Security Engineer (Blue Team)
Job Description
About the Role
- Manage, operate, and improve security technologies across endpoint, application, cloud, network, and on-premises environments.
- Manage SIEM log ingestion, including onboarding new log sources, parsing, normalization, troubleshooting, and maintaining reliable security telemetry.
- Manage and maintain endpoint security solutions, including Wazuh, EDR/XDR, endpoint policies, agent deployment, configuration, and operational troubleshooting.
- Manage and maintain Web Application Firewall (WAF) and related application security controls, including Cloudflare security configurations, WAF rules, access controls, and traffic protection policies.
- Implement and maintain security configurations across hybrid environments, including AWS, GCP, on-premises infrastructure, servers, endpoints, and network devices.
- Perform technical investigation and response to security incidents, including identifying affected assets, containing threats, blocking indicators, isolating endpoints, adjusting security controls, and supporting remediation.
- Develop, implement, and improve security monitoring and detection capabilities, including alert rules, detection use cases, and security automation.
- Perform security hardening, configuration reviews, and remediation of identified security gaps.
- Troubleshoot security tools, integrations, log pipelines, endpoint agents, and security control configurations.
- Collaborate with Infrastructure, Cloud, DevOps, IT Operations, and application teams to implement and maintain security controls.
- Support continuous improvement of Blue Team operational capabilities and security engineering practices.
About You
- Bachelor's degree in Information Technology, Computer Science, Cyber Security, or other relevant fields.
- Minimum 2 years of hands-on experience in Security Engineering, Security Operations, Blue Team, Infrastructure Security, or a related role.
- Hands-on experience managing SIEM platforms and security log ingestion, including onboarding, parsing, troubleshooting, and validating log sources.
- Hands-on experience managing endpoint security technologies, such as Wazuh, EDR/XDR, endpoint protection, or endpoint monitoring solutions.
- Hands-on experience managing or configuring Web Application Firewall (WAF) technologies. Experience with Cloudflare is preferred.
- Hands-on experience implementing or reviewing security configurations in AWS, GCP, and/or on-premises environments.
- Able to perform technical incident response, including investigation, containment, remediation, and implementation of preventive security controls.
- Able to investigate security events using logs, endpoint telemetry, network information, cloud audit logs, and other technical evidence.
- Able to translate security findings into technical actions, such as:
- isolating or containing compromised endpoints;
- blocking malicious IP addresses, domains, URLs, hashes, or other indicators;
- creating or modifying WAF and security rules;
- correcting insecure cloud or infrastructure configurations;
- troubleshooting missing or incomplete security logs;
- implementing hardening and remediation actions.
- Good understanding of Windows and Linux operating systems, including system processes, services, permissions, logs, and basic system administration.
- Good understanding of networking concepts, including TCP/IP, DNS, HTTP/HTTPS, firewalls, routing, VPN, and common network security controls.
- Good understanding of security controls related to authentication, authorization, access control, endpoint protection, network security, cloud security, and application security.
- Familiar with common attack techniques and adversary behavior, including the ability to map technical activity to frameworks such as MITRE ATT&CK.
- Able to perform basic scripting and automation using Python, PowerShell, Bash, or similar technologies.
- Comfortable working with APIs, command-line tools, configuration files, and security platform integrations.
- Strong technical troubleshooting and problem-solving skills.
- Able to work collaboratively with Infrastructure, Cloud, DevOps, IT Operations, and other technical teams during investigation and remediation.
Nice to Have
- Experience developing or tuning detection rules and security monitoring use cases.
- Experience building automation for security operations, incident response, or security configuration management.
- Experience with Infrastructure as Code or configuration management technologies.
- Familiarity with security hardening standards and frameworks such as CIS Benchmarks, NIST Cybersecurity Framework, MITRE ATT&CK, or ISO/IEC 27001.
- Experience performing basic digital forensic or malware investigation to support incident response.
- Security certifications such as:
- Certified Incident Handler Engineer (CIHE)
- EC-Council Certified Incident Handler (ECIH)
- Computer Hacking Forensic Investigator (CHFI)
- CompTIA CySA+
- or equivalent technical cyber security certifications.

