Position Overview
This position will focus on identifying security risks, monitoring vulnerabilities, improving security controls, and helping ensure that our applications, networks, cloud environments, and business data are protected.
Candidate Requirements
High fluency in English C1 and above (speaking, reading, and listening) — mandatory.
The ideal candidate has a broad understanding of network security, web and application security, data security, access control, vulnerability management, incident response, and cloud security.
This is a technical position requiring strong analytical and problem-solving skills. The candidate should be comfortable investigating security issues, identifying weaknesses, understanding how systems can be compromised, and working with developers and IT personnel to implement practical solutions.
The candidate does not need to be a software developer, but should understand how web applications, APIs, databases, networks, operating systems, and cloud environments work.
Network Security
Experience or knowledge in:
- Network security and infrastructure.
- TCP/IP, DNS, HTTP/HTTPS, TLS/SSL, firewalls, VPNs, and network segmentation.
- Network monitoring and identifying suspicious activity.
- Vulnerability identification and attack-path analysis.
- Wireless network security.
- Intrusion detection and prevention.
- Network access controls and secure network architecture.
- Investigating and responding to suspected network security incidents.
Web & Application Security
The candidate should be comfortable evaluating internal and customer-facing applications for security risks and working with developers to address vulnerabilities.
Knowledge of common vulnerabilities such as:
- Cross-Site Scripting (XSS)
- SQL Injection
- Cross-Site Request Forgery (CSRF)
- Broken authentication and authorization.
- Broken access control.
- Insecure API endpoints.
- Improper input validation.
- Sensitive data exposure.
- Insecure file handling.
- Misconfigured security controls.
- Other common OWASP vulnerabilities.
Experience with authentication, authorization, sessions, cookies, tokens, credentials, API security, and secure handling of user input is important.
Data Security
- Protect sensitive customer, employee, financial, and business data.
- Review how sensitive information is stored, transmitted, and accessed.
- Evaluate permissions and identify unnecessary access.
- Understand encryption and secure data-transfer practices.
- Identify potential unauthorized access or unusual data activity.
- Work with database and development teams to improve data security.
- Ensure sensitive information is not unnecessarily exposed through applications, APIs, reports, or databases.
Identity & Access Management
- Review user permissions and access levels.
- Identify excessive or unnecessary privileges.
- Support least-privilege access practices.
- Understand authentication and authorization controls.
- Review privileged accounts and account activity.
- Support multi-factor authentication (MFA).
- Assist with secure employee onboarding and offboarding processes.
Vulnerability Management & Security Testing
The candidate should be able to identify, assess, prioritize, document, and help remediate vulnerabilities.
Responsibilities may include:
- Vulnerability scanning and security assessments.
- Web application and API security testing.
- Network and configuration reviews.
- Authentication and access-control testing.
- Security-focused code or architecture reviews.
- Penetration-testing coordination or execution where qualified.
- Tracking remediation efforts and retesting security fixes.
- Monitoring newly discovered vulnerabilities affecting company systems.
All security testing must be performed on authorized company systems and according to established procedures.
Cloud Security
Experience with cloud security is preferred, particularly:
- AWS and/or Azure
- Cloud networking.
- Cloud identity and access management.
- Security groups and firewall controls.
- Cloud storage security.
- Encryption.
- Logging and monitoring.
- Cloud application security.
- Cloud configuration reviews.
The candidate should understand the security risks associated with improperly configured cloud resources.
Security Monitoring & Incident Response
- Monitor security alerts and investigate suspicious activity.
- Investigate and document potential security incidents.
- Determine the scope and potential impact of security events.
- Assist with containment, remediation, and recovery.
- Participate in post-incident analysis.
- Recommend improvements to prevent similar incidents.
- Maintain appropriate security logs and documentation.
The candidate should be comfortable investigating incidents methodically and logically, rather than making assumptions about the cause.
Secure Software Development
The Security Specialist will work closely with developers to improve application security.
Experience or understanding of:
- Secure application architecture.
- Secure coding practices.
- API security.
- Authentication and authorization.
- Secure data handling and storage.
- Security testing throughout the development lifecycle.
- Identifying and communicating vulnerabilities to developers.
- Recommending practical remediation strategies.
Experience with PHP, Laravel, SQL, JavaScript, APIs, or other web technologies is beneficial.
Security Tools & Technologies
Experience with security tools in areas such as:
- Vulnerability scanners.
- Network monitoring.
- IDS/IPS.
- Web and API security testing.
- SIEM platforms.
- Endpoint security.
- Firewalls.
- Packet analysis.
- Security logging.
- Penetration-testing tools.
- Encryption and credential-security technologies.
Specific tools are less important than the ability to understand findings and determine the appropriate response.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Networking, or a related field, or equivalent practical experience.
- Strong understanding of information security principles.
- Strong analytical and problem-solving skills.
- Understanding of network, web, application, and data security.
- Understanding of authentication, authorization, access control, and encryption.
- Familiarity with common vulnerabilities and attack methods.
- Ability to investigate technical problems and security events.
- Ability to clearly document and communicate security findings.
- Ability to communicate effectively with both technical and non-technical teams.
- Strong attention to detail.
- Willingness to continuously learn about new technologies and security threats.
Preferred Qualifications
Certifications and experience in any of the following are a plus:
- CompTIA Security+
- CompTIA Network+
- CEH
- OSCP
- CISSP
- GIAC certifications
- AWS or Azure security certifications
- Penetration testing
- Vulnerability management
- Incident response
- Network security
- Web application or API security
- Cloud security
- Database security
- SIEM and security monitoring
- Digital forensics
- Secure software development
Certifications are beneficial, but practical technical ability and security knowledge are more important than certifications alone.
Programming & Scripting
Programming or scripting experience is a plus, particularly:
- Python
- PowerShell
- Bash
- JavaScript
- PHP
- SQL
The candidate does not need to be a professional developer, but the ability to write or understand scripts can be valuable for security testing, automation, and investigation.
Problem-Solving & Critical Thinking
We are looking for someone who can think like an attacker while working defensively.
The ideal candidate can:
- Identify weaknesses others may overlook.
- Understand how vulnerabilities can interact.
- Investigate unusual activity.
- Separate symptoms from root causes.
- Evaluate the likelihood and impact of security risks.
- Prioritize issues based on actual business risk.
- Develop practical remediation strategies.
- Verify that security fixes actually work.
- Ask "What could go wrong?" before problems occur.
Collaboration
The Security Specialist will work closely with:
- Full-stack and backend developers.
- Front-end/UI specialists.
- iOS and Android developers.
- Database and data teams.
- IT and infrastructure personnel.
- Financial and business teams.
- Leadership and other application stakeholders.
The goal is not simply to identify security problems, but to help the organization fix them in practical ways.
The candidate should be able to clearly explain:
- What the security risk is.
- Why it matters.
- How it could potentially be exploited.
- What systems or data could be affected.
- How the risk can be reduced or eliminated.
- How to verify that the solution works.
Work Style & Expectations
The ideal candidate is:
- Analytical and detail-oriented.
- Naturally curious and persistent when troubleshooting.
- Comfortable investigating complex technical problems.
- Able to communicate technical risks clearly.
- Comfortable working with developers and IT personnel.
- Able to balance security requirements with practical business needs.
- Willing to take ownership of security issues.
- Continuously interested in learning as technologies and threats evolve.
Work Environment
- Primarily in-office.
- Some occasional remote flexibility may be available.
- Close collaboration with development and IT teams.
- Exposure to internal applications, networks, databases, cloud environments, and business systems.
- Security testing and monitoring must always be performed within authorized systems and established procedures.
What Success Looks Like
A successful Security Specialist will:
- Identify vulnerabilities before they become significant incidents.
- Improve the security of networks, applications, cloud environments, and business systems.
- Help protect sensitive company and customer data.
- Improve access controls and authentication practices.
- Help developers build more secure applications.
- Investigate and respond effectively to security incidents.
- Establish practical security standards and procedures.
- Reduce the organization's overall security risk.
- Become a trusted technical resource for security-related decisions.
- Continuously improve the organization's security posture.