- Company Name
- dotOcean
- Job Title
- dotOcean is looking for a Cyber Security Engineer
- Job Description
-
**Job Title**
Cyber Security Engineer
**Role Summary**
Secure and harden web, network, and system environments in a highly regulated, autonomous‑systems context. Collaborate with DevOps, IT, and engineering teams to detect, analyze, and remediate vulnerabilities, automate security controls, and maintain compliance with ISO 27001, NIS2, and related standards.
**Expectations**
- Bachelor’s degree in IT, Computer Science, Cyber Security, or equivalent.
- 2‑3 years of professional experience as a Cyber‑Security Engineer or in a comparable role.
- Security‑first mindset with proficiency in risk assessment, mitigation, and resilience planning.
- Strong grasp of LAN/WAN topologies, firewalls, EDR, endpoint hardening, Windows/Linux hardening, account and access management, TLS/PKI, and vulnerability scanning tools.
- Familiarity with SIEM platforms and security risk‑management processes.
- Understanding of ISO/IEC 27001, NIS2, and experience with related audits or certifications.
- Experience with container technologies (Docker, Kubernetes) and cloud environments is a plus.
- CEH or similar security certifications valued but not mandatory.
**Key Responsibilities**
- Conduct proactive vulnerability assessments and penetration testing across network, system, and application layers.
- Identify root causes, perform root‑cause analysis, and implement practical remediation plans.
- Automate security monitoring and controls through scripts, CI/CD pipelines, and tooling integrations.
- Draft, review, and enforce security policies, procedures, and standards.
- Support ISO 27001 and NIS2 compliance, including audit preparation and remediation.
- Collaborate with DevOps and engineering teams to embed security into development lifecycles.
- Document findings, action items, and context for stakeholders and maintain security knowledge base.
- Coach team members on security best practices and threat awareness.
**Required Skills**
- Network & system security hardening (firewalls, EDR, hardening baselines).
- Windows & Linux administration.
- Identity & access management (IAM) and privileged account management.
- TLS/PKI, certificate lifecycle management.
- Vulnerability scanners (e.g., Qualys, Nessus, OpenVAS).
- SIEM platforms (Splunk, ELK, QRadar).
- Container security (Docker, Kubernetes) and cloud security (AWS, Azure, GCP).
- Risk assessment and threat modeling.
- Strong communication, documentation, and analytical skills.
**Required Education & Certifications**
- Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related field.
- Certifications such as CEH, CISSP, CompTIA Security+ or equivalent considered a plus.