← Takaisin työpaikkoihin

Security Engineer

  • Etätyö
  • Ruotsi
  • Englanti
  • Julkaistu 09.09.26 18:50

Security EngineerRemote – UK or EUOutside IR35 IntroductionWe are looking for an experienced Security Engineer to join a Security Engineering team responsible for building, operating and improving the security tooling, platforms and services that support Security Operations and wider engineering teams. This is an engineering and platform-focused role, rather than a SOC Analyst position. You will be responsible for developing and maintaining security tooling, security data pipelines, cloud security controls and automation. The RoleAs a Security Engineer, you will take ownership of a defined set of security tools and services, ensuring they are reliable, scalable and fit for purpose. You will work closely with Security Operations, Infrastructure and Platform teams, with a particular focus on security logging, SIEM, AWS cloud security, Kubernetes, Infrastructure as Code and automation. Key responsibilities will include:Owning and maintaining security tools and services including SIEM, log analytics, NIDS, SOAR and WAF.Designing and operating security log pipelines, moving telemetry from different systems into SIEM and analytics platforms.Building and maintaining log collection and pipeline infrastructure running on Kubernetes/EKS.Developing AWS security tooling, controls and guardrails across a large multi-account environment.Developing security tools, integrations and automation using Python.Delivering infrastructure and security services using Infrastructure as Code and GitOps.Monitoring the health, availability and performance of security platforms and driving continuous improvements.Supporting POCs and evaluations of new security technologies and vendors.Working with internal teams to provide technical guidance and support.Ensuring security services and tooling meet relevant audit and compliance requirements. Key Skills & Experience RequiredSecurity Engineering experience within a cloud or enterprise environment.Proven experience designing and operating security log pipelines and onboarding high-volume telemetry into SIEM or log analytics platforms.Experience with OpenSearch, Elasticsearch, Elastic or similar SIEM/log analytics platforms.Experience with log shippers and collectors such as Vector, Fluentd, Fluent Bit, Logstash or similar.Strong hands-on experience with AWS cloud security, ideally within a multi-account environment.Strong knowledge of AWS IAM, CloudTrail, Config and GuardDuty.Experience with Infrastructure as Code, particularly Terraform or similar.Experience working with GitOps and tools such as ArgoCD, Kustomize or Flux.Good knowledge of Kubernetes/EKS and cloud infrastructure.Strong Python scripting and automation skills.Good understanding of fundamental security concepts and security architecture.Ability to take ownership of security tooling and services and proactively identify improvements.Strong communication skills with the ability to work with both technical and non-technical stakeholders.Fluent English. DesirableThe following experience would be advantageous:Container and software supply-chain security.SBOM generation and analysis.Container image signing and provenance.Detection engineering and Sigma rules.Experience with MITRE ATT&CK.Experience with ElastAlert or similar alerting frameworks.Experience with security automation and DevSecOps.Experience running or maintaining a personal homelab or self-hosted infrastructure.