Инженер по безопасности (защита конечных точек и инфраструктуры)

в JustMarkets

О роли

We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.

This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.

You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems

Responsibilities

  • Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
  • Administer device-security controls through MDM/UEM and related management platforms where applicable
  • Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
  • Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
  • Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
  • Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
  • Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
  • Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
  • Maintain file-integrity monitoring and isolation readiness for critical systems where required
  • Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
  • Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
  • Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
  • Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
  • Experience implementing operating-system hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • Fluent in Russian
  • Upper-Intermediate or higher level of English

Will be a plus

  • Experience working with CIS Benchmarks or comparable hardening standards
  • Experience securing both macOS workstations and Linux production servers
  • Experience supporting a large, distributed fleet of managed endpoints or servers
  • Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
  • Experience integrating endpoint telemetry or response workflows with other security platforms
  • Experience in fintech, banking, trading, or another regulated environment
  • Relevant technical education, professional training, or equivalent practical experience

We offer

  • 15 paid vacation days per year
  • 10 paid sick leave days per year
  • 10 days for floating Public holidays
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

We are looking for a hands-on Security Engineer (Endpoint and Infrastructure Protection) to build and operate the controls that protect our employee devices and server workloads.

This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.

You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems

Responsibilities

  • Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
  • Administer device-security controls through MDM/UEM and related management platforms where applicable
  • Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
  • Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
  • Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
  • Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
  • Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
  • Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
  • Maintain file-integrity monitoring and isolation readiness for critical systems where required
  • Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
  • Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
  • Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
  • Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
  • Experience implementing operating-system hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • Fluent in Russian
  • Upper-Intermediate or higher level of English

Will be a plus

  • Experience working with CIS Benchmarks or comparable hardening standards
  • Experience securing both macOS workstations and Linux production servers
  • Experience supporting a large, distributed fleet of managed endpoints or servers
  • Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
  • Experience integrating endpoint telemetry or response workflows with other security platforms
  • Experience in fintech, banking, trading, or another regulated environment
  • Relevant technical education, professional training, or equivalent practical experience

We offer

  • 15 paid vacation days per year
  • 10 paid sick leave days per year
  • 10 days for floating Public holidays
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)
Локация
Азербайджан
Опыт
4+ лет
Занятость
Полная занятость
Зарплата
Не указана
Опубликовано
10 сентября 2026
Языки
Russian, English

О компании

JustMarkets
Financial Services · 201-500
Все вакансии JustMarkets

Ваш отклик

Этот работодатель принимает отклики у себя на сайте. Перейдите на страницу вакансии и заполните форму там.

Перейти на страницу работодателя

Похожие по навыкам

Все похожие вакансии

Вакансии, где совпадает больше всего навыков из этой позиции.

З/п не указана

Оказывает ИТ-поддержку, решает инциденты и управляет сетью и серверной инфраструктурой.

Windows Operating SystemVMwareIncident ManagementTechnical Support+6
ОткликнутьсяПростой откликПростой отклик
Все похожие вакансии
Не указана
Инженер по безопасности (защита конечных точек и инфраструктуры)
Откликнуться