Security Engineer
Sauce Labs Inc.India2w ago
Job description
About the role
Sauce Labs is a leading provider of a comprehensive platform designed for enterprises to effectively test and deploy mobile and web applications. We are currently seeking a dedicated Security Engineer to become a vital member of our Blue Team. This role involves overseeing security measures across our cloud infrastructure, endpoints, and overall environment to ensure the highest level of protection for our systems and data.
Key facts
What you'll do
- Oversee and implement security controls across environments such as Ubuntu, Linux, and Google Kubernetes Engine to safeguard our infrastructure.
- Collaborate with the IT department to monitor and enhance the security of corporate devices and networks.
- Conduct vulnerability assessments and scans utilizing tools like OpenVAS and Tenable Nessus to identify potential security threats.
- Take ownership of vulnerability triage, coordinating with various internal teams to address and remediate identified issues.
- Analyze security alerts and escalate significant concerns to the appropriate channels for further investigation.
- Maintain and improve the security posture of our cloud environments, particularly focusing on best practices within Google Cloud Platform.
- Develop and maintain automation scripts using bash or zsh to streamline security processes and improve efficiency.
- Generate reports on key security metrics, including incident response times, login failures, and key rotation activities.
- Create and manage security policies that align with audit requirements and certifications, ensuring compliance across the organization.
- Document security protocols and maintain logs of incidents to support ongoing security initiatives.
- Participate in an on-call rotation, which may include nights and weekends, to respond to security incidents as they arise.
- Adjust work hours as necessary to engage in global team meetings, including planning sessions, stand-ups, and retrospectives.
Requirements
- An Associate or Bachelor of Science degree in a relevant discipline, or equivalent professional experience in the field.
- A minimum of 3 to 5 years of hands-on experience in cybersecurity, systems administration, or IT support roles.
- Solid understanding and practical experience with Linux systems, particularly Ubuntu administration.
- Proficiency in scripting languages such as zsh or bash to automate security tasks.
- Familiarity with established security frameworks, including MITRE ATT&CK, MITRE ATLAS, OWASP Top 10, Pyramid of Pain, or Cyber Kill Chain.
- Knowledge of Cloud Security Posture Management (CSPM) and best practices for cloud security.
- Experience with various vulnerability scanning tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), OpenVAS, and Tenable Nessus.
- Background in Cybersecurity Analysis or experience in roles related to SaaS, mobile applications, infrastructure, or endpoint security.
Nice to have
- Experience with macOS administration and securing corporate endpoints across various operating systems, including Windows, iOS, Android, or macOS.
- Previous experience as a System Administrator, providing a strong foundation in system security.
- Skills in automation or programming with languages such as Python, SaltStack, or Ansible.
- Experience in developing open-source Security Information and Event Management (SIEM) solutions like Security Onion, Wazuh, or utilizing tools such as OpenSearch, ElasticSearch, or Graylog.
- Familiarity with managing Intrusion Detection Systems (IDS) such as Falco, Wazuh, Snort, Zeek, or Suricata.
- Knowledge of Digital Forensics and Incident Response (DFIR) tools like OSQuery or Velociraptor.
- Experience deploying inline security systems, including Web Application Firewalls (WAF), Intrusion Detection and Prevention Systems (IDP), or Taps.
- Kubernetes certifications such as Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA), or Certified Kubernetes Application Developer (CKAD).
- Understanding of Third-Party Risk Management (TPRM) practices.
- Familiarity with ISO 42001, ISO 27001, or SOC 2 audit standards.
- Experience with securing or utilizing Artificial Intelligence (AI) and Large Language Models (LLM) systems.
Skills & tools
- Google Cloud Platform (GCP)
- Google Kubernetes Engine (GKE)
- Ubuntu / Linux
- Bash / Zsh
- Tenable Nessus / OpenVAS
- SAST / DAST / SCA
Practical notes
- This position requires in-office attendance for three days each week.
- Adherence to all internal security protocols is mandatory, and a security-first mindset is essential for success in this role.
- Sauce Labs is committed to fostering an inclusive workplace and is proud to be an equal opportunity employer.