RediMinds, Inc

RediMinds, Inc

·9 days ago

Security apps & operations engineer

Apply now

Location

remote, United States

Commitment

Full Time

Level

Junior (<2 years)

Required skills

Application SecurityDevSecOpsCloud SecuritySIEMSOC OperationsAWSAzureGCPVulnerability ManagementPythonBashPowerShellIAMThreat ModelingIncident ResponseNetworking

Job Description

Role Summary

We are looking for a motivated Security Apps & Operations Engineer to join our security team. In this role you will be responsible for securing our applications and cloud infrastructure, operating and tuning our SIEM/SOC tooling, and embedding security practices into the software development lifecycle (DevSecOps). You will work cross-functionally with engineering, IT, and compliance teams to identify risks, respond to threats, and continuously improve our security posture. This is a rotational shift role with overlap with US hours.

Key Responsibilities

Application Security & DevSecOps

  • Integrate security tooling (SAST, DAST, SCA) into CI/CD pipelines and enforce security gates.
  • Conduct vulnerability assessments and coordinate remediation with development teams.
  • Perform threat modeling and security code reviews for new features and major changes.
  • Maintain and improve application security standards, policies, and secure coding guidelines.
  • Track and report on vulnerability metrics, SLA adherence, and risk exposure.

Cloud Security (AWS / Azure / GCP)

  • Monitor and enforce cloud security configurations using tools such as AWS Security Hub, Azure Defender, or GCP Security Command Center.
  • Manage Identity and Access Management (IAM) policies, least-privilege principles, and privilege access controls across cloud environments.
  • Perform cloud infrastructure security reviews and ensure compliance with CIS Benchmarks and organizational standards.
  • Respond to cloud security incidents and misconfigurations, driving root-cause analysis and remediation.

SIEM & SOC Operations

  • Operate, tune, and maintain SIEM platforms (e.g., Splunk, Microsoft Sentinel, or equivalent).
  • Develop and maintain detection rules, correlation queries, and alerting logic to reduce noise and improve fidelity.
  • Triage and investigate security alerts; escalate confirmed incidents following the IR playbook.
  • Create dashboards and reports to surface key security metrics for stakeholders.
  • Participate in on-call rotation for security incident response.

General Operations

  • Support audit activities (SOC 2, ISO 27001, or similar) by providing evidence and remediating findings.
  • Document runbooks, playbooks, and standard operating procedures.
  • Stay current with the threat landscape, emerging CVEs, and security tooling developments.
  • Contribute to day-to-day security operation (monitoring)

Requirements

Experience & Education

  • 2 – 3 years of hands-on experience in an application security, security operations, or similar role.
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.

Technical Skills

  • Proficiency with at least one major cloud platform (AWS, Azure, or GCP) and its native security services.
  • Experience with SIEM platforms (Splunk, Sentinel, Elastic Security, or similar) — including writing queries/rules (SPL, KQL, etc.).
  • Familiarity with DevSecOps tooling: SAST (e.g., Semgrep, SonarQube), DAST (e.g., OWASP ZAP, Burp Suite), SCA (e.g., Snyk, Dependabot).
  • Understanding of OWASP Top 10, CVE scoring, and vulnerability management workflows.
  • Scripting ability in Python, Bash, or PowerShell for automation and tooling.
  • Working knowledge of networking concepts (TCP/IP, DNS, TLS, firewalls, proxies).

Soft Skills

  • Clear written and verbal communication — able to explain technical risk to non-technical stakeholders.
  • Detail-oriented with strong analytical and problem-solving skills.
  • Collaborative team player who thrives in a fast-paced, cross-functional environment.

Preferred Qualifications

  • Industry certifications such as CompTIA Security+, AWS Security Specialty, GCIA, GCSA, CEH, or equivalent.
  • Experience with container security (Docker, Kubernetes) and infrastructure-as-code security scanning (Terraform, CloudFormation).
  • Familiarity with compliance frameworks: SOC 2, ISO 27001, NIST CSF, or PCI-DSS.
  • Prior exposure to incident response or digital forensics workflows.
  • Experience with ticketing and ITSM platforms (Jira, ServiceNow).

What We Offer

  • Competitive salary and performance-based bonus.
  • Comprehensive health, dental, and vision benefits.
  • Support for professional certifications and continuous learning.
  • Flexible work arrangements.
  • Collaborative, security-first culture where your work has real impact.

Ready to join the team?

Apply now

Similar Jobs: