Təhlükəsizlik mühəndisi (endpoint və infrastrukturun qorunması)

JustMarkets

Vakansiya haqqında

We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.

This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.

You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems

Responsibilities

  • Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
  • Administer device-security controls through MDM/UEM and related management platforms where applicable
  • Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
  • Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
  • Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
  • Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
  • Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
  • Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
  • Maintain file-integrity monitoring and isolation readiness for critical systems where required
  • Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
  • Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
  • Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
  • Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
  • Experience implementing operating-system hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • Fluent in Russian
  • Upper-Intermediate or higher level of English

Will be a plus

  • Experience working with CIS Benchmarks or comparable hardening standards
  • Experience securing both macOS workstations and Linux production servers
  • Experience supporting a large, distributed fleet of managed endpoints or servers
  • Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
  • Experience integrating endpoint telemetry or response workflows with other security platforms
  • Experience in fintech, banking, trading, or another regulated environment
  • Relevant technical education, professional training, or equivalent practical experience

We offer

  • 15 paid vacation days per year
  • 10 paid sick leave days per year
  • 10 days for floating Public holidays
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.

This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.

You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems

Responsibilities

  • Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
  • Administer device-security controls through MDM/UEM and related management platforms where applicable
  • Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
  • Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
  • Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
  • Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
  • Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
  • Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
  • Maintain file-integrity monitoring and isolation readiness for critical systems where required
  • Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
  • Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
  • Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
  • Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
  • Experience implementing operating-system hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • Fluent in Russian
  • Upper-Intermediate or higher level of English

Will be a plus

  • Experience working with CIS Benchmarks or comparable hardening standards
  • Experience securing both macOS workstations and Linux production servers
  • Experience supporting a large, distributed fleet of managed endpoints or servers
  • Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
  • Experience integrating endpoint telemetry or response workflows with other security platforms
  • Experience in fintech, banking, trading, or another regulated environment
  • Relevant technical education, professional training, or equivalent practical experience

We offer

  • 15 paid vacation days per year
  • 10 paid sick leave days per year
  • 10 days for floating Public holidays
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)
Yerləşmə
Azərbaycan
Təcrübə
4+ il
Məşğulluq
Tam ştat
Əməkhaqqı
Göstərilməyib
Yerləşdirilib
10 sentyabr 2026
Dillər
Russian, English

Şirkət haqqında

JustMarkets
Financial Services · 201-500
JustMarkets — bütün vakansiyalar

Müraciətin

Bu işəgötürən müraciətləri öz saytında qəbul edir. Vakansiyanın səhifəsinə keç və oradakı formanı doldur.

İşəgötürənin səhifəsinə keç

Bacarıqlara görə oxşar

Bütün oxşar vakansiyalar

Bu vakansiyanın bacarıqları ilə ən çox üst-üstə düşən vakansiyalar.

Bütün oxşar vakansiyalar
Göstərilməyib
Təhlükəsizlik mühəndisi (endpoint və infrastrukturun qorunması)
Müraciət et