Information Security Engineer (Vulnerability Management and Operations)
Job Reference: 161812
Industry: Information and Communications Technology
Responsibilities:
- Self-starter with the flexibility to work remotely and support a global team, with the ability to track and lead multiple activities concurrently while maintaining a thorough focus on protecting customer data.
- Extensive experience in vulnerability management, including hands-on expertise with vulnerability scanning tools such as Tenable and Qualys, excellent knowledge of common security vulnerabilities, and the ability to assess their severity, business impact, and remediation requirements.
- Proven ability to independently analyze, communicate, support, and drive remediation of identified vulnerabilities, conduct proof-of-concept testing for known vulnerabilities, and continuously improve processes through automation and innovation.
- Good technical understanding of networking and security, including IPv4 and IPv6 networks, penetration testing methodologies, Linux administration, SQL, and engagement with the broader security research community.
- Excellent analytical and problem-solving skills, with demonstrated critical thinking abilities and experience solving complex logic and algorithmic challenges in support of enterprise security objectives.
Technical Skills
- Familiar with one or more of the following programming : Python, Go, Rust, and/or Bash scripting
- Working knowledge of container technologies (Docker, Kubernetes) and container image/registry vulnerability scanning(e.g. Twistlock/Prisma Cloud, Trivy)
- Working knowledge of cloud platforms (AWS, GCP, and/or Azure) and cloud security concepts (IAM, networksecurity groups, workload/posture management)
- DevSecOps experience or knowledge is good to have — integrating security scanning and gates into CI/CD pipelines,Infrastructure as Code (e.g. Terraform) security review, shift-left remediation practices.
AI & Automation
- Awareness of and interest in AI-driven security operations trends; hands-on experience with LLM tooling is a highly advantageus.
- Familiarity with the Model Context Protocol (MCP) and experience building or integrating MCP servers/tools
- Exposure to designing or developing AI agents (e.g. agentic workflows for vulnerability triage, enrichment, orremediation tracking) is a plus
EDUCATION & EXPERIENCE
- BS in Computer Science, Information Technology, Information Security, or related field
- 3 years experience in information security or related field
- Experience with container/cloud security and DevSecOps practices, and/or exposure to AI agent or MCP tooling, is aplus
