Senior Information Security Engineer (InfraSec)

About the job

The world’s most critical--and at-risk--business applications have been neglected for far too long. Onapsis eliminates this blind spot by providing cybersecurity solutions dedicated to business-critical applications. Whether running on-premises, in the cloud, or in a hybrid environment, Onapsis helps nearly 30% of the Forbes Global 100 understand the threats and risks across their SAP and Oracle landscapes. 

What you will be doing, your legacy: 

  • Network Security: Administer and optimize firewalls and VPN solutions to ensure secure network traffic and remote access. 
  • Infrastructure Security: Design, implement, and maintain security measures to protect the organization’s infrastructure, focusing on network security and protocols like TCP/IP, UDP, HTTP, SSL, DNS, and IPSec.
  • Cryptography: Manage cryptographic processes, including the generation and renewal of public/private keys and certificates to maintain secure communications.
  • Security Monitoring & Incident Response: Collaborate with the Security Operations Center (SOC) team to monitor security alerts, investigate incidents, and respond to security breaches and vulnerabilities in a timely manner.
  • Automation: Automate security tasks and processes through CI/CD pipelines to enhance operational efficiency.
  • Cloud Security: Implement and maintain security practices for managing cloud resources, ensuring secure access to instances, storage, services, and infrastructure, as well as monitoring and auditing activities.
  • Endpoint & Server Protection: Secure endpoints and servers by implementing effective protection strategies.
  • Web Security: Manage web application security, including the configuration and oversight of Web Application Firewalls (WAF).
  • Vulnerability Management: Lead the vulnerability management process, including identifying, prioritizing, and remediating vulnerabilities across infrastructure, applications, and cloud environments.

Requirements:

  • 5+ years of experience managing network security infrastructure, including firewall, IDS/IPS, and VPN administration (e.g., Palo Alto, CheckPoint, Cisco).
  • Solid understanding of network protocols (TCP/IP, UDP, HTTP, SSL, DNS, IPSec) and their role in maintaining secure systems. Proficiency in configuring and managing VPNs and secure connections via protocols like IPSec/SSL.
  • Expertise in cryptography, including managing encryption processes, key generation, and certificate renewal procedures.
  • Ability to integrate security into DevOps workflows using CI/CD tools like GitLab. Proficient in automating security tasks and processes using Python or another scripting language.
  • Strong working knowledge of cloud security practices across major platforms such as AWS, GCP, and Azure.
  • In-depth experience in securing endpoints and servers across various operating systems (Windows, Linux, macOS) through endpoint protection platforms (EPP), endpoint detection and response (EDR), and server hardening practices.
  • Hands-on experience with web security solutions, including WAF administration (AWS WAF, CloudFlare) and protection against common vulnerabilities (SQL injection, XSS, DDoS attacks, etc).
  • Advanced level of spoken and written English.
  • Strong communication and teamwork skills.

Desired skills or interests in:

  • Practical experience working in an agile environment.
  • Knowledge of information security standards (e.g., ISO 27001, NIST 800-53, CIS Critical Security Controls, etc.), and related security principles for risk identification and analysis.
  • Certifications in security, networking and/or cloud environments.
  • Continuous learning mindset, staying up-to-date with emerging cybersecurity trends and threats.
  • Strong problem-solving and analytical skills to make informed decisions regarding risk mitigation.

What we offer: 

  • A role in shaping the future of protecting the most critical applications that run the world's business and a career that grows as the company grows.
  • A unique culture of high achievement and teamwork.
  • Supportive and humble colleagues are the space's top problem solvers and innovators.
  • Financial security through competitive compensation and incentives.

Employment: Onapsis hires full-time employees in Argentina.

Location: remote in Argentina.

 About Onapsis:

Onapsis protects the business applications that run the global economy. The Onapsis Platform delivers vulnerability management, change assurance, and continuous compliance for business applications from leading vendors such as SAP, Oracle, and others. The Onapsis Platform is powered by the Onapsis Research Labs, the team responsible for the discovery and mitigation of more than 1,000 zero-day vulnerabilities in business applications.

Onapsis is headquartered in Boston, MA, with offices in Heidelberg, Germany and Buenos Aires, Argentina, and proudly serves hundreds of the world’s leading brands, including close to 30% of the Forbes Global 100, six of the top 10 automotive companies, five of the top 10 chemical companies, four of the top 10 technology companies, and three of the top 10 oil and gas companies.

For more information, connect with Onapsis on LinkedIn or visit https://www.onapsis.com.

#LI-AC1

#Remote

 

 

Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Information Security Engineer Q&A's
Report this job
Apply for this job