Skip to content

Open nowPosted 8 days ago

IT Security Junior Engineer/Engineer

Creative Capsule12 open roles

Where
Goa, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Security Junior Engineer/EngineerCreative Capsule · Goa, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Creative Capsule's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 8 days ago

The posting

This position is responsible for supporting the organization’s security monitoring, incident response, and vulnerability management activities. The role will primarily focus on SOC operations using Wazuh, including monitoring security alerts, reviewing logs, validating incidents, escalating risks, and supporting response actions for issues such as unauthorized access, malware, phishing, suspicious activity, and possible data exposure. You will also support application and server vulnerability assessment activities, including reviewing web applications, APIs, mobile applications, Linux and Windows servers, validating scan results, preparing remediation guidance, and verifying fixes.

Responsibilities:

  • Monitor security events and alerts using Wazuh and other tools such as EDR, firewall, email security, cloud, endpoint, and network security platforms
  • Analyze SIEM alerts, logs, agent data, vulnerability findings, file integrity monitoring events, authentication logs, and security events to identify suspicious activity, unauthorized access, malware, phishing attempts, data exposure, and policy violations
  • Perform initial alert validation, severity assessment, false-positive review, and incident prioritization based on alert context, affected assets, risk level, and business impact
  • Support incident containment and response actions such as blocking malicious indicators, disabling compromised accounts, isolating affected systems, removing malicious emails, revoking suspicious sessions, and validating remediation
  • Track incidents from detection to closure and ensure timely follow-up on investigation, remediation, and preventive actions
  • Perform application vulnerability assessments for web applications, APIs, and mobile applications using automated tools and manual verification where required
  • Perform server vulnerability assessments on Linux and Windows servers to identify missing patches, insecure configurations, exposed services, weak protocols, and known vulnerabilities
  • Review vulnerability scan results, validate findings, remove false positives, assign severity, and prepare clear remediation guidance for application and server teams
  • Track vulnerability remediation status, follow up with owners, verify fixes through retesting, and maintain vulnerability assessment reports
  • Support SIEM rule tuning, alert quality improvement, false-positive reduction, detection use-case creation, dashboard review, and security monitoring improvements
  • Assess the security posture of third-party tools and services before adoption to identify risks and ensure compliance with organizational policies
  • Research emerging security topics and new attack vectors to support continuous improvement of security monitoring and vulnerability assessment practices
  • Manage assigned timelines, deadlines, and expectations, including coordination with internal teams and customer-facing stakeholders where required

Technical Qualification:

  • Experience in SIEM tools for security alert monitoring, log analysis, agent monitoring, vulnerability detection, file integrity monitoring, and dashboard review
  • Experience of application vulnerability assessment for web applications, APIs, and mobile applications using tools such as Burp Suite, OWASP ZAP, MobSF, and related security testing tools
  • Proficient in understanding SOC operations, security monitoring, incident response, alert triage, escalation, and incident documentation
  • Proficient in reviewing and analyzing logs from Windows, Linux, firewall, endpoint, email security, cloud, and network security platforms
  • Proficient in validating vulnerability scan results, identifying false positives, assigning severity, preparing remediation recommendations, and verifying fixes through retesting
  • Proficient in preparing clear security reports, incident summaries, vulnerability assessment reports, and remediation follow-up updates for technical and non-technical stakeholders
  • Knowledge of common security events such as failed logins, privilege changes, malware alerts, suspicious process execution, phishing attempts, unauthorized access, and data exposure indicators
  • Knowledge of the incident response lifecycle, including detection, analysis, containment, remediation, recovery, and lessons learned
  • Knowledge of server vulnerability assessment for Linux and Windows servers using tools such as Nessus, Rapid7 InsightVM, Wazuh vulnerability detection, or similar vulnerability scanning tools
  • Knowledge of OWASP Top 10, common application security issues, exploitation concepts, risk rating, and remediation guidance
  • Understanding of network security concepts, including TCP/IP, DNS, HTTP/HTTPS, VPN, firewall rules, ports, protocols, and common attack techniques
  • Understanding of operating system hardening, patch management, insecure configurations, exposed services, weak protocols, and secure baseline checks
  • Familiarity with cloud security fundamentals for AWS, Azure, or GCP, including basic logging, identity, access, and configuration review concepts

Personal Skills:

  • Ability to communicate well verbally and in writing with various levels from junior developers to executive staff
  • Ability to stay calm, professional in troubleshooting and resolving support issues
  • Ability to quickly learn new concepts and software
  • Ability to work in a team environment
  • Ability to adjust tasks and schedule and adapt to changing priorities
  • Ability to analyze security issues carefully and make practical decisions based on risk and impact
  • Ability to take ownership of assigned work, follow up with teams, and ensure security issues are tracked to closure

Education and Work Experience:

  • Background in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred
  • The candidate should have over 1 year of relevant work experience in IT security, SOC operations, vulnerability assessment, or a related area
  • Certification in IT Security such as CEH, CompTIA Security+, Certified SOC Analyst (CSA), or any related certification will be an added advantage
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Creative Capsule's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Creative Capsule's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Creative Capsule's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.