Senior Security Engineer
Tech Stack / Keywords
Firma i stanowisko
GS Services is seeking a Senior Security Engineer for a cybersecurity team supporting a client with complex Windows/Linux infrastructure, both on-premises and cloud environments. The role involves designing, implementing, and operating large-scale corporate security mechanisms, collaborating with security, IT, platform, and engineering teams.
Wymagania
- 7+ years of experience in security engineering or similar roles.
- Extensive experience in identity and access management including Active Directory, Microsoft Entra (Azure AD), and SAML/SSO integrations.
- Experience with endpoint protection platforms such as CrowdStrike and Defender.
- Strong experience with Windows and Linux systems at scale, focusing on security and performance optimization.
- Advanced scripting and automation skills in PowerShell, Python, or similar.
- Experience integrating systems via APIs, automation pipelines, or orchestration tools.
- Solid knowledge of OS hardening, network security and segmentation, and security monitoring pipelines.
- Excellent diagnostic, analytical, and problem-solving skills.
- Ability to work independently and manage multiple parallel initiatives.
- Excellent written and verbal communication skills, capable of explaining technical conclusions to varied audiences.
Nice to have:
- Experience in high-availability or regulated environments with strict change control.
- Knowledge of cloud security concepts in AWS and/or Azure.
- Experience with complex security initiatives.
- Experience managing and configuring hardware firewalls.
- Experience deploying enterprise phishing-resistant authentication.
- Experience with MDM platforms (Intune, Jamf) and device compliance systems.
- Familiarity with SIEM platforms like Splunk or Sumologic.
- Experience securing AI usage.
Certifications:
- Preferred certifications include CISSP, CEH, CompTIA CySA+ or Security+, Microsoft SC-200, AWS Security Specialty or equivalents.
Obowiązki
IAM:
- Assist in implementing data scanning and threat removal solutions.
- Improve reliability and usability of PAM solutions.
- Test and deploy phishing-resistant authentication solutions such as Windows Hello for Business, FIDO2/YubiKey, and passwordless processes.
- Configure SAML for security applications.
Endpoint Security:
- Configure and optimize endpoint protection platforms like Microsoft Defender and CrowdStrike Falcon on Windows and Linux.
- Manage policies, exclusions, and ensure stability across environments.
- Develop performance indicators for agents, resource utilization, and security signals at scale.
Infrastructure and Network Security:
- Assist in firewall requirement verification.
- Support segmentation and workload protection technologies such as Zero Networks on Windows and Linux.
- Participate in designing secure architecture for AWS/Azure cloud and on-premises.
- Review and simplify Zero Trust rules in Cloudflare.
Artificial Intelligence Security:
- Implement security for AI tools such as Claude, Cursor, GitHub Copilot, and Microsoft Copilot.
- Identify hidden AI systems and develop tools for their removal.
Automation:
- Create automation scripts and solutions in PowerShell, Python, and shell scripting for tagging, classification, monitoring verification, and audit reporting.
- Integrate security tools with APIs and CI/CD processes (e.g., Jenkins).
Detection, Response, Engineering, and Incident Support:
- Assess, create, and optimize logging pipelines in corporate and SaaS environments balancing cost and coverage.
- Deploy and optimize intrusion detection/prevention and data loss prevention solutions across network firewalls, endpoints, and SaaS applications.
- Support security operations by investigating alerts, incidents, unusual behaviors, and automate classification using AI.
- Participate in root cause analysis and remediation efforts.
Vulnerability Management and Application Security:
- Optimize vulnerability management tools like Nessus for scanning, reporting, and remediation, coordinating with EDR tools.
- Review application security tool results for coverage, remediation, and reporting.
Cloud Security:
- Implement cloud security solutions for AWS and Azure and deploy cloud security posture management tools.
- Identify and remediate deviations from best practices in IAM in cloud.
- Assist in configuring roles and policies enforcing least privilege.
- Configure native and platform-independent security tools to mitigate risks.
Project Leadership:
- Lead security engineering initiatives from design to production rollout.
- Use structured deployment strategies (canary, staging, phased rollout) to minimize operational risk.
- Collaborate with DevOps, Platform, Engineering, and Corporate IT teams.
Benefity
- Up to 210 PLN net per hour + VAT.
- Onboarding for several days in London office.
- Cooperation model: B2B full-time.
- Remote work with occasional visits to London office.
- Immediate start availability.
Inne informacje
The position requires advanced English proficiency at minimum C1 level. The recruitment process complies with GDPR. Personal data will be processed by GS Services with storage duration depending on candidate consent. Data will not be shared outside the EEA or international organizations. Candidates have rights including data access, correction, deletion, and complaint submission under GDPR.
GS Services
7 aktywnych ofert