Information Security Engineer (Infrastructure & SecOps)
We are seeking a hands-on Information Security Engineer with a strong foundation in IT systems administration or network engineering. In this role, you will go far beyond monitoring dashboards and vendor alerts. You will analyze system and network architecture, identify underlying technical vulnerabilities, implement hardening controls across on-prem operating systems and network infrastructure, and build automated security workflows.
Infrastructure Hardening & Security Architecture
Audit and technically harden on-premises infrastructure (Windows Server, Linux, Active Directory, hypervisors, network appliances) based on CIS Benchmarks and industry best practices.
Design and implement architectural security controls, including network microsegmentation, tiered administrative models (Active Directory Tiering Model), Privileged Access Management (PAM), and secure configurations for reverse proxies and internal services.
SecOps, Incident Response & Threat Hunting
Analyze low-level security events: parse raw packet captures (pcap), trace system calls, and audit raw event telemetry across Windows Event Logs, Sysmon, and Linux auditd.
Onboard and normalize log sources, author custom detection logic, and fine-tune SIEM/EDR alerting rules beyond out-of-the-box templates.
Lead technical incident triage, conduct Root Cause Analysis (RCA), and isolate attack vectors to prevent recurrence.
Vulnerability & Attack Surface Management
Execute infrastructure vulnerability scans, manually validate findings to eliminate false positives, and build actionable technical remediation roadmaps with IT operations.
Maintain attack surface visibility and technical asset inventory.
Automation & Security Tooling
Automate recurring security tasks, configuration compliance checks, and log parsing using scripting languages (PowerShell, Python, Bash).
Administer, deploy, and maintain core enterprise security platforms, including PAM (Privileged Access Management), EDR, and DLP solutions.
Technical Compliance & Audits
Translate ISO/IEC 27001 requirements and corporate security policies into technical infrastructure controls.
Collect and generate technical audit evidence, configuration baselines, and verification reports.
Hands-on Infrastructure Background: 3+ years of direct experience in Systems Administration (Windows/Linux), Network Engineering, or SecOps / L2+ SOC engineering.
Deep Networking Knowledge: Strong understanding of the TCP/IP stack, DNS, DHCP, routing protocols, VLANs, TLS/SSL, and packet-level inspection tools (Wireshark, tcpdump).
Operating Systems & Identity Architecture: In-depth knowledge of Active Directory internals (Kerberos, NTLM, Group Policy Objects, DACLs/SACLs), authentication protocols, OS-level service hardening, and privilege separation.
Scripting & Automation: Proven ability to write scripts in PowerShell, Python, or Bash for system administration, log analysis, and API integrations.
Security Tooling & Log Analysis: Practical experience with vulnerability assessment tools (Nmap, Nessus/OpenVAS) and hands-on log analysis in SIEM/EDR environments.
Preferred Qualifications
Practical experience deploying or maintaining PAM platforms (e.g., JumpServer, CyberArk) and enterprise DLP systems.
Working knowledge of virtualization and container platforms (Hyper-V, VMware, Docker).