Security Engineer
Israel - Legal - Full-time - Intermediate
Glassbox is looking for a Senior Security Engineer to join our Global Data Protection team
We are Glassbox, a world’s leader in digital experience intelligence (DXI), and on a mission to deliver frictionless digital journeys to leading brands and their customers all over the world
We are a hyper-growth scale-up company that continues to grow quarter-on-quarter and our customers love us- named a 2022 leader in 9 G-2 categories based on customer reviews!
So, now is the perfect time to come to Glassbox and help us accelerate our global leadership position!
Will you join us on this journey?
What You Will Do
- Implement security tools and take actions as needed to close cyber security gap analysis and risk assessment findings (Partial Hands-on)
- Designing, and planning a secure environment according to company requirements and controls
- Create and tune security alerts to ensure 24x7 monitoring by our SOC team
- Create and tune procedures and runbooks and cyber simulation exercises for the SOC team to handle alerts
- Perform internal & external, technical, and procedural security audits
- Engage with IT, cloud, and compliance teams to ensure requirements, policies, and adoption is executed with excellence
- Create and Maintain reports and evidence for our compliance such as SOC2 and ISO
- Performing Internal Penetration tests on application and cloud Infrastructure
What You Will Need
- Hands-on experience with AWS or Azure security best practices and AWS or Azure services (A must)
- Solid understanding and experience with security standards and practices (CIS, OWASP, SANS, etc.)
- AWS Cloud infrastructure Services S3, VPC, EC2, RDS, IAM, ELBs, Route53, Lambda, ECR, ECS, along with AWS security tools
- Hands-on experience in Linux (Red Hat / CentOS), network architecture and security implementation
- Identity management and authentication systems and protocols (AD, SAML, OAuth, etc.)
- 3+ years of experience with Cloud Security (research, engineering and/or architecture)
- Address Penetration test findings
- Basic scripting using Python Bash PowerShell
- Deep understanding of network structure and network protocols
- Experience with SEIM implementation
- Passion for new technologies
Advantage
- Either of the following certifications: CISM, AWS Solution Architect, Sysops Administrator, CKS
- Experience with containerized environments and microservices (i.e., Docker, AWS ECS or Kubernetes)
- Knowledge in VPN and Zero-trust Connections
- Background and experience with Software and Application security
- Knowledge in PT using Burp Suite, Nessus, Nmap and SSL Scan and more