28 sep
|
Everseen
|
Barcelona
28 sep
Everseen
Barcelona
The Role As a Security Engineer with Everseen’s Security team, you will work closely with Infrastructure and Security teams, build, automate, and operate across a modern cloud, network, and on-premises stack. You'll take direct ownership of hardening our environments and improving detection coverage within a streamlined, collaborative culture. What you’ll do Cloud & Container Security Define and maintain security standards for various workloads (AKS, GKE) — covering RBAC, network policies, and admission controls Maintain and improve security posture across Azure (Entra ID, Sentinel, Defender for Cloud) Contribute to container image scanning and runtime security monitoring Support JFrog Artifactory operations including artifact security and access control Infrastructure & Endpoint Security Apply and maintain CIS benchmark hardening across all environments company-wide. Manage patching across Linux systems, ensuring timely remediation and compliance. Support vulnerability management lifecycle: triage, prioritization, and remediation tracking Detection, Monitoring & Response Maintain and improve Microsoft Sentinel log ingestion, analytics rules, and detection coverage. Investigate security alerts, triage incidents, and support SOC activities. Build and maintain correlation rules, workbooks, and SOAR playbooks. Dev Sec Ops & Automation Implement and maintain SAST, DAST, dependency scanning, and secrets detection in Git Lab CI/CD. Automate security operations tasks using Bash and Ansible. Contribute to Infrastructure-as-Code security reviews (Terraform, Helm, Kubernetes manifests). Support shift-left security practices and developer security enablement. Collaborating With You will work closely with the Infrastructure and Security teams, operating seamlessly alongside network engineering, Dev Ops, and development groups. Day-to-day,
your collaboration will be highly technical working directly with engineering peers to harden our infrastructure and integrate security tooling into CI/CD pipelines. Profile and Skills Must-Have Experience 3+ years in a Security Engineer, Dev Sec Ops, or equivalent hands‑on role. Solid Linux fundamentals: Comfortable navigating, troubleshooting and administering Linux environments strictly via the command line. Cloud Infrastructure: Practical experience with at least one major cloud platform (Azure or GCP is strongly preferred). Networking fundamentals: Understanding of TCP/IP, DNS, routing, firewall rule logic, and VPN concepts. Automation & IAC: Proficient in Bash for scripting, alongside hands‑on experience with configuration management and provisioning tools like Ansible and/or Terraform. Vulnerability Management & Cloud Security: Hands‑on experience with traditional and cloud‑native security tooling such as Tenable (including Tenable Cloud Security / Ermetic), Wazuh, Qualys, or equivalent platforms. Container Ecosystems: Hands‑on experience with Docker, Kubernetes, and container image scanning. Software Development Lifecycle: Experience with Git Lab CI/CD pipeline security integration (SAST, DAST, secret detection). Strong Differentiators & Nice-to-Haves Microsoft Sentinel administration (log ingestion, KQL query writing, analytics rules) or other SIEM administration experience. Azure certifications (e.G., AZ-500: Azure Security Engineer). RHEL subscription management, Insights, and patch automation with Ansible. Working knowledge of security frameworks in a live environment (ISO 27001, NIST, or CIS Benchmarks). Ways of Working & Soft Skills Ownership mindset: You close the loop and solve problems; you don't just flag issues. Clear communication: You are comfortable coordinating asynchronously and possess business-fluent English for both written and verbal collaboration. #J-18808-Ljbffr
📌 Security Engineer (Barcelona)
🏢 Everseen
📍 Barcelona