Security Engineer
Job description
About the role
Virtuozzo is seeking a Security Engineer to join their team on a contract basis. The role focuses on protecting the company's container virtualization and cloud infrastructure platforms from emerging and evolving threats. The engineer will work to identify vulnerabilities, strengthen defenses, and ensure the security posture of Virtuozzo's products and services across all deployment environments. This position involves close collaboration with development and operations teams to embed security practices throughout the entire software development lifecycle, from initial design through production deployment, and to build a culture of security awareness within the organization.
Key facts
What you'll do
- Evaluate and address security weaknesses found in Virtuozzo's virtualization and container platforms.
- Design and implement security controls to safeguard cloud infrastructure and container environments.
- Conduct penetration testing and vulnerability assessments across Virtuozzo's product suite and services.
- Review source code for security flaws and recommend effective remediation strategies to developers.
- Develop and maintain security policies, procedures, and documentation for the engineering organization.
- Monitor threat intelligence feeds and apply relevant findings to Virtuozzo's security practices.
- Respond to security incidents, perform root cause analysis, and drive remediation efforts forward.
- Collaborate with product teams to integrate security requirements into the development workflow.
- Perform security architecture reviews for new features and existing system components regularly.
- Advise engineering staff on secure coding practices and threat modeling techniques effectively.
- Automate security testing and scanning processes within the continuous integration and delivery pipeline.
- Maintain and update the company's incident response plan and disaster recovery procedures.
- Coordinate with external security researchers and bug bounty participants to validate findings.
- Track and report on security metrics, trends, and compliance status to leadership.
- Assess third-party dependencies and open source components for known security vulnerabilities, license compliance, and supply chain risks.
- Contribute to the development of internal security tooling, reusable automation frameworks, and shared libraries for the engineering team.
Requirements
- Bachelor's degree in computer science, cybersecurity, or a related technical field.
- Several years of hands-on experience in application or infrastructure security roles.
- Strong understanding of containerization technologies and virtualization security concepts and practices.
- Familiarity with cloud computing platforms and their associated security challenges and risks.
- Proficiency in at least one programming or scripting language for security tooling.
- Experience conducting penetration tests and vulnerability assessments on software systems.
- Knowledge of common web application vulnerabilities and effective mitigation strategies.
- Ability to analyze complex systems and identify potential attack vectors quickly.
- Demonstrated experience with security hardening of Linux-based operating systems and services.
- Comfort working in a fast-paced environment with shifting priorities and deadlines.
- Excellent written and verbal communication skills for reporting security findings to both technical and non-technical stakeholders clearly and concisely.
Nice to have
- Prior experience working with Virtuozzo or similar container virtualization products and platforms.
- Professional certifications such as CISSP, CEH, OSCP, or equivalent recognized security credentials.
- Background in open source software development, active community security contributions, code reviews, and upstream patch submissions.
- Experience with DevSecOps practices and security automation frameworks in production deployment and release environments.
Skills & tools
- Proficiency in Linux operating systems and system-level security hardening configurations and settings.
- Experience with vulnerability scanning and static analysis tools for thorough code review.
- Knowledge of network security protocols, firewall rules, and access control list management.
- Familiarity with security information and event management platforms for continuous monitoring, alerting, and incident correlation.
- Understanding of encryption standards, cryptographic protocols, and key management best practices.
- Comfort with scripting languages such as Python, Bash, or PowerShell for automation tasks.
Practical notes
- This is a contract position with a defined engagement period and specific scope of work.
- The specific work location has not been determined or disclosed by the employer at this time.
- Compensation details are not included in the current job listing and should be discussed directly.
- Candidates should expect to work closely with cross-functional engineering and product teams on a regular basis.
- The hiring process may include technical interviews, coding assessments, and security scenario evaluations.
- The role may require occasional travel to Virtuozzo offices or customer sites for on-site security reviews, workshops, and collaboration sessions.
About the company
Virtuozzo is a software company that develops virtualization and cloud management software for cloud computing providers, managed services providers and internet hosting service providers. The company's software enables service providers to offer Infrastructure as a service, Container-as-a-Service, Platform as a service, Kubernetes-as-a-Service, WordPress-as-a-Service and other solutions.