ВАКАНСИЯ
набор закрыт
обновлено 31 день назад
[Архив] Jun/Mid Information Security Engineer
НС
Название скрыто (Fintech)
Грейд
Middle
Направление
—
Опыт
1–3 years
Формат
Удалёнка
Город
—
Занятость
Полная
Стек
LinuxPythonBashGitRapid7NessusOpenVASQualys
О вакансии
We are a proprietary algorithmic trading firm. Our team handles the entire trading cycle — from software development to designing and implementing strategies and algorithms.
Our trading activity spans major exchanges. The firm operates across a wide spectrum of asset classes: equities, equity derivatives, options, commodity futures, rates futures, and others. We deploy a diverse and expanding set of algorithmic trading strategies, leveraging both high- and medium-frequency approaches.
Our team consists of 200+ specialists, with a heavy tilt toward technology — 70% are technical experts working in development, infrastructure, testing, and analytics. The rest of the team covers business functions such as Risks, Compliance, Legal, Operations, and more.
Driven by a commitment to innovation and performance, BHFT is actively growing its footprint in traditional financial markets. We foster a results-oriented culture built on collaboration, transparency, and continuous improvement, while providing the flexibility of remote work within a globally distributed team.
Job Description
We are seeking an Information Security Engineer to join our security team and take full ownership of two key operational areas: vulnerability management and security monitoring. You will be the person ensuring our detection and remediation workflows operate smoothly on a daily basis — triaging findings, tuning alerts, driving fixes forward, and supporting the team when incidents occur.
What You'll Do
Vulnerability Management
We Offer
Work in a modern IT company — no bureaucracy or legacy systems.
Genuine opportunities for professional growth and meaningful impact.
Fully remote work from anywhere in the world, on a flexible schedule.
Compensation for health insurance, sports, professional development, and more.
Our trading activity spans major exchanges. The firm operates across a wide spectrum of asset classes: equities, equity derivatives, options, commodity futures, rates futures, and others. We deploy a diverse and expanding set of algorithmic trading strategies, leveraging both high- and medium-frequency approaches.
Our team consists of 200+ specialists, with a heavy tilt toward technology — 70% are technical experts working in development, infrastructure, testing, and analytics. The rest of the team covers business functions such as Risks, Compliance, Legal, Operations, and more.
Driven by a commitment to innovation and performance, BHFT is actively growing its footprint in traditional financial markets. We foster a results-oriented culture built on collaboration, transparency, and continuous improvement, while providing the flexibility of remote work within a globally distributed team.
Job Description
We are seeking an Information Security Engineer to join our security team and take full ownership of two key operational areas: vulnerability management and security monitoring. You will be the person ensuring our detection and remediation workflows operate smoothly on a daily basis — triaging findings, tuning alerts, driving fixes forward, and supporting the team when incidents occur.
What You'll Do
Vulnerability Management
- Operate our vulnerability scanner: ensure coverage, manage scan schedules, and keep agents/engines in a healthy state.
- Conduct weekly triage of findings — evaluate severity × exposure, deduplicate results, and route issues to responsible teams.
- Track remediation progress against SLAs, follow up with teams, verify fixes, and re-scan to confirm closure.
- Monitor vulnerability feeds and vendor advisories (GitLab, Ubuntu, network equipment, key dependencies) and highlight time-critical patches.
- Maintain vulnerability metrics: open criticals, finding age, and mean time to patch.
- Operate our central log pipeline: onboard new log sources, monitor shipper health, and manage retention.
- Maintain and tune detection rules and alerts (authentication anomalies, firewall changes, privileged actions, exchange-account events).
- Triage security alerts, escalate per playbooks, and participate in the on-call duty rotation.
- Support incident response: evidence collection, timeline reconstruction, and post-incident follow-up.
- 1–3 years of experience in a security, DevOps, or systems administration role.
- Strong Linux fundamentals: processes, users/permissions, logs, systemd, SSH.
- Networking basics: TCP/IP, DNS, firewalls, VPN concepts.
- Understanding of the vulnerability lifecycle: CVE, CVSS, patching vs. mitigating.
- Scripting skills in Python or Bash (automating a report, parsing a log, calling an API).
- Comfortable working with Git and merge-request workflows.
- Hands-on experience with a vulnerability scanner (Rapid7, Nessus, OpenVAS, Qualys).
- Hands-on experience with a log/SIEM stack (Graylog, ELK, Wazuh, Splunk).
- Experience with Ansible or another configuration-management tool.
- Basic familiarity with containers/Kubernetes.
We Offer
Work in a modern IT company — no bureaucracy or legacy systems.
Genuine opportunities for professional growth and meaningful impact.
Fully remote work from anywhere in the world, on a flexible schedule.
Compensation for health insurance, sports, professional development, and more.
Требованияобязательно
1–3 года опыта в роли security, DevOps или системного администрирования
Уверенные основы Linux: процессы, пользователи/права, логи, systemd, SSH
Базовые знания сетей: TCP/IP, DNS, firewalls, концепции VPN
Понимание жизненного цикла уязвимостей: CVE, CVSS, патчинг vs. митигация
Навыки скриптинга на Python или Bash
Опыт работы с Git и merge-request workflow
Будет плюсом
Опыт работы со сканером уязвимостей (Rapid7, Nessus, OpenVAS, Qualys)
Опыт работы со стеком логов/SIEM (Graylog, ELK, Wazuh, Splunk)
Опыт работы с Ansible или другим инструментом конфигурационного управления
Базовое знакомство с контейнерами/Kubernetes
Что предлагают
Полностью удалённая работа из любой точки мира
Гибкий график
Компенсация медицинской страховки, спорта, профессионального развития
Источник
Подробнее и отклик → getmatch.ru
Заполнить профильполучайте подобные вакансии
Работодатель? Опубликуйте напрямую
Агрегировано Codeby Jobs. Источник: getmatch_ru (getmatch.ru). Удаление по запросу: @admin.
Компания
Похожие вакансии
Карьера в ИБ
Вакансии по стеку