Information Security Engineer supporting EdgeUno’s cybersecurity initiatives. Responsible for governance, threat detection, vulnerability management, and compliance in a hybrid environment.
Responsibilities
Support maintenance and continuous improvement of the Information Security Management System (ISMS) aligned with ISO 27001:2022
Update and maintain policies, processes, and procedures to reflect evolving security controls and compliance requirements
Assist in risk assessments, control evaluations, and internal security reviews
Configure, maintain, and create use cases and playbooks in Wazuh SIEM and SOAR platforms for enhanced threat detection and automated incident response
Conduct vulnerability management for infrastructure and applications using tools such as Nessus, Snyk, and Fortinet
Participate in incident response activities, including investigation, containment, remediation, and reporting
Support continuous monitoring and alerting through SOC operations
Contribute to threat intelligence gathering, focusing on Indicators of Compromise (IoCs) by geography and industry
Monitor and manage IP reputation and malicious domain blocking in line with regulatory and compliance requirements
Support periodic IAM reviews, user cleanup, and recertification processes to enforce least privilege and proper access control
Collaborate with IT to ensure consistent enforcement of IAM policies and account lifecycle management
Help execute and evaluate phishing and ransomware simulations using Smartfense and others
Assist in external security audits with providers and clients, supplying evidence and documentation as required
Support internal control testing, on-demand audits, and penetration testing for platforms, processes, and third parties
Participate in security reviews for information exchange with vendors and partners
Support the implementation, deployment, and management of Data Loss Prevention (DLP) tools and processes, including data classification and monitoring
Maintain and optimize Defender, Fortinet, and Linux-based security tools
Use Wireshark and Zabbix for traffic analysis, anomaly detection, and network performance monitoring
Requirements
Bachelor’s degree in Information Security, Computer Science, Engineering, or related field
3+ years of hands-on experience in information security, SOC, or cyber defense operations
Practical knowledge of ISO 27001, NIST CSF, MITRE ATT&CK, and CIS Controls
Experience with SIEM, SOAR, Vulnerability Management, DLP, and IAM tools
Familiarity with incident response, network monitoring, and threat intelligence workflows
Strong command of Linux administration and security hardening
Understanding of DevSecOps, automation, and scripting (Python, Bash preferred)
Excellent communication and documentation skills in English (Spanish and/or Portuguese highly desirable).
Junior Security Incident Responder in an innovative IT service company protecting clients against cyber threats. Collaborating with teams to enhance IT security and respond to incidents.
Security Incident Responder managing IT security incidents in the Security Operations Center, analyzing threats and coordinating responses effectively for clients' safety.
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.
Werkstudent Cyber Security bei Wavestone, Unterstützung im IT - Consulting und Entwicklung im Bereich Cyber - Sicherheit. Analyse von Trends und aktive Teilnahme an Teamaktivitäten.
Project Manager for Security Technology managing complex security projects in MENA region. Involving internal teams and external integrators ensuring project success and client satisfaction.
Cyber Security Manager at British American Tobacco strengthening cyber resilience across Western Europe. Responsible for managing security initiatives and collaborating with regional teams.
Stagiaire responsable de l’accompagnement à la mise en place d’un système SSE pour un bureau d’études en ingénierie. Impliqué dans la structuration, suivi et déploiement de systèmes SSE.
Graduate Cyber Technician contributing to Babcock Australasia's Defence Industry initiative. Join the 2027 Graduate Program and engage in personal and professional development.
Engineering Intern involved in real work and active projects at Babcock Australasia. Collaborating with experienced professionals to gain real - life experience in a supportive environment.
Senior Security Engineer establishing and maintaining cybersecurity measures for a financial services company. Responsible for leading security event responses, documentation of policies, and training.