Search Jobs

Search by job, company or skills

Security Engineer (Blue Team)

Security Engineer (Blue Team)

KROM
2-4 Years
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

About the Role

  • Manage, operate, and improve security technologies across endpoint, application, cloud, network, and on-premises environments.
  • Manage SIEM log ingestion, including onboarding new log sources, parsing, normalization, troubleshooting, and maintaining reliable security telemetry.
  • Manage and maintain endpoint security solutions, including Wazuh, EDR/XDR, endpoint policies, agent deployment, configuration, and operational troubleshooting.
  • Manage and maintain Web Application Firewall (WAF) and related application security controls, including Cloudflare security configurations, WAF rules, access controls, and traffic protection policies.
  • Implement and maintain security configurations across hybrid environments, including AWS, GCP, on-premises infrastructure, servers, endpoints, and network devices.
  • Perform technical investigation and response to security incidents, including identifying affected assets, containing threats, blocking indicators, isolating endpoints, adjusting security controls, and supporting remediation.
  • Develop, implement, and improve security monitoring and detection capabilities, including alert rules, detection use cases, and security automation.
  • Perform security hardening, configuration reviews, and remediation of identified security gaps.
  • Troubleshoot security tools, integrations, log pipelines, endpoint agents, and security control configurations.
  • Collaborate with Infrastructure, Cloud, DevOps, IT Operations, and application teams to implement and maintain security controls.
  • Support continuous improvement of Blue Team operational capabilities and security engineering practices.

About You

  • Bachelor's degree in Information Technology, Computer Science, Cyber Security, or other relevant fields.
  • Minimum 2 years of hands-on experience in Security Engineering, Security Operations, Blue Team, Infrastructure Security, or a related role.
  • Hands-on experience managing SIEM platforms and security log ingestion, including onboarding, parsing, troubleshooting, and validating log sources.
  • Hands-on experience managing endpoint security technologies, such as Wazuh, EDR/XDR, endpoint protection, or endpoint monitoring solutions.
  • Hands-on experience managing or configuring Web Application Firewall (WAF) technologies. Experience with Cloudflare is preferred.
  • Hands-on experience implementing or reviewing security configurations in AWS, GCP, and/or on-premises environments.
  • Able to perform technical incident response, including investigation, containment, remediation, and implementation of preventive security controls.
  • Able to investigate security events using logs, endpoint telemetry, network information, cloud audit logs, and other technical evidence.
  • Able to translate security findings into technical actions, such as:
  • isolating or containing compromised endpoints;
  • blocking malicious IP addresses, domains, URLs, hashes, or other indicators;
  • creating or modifying WAF and security rules;
  • correcting insecure cloud or infrastructure configurations;
  • troubleshooting missing or incomplete security logs;
  • implementing hardening and remediation actions.
  • Good understanding of Windows and Linux operating systems, including system processes, services, permissions, logs, and basic system administration.
  • Good understanding of networking concepts, including TCP/IP, DNS, HTTP/HTTPS, firewalls, routing, VPN, and common network security controls.
  • Good understanding of security controls related to authentication, authorization, access control, endpoint protection, network security, cloud security, and application security.
  • Familiar with common attack techniques and adversary behavior, including the ability to map technical activity to frameworks such as MITRE ATT&CK.
  • Able to perform basic scripting and automation using Python, PowerShell, Bash, or similar technologies.
  • Comfortable working with APIs, command-line tools, configuration files, and security platform integrations.
  • Strong technical troubleshooting and problem-solving skills.
  • Able to work collaboratively with Infrastructure, Cloud, DevOps, IT Operations, and other technical teams during investigation and remediation.

Nice to Have

  • Experience developing or tuning detection rules and security monitoring use cases.
  • Experience building automation for security operations, incident response, or security configuration management.
  • Experience with Infrastructure as Code or configuration management technologies.
  • Familiarity with security hardening standards and frameworks such as CIS Benchmarks, NIST Cybersecurity Framework, MITRE ATT&CK, or ISO/IEC 27001.
  • Experience performing basic digital forensic or malware investigation to support incident response.
  • Security certifications such as:
  • Certified Incident Handler Engineer (CIHE)
  • EC-Council Certified Incident Handler (ECIH)
  • Computer Hacking Forensic Investigator (CHFI)
  • CompTIA CySA+
  • or equivalent technical cyber security certifications.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

SIEM log ingestion

Wazuh EDR XDR

About Company

Similar Jobs

5-7 yrs
Indonesia
Skills:
Bash, Firewall Management, Restful Apis, Python, Go, Security automation workflows, Vulnerability assessment methodologies, Adversary simulation exercises, Enterprise-grade perimeter security technologies, Threat emulation frameworks, Exploitation techniques, Security testing tools, Cloudflare, Attack simulation methodologies