1. Home
  2. Jobs
  3. Avertra
  4. Security Engineer
FullStack

Security Engineer

Avertra
Jordan Listed 1h ago via Naukrigulf
react typescript kubernetes azure ci/cd devops soc siem owasp security

Job Description Roles & Responsibilities Requirements Needed Competencies Technical expertise integrating and tuning security scanners in CI/CD pipelines (Azure DevOps ideal): SAST, DAST, SCA, secrets, IaC. Technical expertise in DAST (OWASP ZAP or equivalent) and semantic SAST engines (Semgrep / CodeQL) on TypeScript / React / Node codebases. Technical expertise in SIEM detection engineering (Microsoft Sentinel and/or Wazuh / Elastic): writing detections, correlation, alert tuning, and playbooks. Technical expertise in Kubernetes / AKS security and runtime detection (Falco / Defender for Containers), network policies, and Pod Security Standards. Technical expertise in vulnerability management: aggregation / dedup, risk-based SLAs, and triage (DefectDojo or equivalent). Technical expertise in Azure security fundamentals: Defender for Cloud, Entra ID / RBAC, Key Vault, and edge WAF (OWASP ruleset). Solid grounding in OWASP Top 10, TLS / PKI, authentication protocols, and API security. Strong decision-making capabilities to weigh the relative costs and benefits of controls and prioritize risk-based remediation. Ability to produce clean, audit-ready evidence for SOC 2 and/or PCI DSS control requirements (supporting, not running, the audit). Builderu2019s mindset: OSS-first, iterating toward managed services. Clear communicator: able to translate risk for engineers and executives, with strong written English and documentation. Collaborative: drives secure-by-default practices through the DevOps and engineering teams rather than owning infrastructure directly. Education Bacheloru2019s on Computer Science, Information Technology, or a related field is recommended as a reasonable default, to be confirmed. Experience 4u20137 years in security engineering, DevSecOps, or application security, with hands-on experience building and tuning security controls. Comfortable partnering with DevOps / platform teams rather than owning infrastructure directly. Knowledge, Skills and Abilities Excellent written and spoken English; able to translate risk clearly for both engineers and executives. Experience preparing an organization for a first SOC 2 Type II or PCI DSS assessment (nice-to-have). Familiarity with GRC / continuous-compliance platforms (Vanta, Drata); policy-as-code (OPA / Conftest); threat modeling (nice-to-have). Preference for OSS-first security tooling with a managed Azure-native upgrade path. Effective listening and multi-tasking capabilities across concurrent security workstreams. Preferences Certified Kubernetes Security Specialist (CKS) Microsoft SC-200 Microsoft AZ-500 OSCP CEH PCI ISA / PCIP CISSP / CISM Travel Up to 15% Work Schedule Mondayu2013Friday, 10:00 AM u2013 7:00 PM (or as agreed). Hybrid work model, demand-based. Desired Candidate Profile Technical expertise integrating and tuning security scanners in CI/CD pipelines (Azure DevOps ideal): SAST, DAST, SCA, secrets, IaC. Technical expertise in DAST (OWASP ZAP or equivalent) and semantic SAST engines (Semgrep / CodeQL) on TypeScript / React / Node codebases. Technical expertise in SIEM detection engineering (Microsoft Sentinel and/or Wazuh / Elastic): writing detections, correlation, alert tuning, and playbooks. Technical expertise in Kubernetes / AKS security and runtime detection (Falco / Defender for Containers), network policies, and Pod Security Standards. Technical expertise in vulnerability management: aggregation / dedup, risk-based SLAs, and triage (DefectDojo or equivalent). Technical expertise in Azure security fundamentals: Defender for Cloud, Entra ID / RBAC, Key Vault, and edge WAF (OWASP ruleset). Solid grounding in OWASP Top 10, TLS / PKI, authentication protocols, and API security. Strong decision-making capabilities to weigh the relative costs and benefits of controls and prioritize risk-based remediation. Ability to produce clean, audit-ready evidence for SOC 2 and/or PCI DSS control requirements (supporting, not running, the audit). Builderu2019s mindset: OSS-first, iterating toward managed services. Clear communicator: able to translate risk for engineers and executives, with strong written English and documentation. Collaborative: drives secure-by-default practices through the DevOps and engineering teams rather than owning infrastructure directly. Education Bacheloru2019s on Computer Science, Information Technology, or a related field is recommended as a reasonable default, to be confirmed. Experience 4u20137 years in security engineering, DevSecOps, or application security, with hands-on experience building and tuning security controls. Comfortable partnering with DevOps / platform teams rather than owning infrastructure directly. Knowledge, Skills and Abilities Excellent written and spoken English; able to translate risk clearly for both engineers and executives. Experience preparing an organization for a first SOC 2 Type II or PCI DSS assessment (nice-to-have). Familiarity with GRC / continuous-compliance platforms (Vanta, Drata); policy-as-code (OPA / Conftest); threat modeling (nice-to-have). Preference for OSS-first security tooling with a managed Azure-native upgrade path. Effective listening and multi-tasking capabilities across concurrent security workstreams. Preferences Certified Kubernetes Security Specialist (CKS) Microsoft SC-200 Microsoft AZ-500 OSCP CEH PCI ISA / PCIP CISSP / CISM Company Industry IT - Software Services Department / Functional Area IT Software Keywords Security Engineer Get real-time job updates only on our App

Ready to apply?

You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.

Apply Now

Opens the employer's site in a new tab

  • CompanyAvertra
  • LocationJordan
  • CategoryFullStack
  • SourceNaukrigulf
  • Listed1h ago

Related FullStack jobs

More FullStack