on-premises stack. You'll take direct ownership of hardening our environments and improving detection coverage within a streamlined, collaborative culture.
No espere a enviar su solicitud después de leer esta descripción;
se espera un gran volumen de candidaturas para esta posibilidad.
What you’ll doCloud & Container Security
- Define and maintain security standards for various workloads (AKS, GKE) — covering RBAC, network policies, and admission controls
- Maintain and improve security posture across Azure (Entra ID, Sentinel, Defender for Cloud)
- Contribute to container image scanning and runtime security monitoring
- Support JFrog Artifactory operations including artifact security and access control
Infrastructure & Endpoint Security
- Apply and maintain CIS benchmark hardening across all environments company-wide.
- Manage patching across Linux systems, ensuring timely remediation and compliance.
- Support vulnerability management lifecycle: triage, prioritization, and remediation tracking
Detection, Monitoring & Response
- Maintain and improve Microsoft Sentinel log ingestion, analytics rules, and detection coverage.
- Investigate security alerts, triage incidents, and support SOC activities.
- Build and maintain correlation rules, workbooks, and SOAR playbooks.
DevSecOps & Automation
- Implement and maintain SAST, DAST, dependency scanning, and secrets detection in GitLab CI/CD.
- Automate security operations tasks using Bash and Ansible.
- Contribute to Infrastructure-as-Code security reviews (Terraform, Helm, Kubernetes manifests).
- Support shift-left security practices and developer security enablement.
Collaborating With
You will work closely with the Infrastructure and Security teams, operating seamlessly alongside network engineering, DevOps,
and development groups. Day-to-day, your collaboration will be highly technical working directly with engineering peers to harden our infrastructure and integrate security tooling into CI/CD pipelines.
Profile and SkillsMust-Have Experience
- 3+ years in a Security Engineer, DevSecOps, or equivalent hands‑on role.
- Solid Linux fundamentals: Comfortable navigating, troubleshooting and administering Linux environments strictly via the command line.
- Cloud Infrastructure: Practical experience with at least one major cloud platform (Azure or GCP is strongly preferred).
- Networking fundamentals: Understanding of TCP/IP, DNS, routing, firewall rule logic, and VPN concepts.
- Automation & IAC: Proficient in Bash for scripting, alongside hands‑on experience with configuration management and provisioning tools like Ansible and/or Terraform.
- Vulnerability Management & Cloud Security: Hands‑on experience with traditional and cloud‑native security tooling such as Tenable (including Tenable Cloud Security / Ermetic), Wazuh, Qualys, or equivalent platforms.
- Container Ecosystems: Hands‑on experience with Docker, Kubernetes, and container image scanning.
- Software Development Lifecycle: Experience with GitLab CI/CD pipeline security integration (SAST, DAST, secret detection).
Strong Differentiators & Nice-to-Haves
- Microsoft Sentinel administration (log ingestion, KQL query writing, analytics rules) or other SIEM administration experience.
- Azure certifications (e.G., AZ-500: Azure Security Engineer).
- RHEL subscription management, Insights, and patch automation with Ansible.
- Working knowledge of security frameworks in a live environment (ISO 27001, NIST, or CIS Benchmarks).
Ways of Working & Soft Skills
- Ownership mindset: You close the loop and solve problems;
you don't just flag issues. xhfqzwm
- Clear communication: You are comfortable coordinating asynchronously and possess business-fluent English for both written and verbal collaboration.
#J-18808-Ljbffr
📌 Security Engineer (Barcelona)
🏢 Everseen
📍 Barcelona