Skip to main content
C

Creative Capsule

IT Security Junior Engineer/Engineer

Goa, IN, India1+ yrsPosted 3 days ago

Skills

LinuxAWSAzureGoogle CloudCybersecurity

Job description

This position is responsible for supporting the organization’s security monitoring, incident response, and vulnerability management activities. The role will primarily focus on SOC operations using Wazuh, including monitoring security alerts, reviewing logs, validating incidents, escalating risks, and supporting response actions for issues such as unauthorized access, malware, phishing, suspicious activity, and possible data exposure. You will also support application and server vulnerability assessment activities, including reviewing web applications, APIs, mobile applications, Linux and Windows servers, validating scan results, preparing remediation guidance, and verifying fixes.

Responsibilities

Monitor security events and alerts using Wazuh and other tools such as EDR, firewall, email security, cloud, endpoint, and network security platforms

Analyze SIEM alerts, logs, agent data, vulnerability findings, file integrity monitoring events, authentication logs, and security events to identify suspicious activity, unauthorized access, malware, phishing attempts, data exposure, and policy violations

Perform initial alert validation, severity assessment, false-positive review, and incident prioritization based on alert context, affected assets, risk level, and business impact

Support incident containment and response actions such as blocking malicious indicators, disabling compromised accounts, isolating affected systems, removing malicious emails, revoking suspicious sessions, and validating remediation

Track incidents from detection to closure and ensure timely follow-up on investigation, remediation, and preventive actions

Perform application vulnerability assessments for web applications, APIs, and mobile applications using automated tools and manual verification where required

Perform server vulnerability assessments on Linux and Windows servers to identify missing patches, insecure configurations, exposed services, weak protocols, and known vulnerabilities

Review vulnerability scan results, validate findings, remove false positives, assign severity, and prepare clear remediation guidance for application and server teams

Track vulnerability remediation status, follow up with owners, verify fixes through retesting, and maintain vulnerability assessment reports

Support SIEM rule tuning, alert quality improvement, false-positive reduction, detection use-case creation, dashboard review, and security monitoring improvements

Assess the security posture of third-party tools and services before adoption to identify risks and ensure compliance with organizational policies

Research emerging security topics and new attack vectors to support continuous improvement of security monitoring and vulnerability assessment practices

Manage assigned timelines, deadlines, and expectations, including coordination with internal teams and customer-facing stakeholders where required

Technical Qualification:

Experience in SIEM tools for security alert monitoring, log analysis, agent monitoring, vulnerability detection, file integrity monitoring, and dashboard review

Experience of application vulnerability assessment for web applications, APIs, and mobile applications using tools such as Burp Suite, OWASP ZAP, MobSF, and related security testing tools

Proficient in understanding SOC operations, security monitoring, incident response, alert triage, escalation, and incident documentation

Proficient in reviewing and analyzing logs from Windows, Linux, firewall, endpoint, email security, cloud, and network security platforms

Proficient in validating vulnerability scan results, identifying false positives, assigning severity, preparing remediation recommendations, and verifying fixes through retesting

Proficient in preparing clear security reports, incident summaries, vulnerability assessment reports, and remediation follow-up updates for technical and non-technical stakeholders

Knowledge of common security events such as failed logins, privilege changes, malware alerts, suspicious process execution, phishing attempts, unauthorized access, and data exposure indicators

Knowledge of the incident response lifecycle, including detection, analysis, containment, remediation, recovery, and lessons learned

Knowledge of server vulnerability assessment for Linux and Windows servers using tools such as Nessus, Rapid7 InsightVM, Wazuh vulnerability detection, or similar vulnerability scanning tools

Knowledge of OWASP Top 10, common application security issues, exploitation concepts, risk rating, and remediation guidance

Understanding of network security concepts, including TCP/IP, DNS, HTTP/HTTPS, VPN, firewall rules, ports, protocols, and common attack techniques

Understanding of operating system hardening, patch management, insecure configurations, exposed services, weak protocols, and secure baseline checks

Familiarity with cloud security fundamentals for AWS, Azure, or GCP, including basic logging, identity, access, and configuration review concepts

Personal Skills:

Ability to communicate well verbally and in writing with various levels from junior developers to executive staff

Ability to stay calm, professional in troubleshooting and resolving support issues

Ability to quickly learn new concepts and software

Ability to work in a team environment

Ability to adjust tasks and schedule and adapt to changing priorities

Ability to analyze security issues carefully and make practical decisions based on risk and impact

Ability to take ownership of assigned work, follow up with teams, and ensure security issues are tracked to closure

Education and Work Experience:

Background in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred

The candidate should have over 1 year of relevant work experience in IT security, SOC operations, vulnerability assessment, or a related area

Certification in IT Security such as CEH, CompTIA Security+, Certified SOC Analyst (CSA), or any related certification will be an added advantage

Apply on Creative Capsule