Əməliyyat sistemlərinin sazlanması və virtual mühitlərin idarə olunması bacarığı tələb olunur.
Vakansiya haqqında
We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.
This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.
You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems
Responsibilities
- Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
- Administer device-security controls through MDM/UEM and related management platforms where applicable
- Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
- Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
- Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
- Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
- Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
- Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
- Maintain file-integrity monitoring and isolation readiness for critical systems where required
- Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
- Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking
Requirements
- 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
- Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
- Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
- Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
- Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
- Experience implementing operating-system hardening and working with native security controls
- Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
- Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
- Fluent in Russian
- Upper-Intermediate or higher level of English
Will be a plus
- Experience working with CIS Benchmarks or comparable hardening standards
- Experience securing both macOS workstations and Linux production servers
- Experience supporting a large, distributed fleet of managed endpoints or servers
- Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
- Experience integrating endpoint telemetry or response workflows with other security platforms
- Experience in fintech, banking, trading, or another regulated environment
- Relevant technical education, professional training, or equivalent practical experience
We offer
- 15 paid vacation days per year
- 10 paid sick leave days per year
- 10 days for floating Public holidays
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.
This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.
You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems
Responsibilities
- Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
- Administer device-security controls through MDM/UEM and related management platforms where applicable
- Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
- Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
- Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
- Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
- Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
- Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
- Maintain file-integrity monitoring and isolation readiness for critical systems where required
- Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
- Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking
Requirements
- 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
- Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
- Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
- Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
- Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
- Experience implementing operating-system hardening and working with native security controls
- Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
- Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
- Fluent in Russian
- Upper-Intermediate or higher level of English
Will be a plus
- Experience working with CIS Benchmarks or comparable hardening standards
- Experience securing both macOS workstations and Linux production servers
- Experience supporting a large, distributed fleet of managed endpoints or servers
- Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
- Experience integrating endpoint telemetry or response workflows with other security platforms
- Experience in fintech, banking, trading, or another regulated environment
- Relevant technical education, professional training, or equivalent practical experience
We offer
- 15 paid vacation days per year
- 10 paid sick leave days per year
- 10 days for floating Public holidays
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Şirkət haqqında
Müraciətin
Bu işəgötürən müraciətləri öz saytında qəbul edir. Vakansiyanın səhifəsinə keç və oradakı formanı doldur.
İşəgötürənin səhifəsinə keçBacarıqlara görə oxşar
Bütün oxşar vakansiyalarBu vakansiyanın bacarıqları ilə ən çox üst-üstə düşən vakansiyalar.
İT dəstəyi göstərir, insidentləri həll edir və şəbəkə ilə server infrastrukturunu idarə edir.
Bank sistemlərinin təhlükəsizliyini təmin edir və informasiya təhlükəsizliyi üzrə 2 ildən çox təcrübəsi var
İT infrastrukturunun texniki dəstəyi və problemlərin həlli üçün ən azı 1 il təcrübə tələb olunur


