Hybrid Information Security Engineer

Posted last week

Apply now

About the role

  • Support maintenance and continuous improvement of the Information Security Management System (ISMS) aligned with ISO 27001:2022
  • Update and maintain policies, processes, and procedures to reflect evolving security controls and compliance requirements
  • Assist in risk assessments, control evaluations, and internal security reviews
  • Configure, maintain, and create use cases and playbooks in Wazuh SIEM and SOAR platforms for enhanced threat detection and automated incident response
  • Conduct vulnerability management for infrastructure and applications using tools such as Nessus, Snyk, and Fortinet
  • Participate in incident response activities, including investigation, containment, remediation, and reporting
  • Support continuous monitoring and alerting through SOC operations
  • Contribute to threat intelligence gathering, focusing on Indicators of Compromise (IoCs) by geography and industry
  • Monitor and manage IP reputation and malicious domain blocking in line with regulatory and compliance requirements
  • Support periodic IAM reviews, user cleanup, and recertification processes to enforce least privilege and proper access control
  • Collaborate with IT to ensure consistent enforcement of IAM policies and account lifecycle management
  • Help execute and evaluate phishing and ransomware simulations using Smartfense and others
  • Assist in external security audits with providers and clients, supplying evidence and documentation as required
  • Support internal control testing, on-demand audits, and penetration testing for platforms, processes, and third parties
  • Participate in security reviews for information exchange with vendors and partners
  • Support the implementation, deployment, and management of Data Loss Prevention (DLP) tools and processes, including data classification and monitoring
  • Maintain and optimize Defender, Fortinet, and Linux-based security tools
  • Use Wireshark and Zabbix for traffic analysis, anomaly detection, and network performance monitoring

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or related field
  • 3+ years of hands-on experience in information security, SOC, or cyber defense operations
  • Practical knowledge of ISO 27001, NIST CSF, MITRE ATT&CK, and CIS Controls
  • Experience with SIEM, SOAR, Vulnerability Management, DLP, and IAM tools
  • Familiarity with incident response, network monitoring, and threat intelligence workflows
  • Strong command of Linux administration and security hardening
  • Understanding of DevSecOps, automation, and scripting (Python, Bash preferred)
  • Excellent communication and documentation skills in English (Spanish and/or Portuguese highly desirable).

Benefits

  • Access to cutting-edge tools
  • Professional development opportunities

Job title

Information Security Engineer

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job