Security Apps & Operations Engineer
RediMinds, Inc · 1 day ago
Role Summary
We are looking for a motivated Security Apps & Operations Engineer to join our security team. In this role you will be responsible for securing our applications and cloud infrastructure, operating and tuning our SIEM/SOC tooling, and embedding security practices into the software development lifecycle (DevSecOps). You will work cross-functionally with engineering, IT, and compliance teams to identify risks, respond to threats, and continuously improve our security posture. This is a rotational shift role with overlap with US hours.
Key Responsibilities
Application Security & DevSecOps
-
Integrate security tooling (SAST, DAST, SCA) into CI/CD pipelines and enforce security gates.
-
Conduct vulnerability assessments and coordinate remediation with development teams.
-
Perform threat modeling and security code reviews for new features and major changes.
-
Maintain and improve application security standards, policies, and secure coding guidelines.
-
Track and report on vulnerability metrics, SLA adherence, and risk exposure.
Cloud Security (AWS / Azure / GCP)
-
Monitor and enforce cloud security configurations using tools such as AWS Security Hub, Azure Defender, or GCP Security Command Center.
-
Manage Identity and Access Management (IAM) policies, least-privilege principles, and privilege access controls across cloud environments.
-
Perform cloud infrastructure security reviews and ensure compliance with CIS Benchmarks and organizational standards.
-
Respond to cloud security incidents and misconfigurations, driving root-cause analysis and remediation.
SIEM & SOC Operations
-
Operate, tune, and maintain SIEM platforms (e.g., Splunk, Microsoft Sentinel, or equivalent).
-
Develop and maintain detection rules, correlation queries, and alerting logic to reduce noise and improve fidelity.
-
Triage and investigate security alerts; escalate confirmed incidents following the IR playbook.
-
Create dashboards and reports to surface key security metrics for stakeholders.
-
Participate in on-call rotation for security incident response.
General Operations
-
Support audit activities (SOC 2, ISO 27001, or similar) by providing evidence and remediating findings.
-
Document runbooks, playbooks, and standard operating procedures.
-
Stay current with the threat landscape, emerging CVEs, and security tooling developments.
-
Contribute to day-to-day security operation (monitoring)
Requirements
Experience & Education
-
2 – 3 years of hands-on experience in an application security, security operations, or similar role.
-
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
Technical Skills
-
Proficiency with at least one major cloud platform (AWS, Azure, or GCP) and its native security services.
-
Experience with SIEM platforms (Splunk, Sentinel, Elastic Security, or similar) — including writing queries/rules (SPL, KQL, etc.).
-
Familiarity with DevSecOps tooling: SAST (e.g., Semgrep, SonarQube), DAST (e.g., OWASP ZAP, Burp Suite), SCA (e.g., Snyk, Dependabot).
-
Understanding of OWASP Top 10, CVE scoring, and vulnerability management workflows.
-
Scripting ability in Python, Bash, or PowerShell for automation and tooling.
-
Working knowledge of networking concepts (TCP/IP, DNS, TLS, firewalls, proxies).
Soft Skills
-
Clear written and verbal communication — able to explain technical risk to non-technical stakeholders.
-
Detail-oriented with strong analytical and problem-solving skills.
-
Collaborative team player who thrives in a fast-paced, cross-functional environment.
Preferred Qualifications
-
Industry certifications such as CompTIA Security+, AWS Security Specialty, GCIA, GCSA, CEH, or equivalent.
-
Experience with container security (Docker, Kubernetes) and infrastructure-as-code security scanning (Terraform, CloudFormation).
-
Familiarity with compliance frameworks: SOC 2, ISO 27001, NIST CSF, or PCI-DSS.
-
Prior exposure to incident response or digital forensics workflows.
-
Experience with ticketing and ITSM platforms (Jira, ServiceNow).
What We Offer
-
Competitive salary and performance-based bonus.
-
Comprehensive health, dental, and vision benefits.
-
Support for professional certifications and continuous learning.
-
Flexible work arrangements.
-
Collaborative, security-first culture where your work has real impact.
