i
Zyoin
95 Zyoin Jobs
Senior Security Engineer - Vulnerability Management Tools (5-10 yrs)
Zyoin
posted 12hr ago
Flexible timing
Key skills for the job
Job Description :
Responsibilities :
- Work with team members to continuously improve coverage, and efficiency and deliver customer-facing and internal services.
- Participate in the full software development lifecycle.
- Build well-designed, testable, efficient, secure vulnerability and misconfiguration detection code in the following areas :
Classic Endpoint Vulnerability and Config Management :
- Host-based vulnerabilities (OVAL based).
- Network-based vulnerability tests (NVTs).
- Configuration Benchmark automations development (i. e. CIS).
Cloud Config and Posture Management :
- Dev of security policy in cloud service providers.
- Pipeline hardening checks and policy development.
- Assist operational teams in resolving unexpected results, receive feedback, and improve detection efficacy.
- Arctic Wolf offers a culture of sharing, so every team can share their work with the entire department during our team and SP-wide demos.
- Once a year they hold a department-wide Hackathon, teaming up across all R and D teams over four days to collaborate and build cool ideas outside the normal project scope.
Requirements :
- A minimum of 5+ years of experience with competency in at least one backend language (any of Go, Python, Java, or Javascript preferred).
- A full understanding/application of secure development practices.
- Security-minded practitioners experienced in operational or security engineering roles with an emphasis on vulnerability and misconfiguration detection tooling.
- Full understanding and use of DevOps methods and practices.
- Understanding and ability to work with test-driven development.
- Experience with AWS, Docker, Kubernetes, and IaC is an asset.
- Experience with 3rd Party Vulnerability Management tools (Qualys, Nessus, Rapid7 OpenVAS).
- Experience with Cloud-based configuration and Security Posture Management tools (Azure Security Centre, AWS Security Hub, Sonrai, Cloudsploit, Prisma Cloud).
- A background working with open-source vulnerability and pen-testing platforms such as Nmap, OpenVAS, Burp, or Metasploit.
- IT Deployment backgrounds in particular leveraging deployment automation tools such as Salt or Ansible.
Functional Areas: Software/Testing/Networking
Read full job descriptionPrepare for Senior Security Engineer roles with real interview advice
5-10 Yrs