Skip to content

Open nowPosted 47 days ago

Security Engineer

Workable (global search)108,016 open roles

Where
Sri Lanka
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerWorkable (global search) · Sri Lanka
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 47 days ago

Workable (global search) median: 7 days open

The posting

Security Engineer

GXA is seeking a highly capable Security Engineer to support the delivery and operation of our gShield security services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.

The Security Engineer serves as a Tier 3 escalation point for active security and technical issues and plays a key role in operating and improving the gShield security stack across client environments. This individual will work closely with the InfoSec Manager (vISM), vCISO, SOC, Centralized Services, onboarding teams, and internal technical leadership to strengthen client security posture and support rapid, effective response to threats and technical issues.

This is an execution-focused role for someone who is comfortable working across security and the underlying IT infrastructure that supports it. The ideal candidate understands how networks, servers, identity, endpoints, cloud services, and security controls work together and can troubleshoot across these layers when the root cause is not immediately clear.

This person should be comfortable working in live security events, analyzing alerts and evidence, troubleshooting infrastructure and security issues, executing or supporting remediation, and helping maintain the operational excellence of GXA's security program.

Key Responsibilities

Incident Response

  • Serve as a Tier 3 escalation point for active security incidents, including business email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
  • Lead technical analysis during incident response and war room events, including log review, IOC hunting, attacker activity analysis, and lateral movement tracing.
  • Execute containment and eradication actions such as endpoint isolation, session revocation, credential resets, access restriction, and other appropriate remediation actions.
  • Troubleshoot incidents that may span multiple technical layers, including identity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
  • Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
  • Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
  • Communicate clearly during active incidents, including what is known, what has been investigated, what actions have been taken, what is being investigated next, and where additional support is required.
  • Produce accurate incident timelines, technical findings, and evidence packages for vCISO review and client-facing follow-up.

Tool Operations & Security Stack Support

  • Operate daily within the gShield toolstack, including platforms such as Huntress, Microsoft Defender for Endpoint (MDE), Cyrisma, DNSFilter, SIEM, and related security technologies.
  • Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
  • Support SIEM operations including query development, alert review, log analysis, investigation, and rule tuning.
  • Assist in tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
  • Monitor for security gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
  • Correlate information across identity, endpoint, network, server, and cloud sources when investigating security issues.
  • Work within established security standards, baselines, and operational policies defined by the security team and vITMs.

Infrastructure & Security Engineering

  • Apply security principles across on-premises, cloud, and hybrid client environments.
  • Troubleshoot security issues involving underlying infrastructure components such as Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
  • Understand how identity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
  • Support security hardening of Windows, endpoint, identity, network, and cloud environments.
  • Assist with identity and access security including MFA, Conditional Access, privileged access, authentication, authorization, and account security.
  • Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
  • Work effectively with technologies that may be unfamiliar by researching, testing, validating, and documenting appropriate solutions while escalating appropriately when additional expertise is required.

Client Delivery Support

  • Execute technical remediation items identified through MRMMs, preventative actions, vulnerability reviews, and security recommendations.
  • Support gShield deliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
  • Assess vulnerabilities based not only on severity scores but also on asset criticality, exposure, exploitability, existing controls, and business impact.
  • Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifying appropriate compensating controls when immediate remediation is not possible.
  • Validate remediation and confirm that identified risks have been appropriately addressed.
  • Act as a quality assurance resource for client onboarding into the gShield toolstack, while execution remains with onboarding and Centralized Services teams.
  • Assist with client hardening efforts and follow-through on security improvement actions across managed environments.
  • Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.

Internal Security Posture

  • Support remediation of internal GXA security backlog items, including POA&M-related work.
  • Assist with rollout and support of phishing-resistant MFA, passkeys, and other internal security initiatives.
  • Contribute to security engineering efforts related to Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Help improve internal security controls, tool effectiveness, and technical enforcement mechanisms.
  • Support security hardening and remediation across internal identity, endpoint, server, network, and cloud environments where needed.

Documentation & Process Improvement

  • Write and maintain security engineering SOPs, runbooks, detection playbooks, troubleshooting procedures, and response procedures related to gShield operations and incident response.
  • Document technical findings, repeatable procedures, remediation steps, and lessons learned from incidents and tool operations.
  • Clearly document what was identified, what actions were taken, why those actions were taken, and what follow-up is required.
  • Collaborate with security leadership and technical stakeholders on process improvements, skill development, and automation opportunities.
  • Contribute technical depth to broader security documentation where needed, while recognizing that ownership of policy, standards, and governance documentation remains with security leadership and related functions.

Qualifications

  • 5–7+ years of experience across cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong technical foundation across IT infrastructure and security, with practical understanding of networking, servers, identity, endpoints, cloud services, and how these technologies interact.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of infrastructure technologies and concepts such as Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Strong hands-on experience with security engineering, threat detection, security operations, incident investigation, or incident response workflows.
  • Experience working with security platforms such as Microsoft Defender, Huntress, DNSFilter, SIEM solutions, vulnerability management tools, and endpoint security technologies.
  • Ability to investigate security alerts, analyze logs, trace attacker activity, determine scope, and support containment and remediation.
  • Familiarity with common attack types including phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Experience supporting security controls within Microsoft 365, Microsoft Entra ID, endpoint, and cloud environments.
  • Understanding of vulnerability management and remediation, including prioritization based on technical severity, exposure, asset criticality, and business risk.
  • Ability to independently troubleshoot technical problems, develop and test hypotheses, identify root causes, and recognize when escalation or additional expertise is appropriate.
  • Ability to remain calm, structured, and methodical during active incidents, outages, and technical escalations, including situations where the root cause is initially unknown.
  • Strong verbal and written communication skills, with the ability to provide concise technical updates explaining current status, actions completed, current investigation, and next steps.
  • Strong documentation skills and ability to write clear technical procedures and findings.
  • Ability to acknowledge knowledge gaps, research unfamiliar technologies, learn quickly, and apply new knowledge safely in production environments.
  • Strong collaboration skills with security, infrastructure, service delivery, leadership, and client stakeholders.

Preferred Qualifications

  • 1-2 years in a Cybersecurity role.
  • Experience in an MSP, MSSP, or multi-client environment.
  • Prior experience in systems administration, network engineering, infrastructure engineering, or a similarly hands-on IT role before or alongside cybersecurity responsibilities.
  • Experience supporting both traditional on-premises infrastructure and cloud environments.
  • Familiarity with Intune, Microsoft Defender, Microsoft Sentinel, AppLocker, ThreatLocker, and RMM-based scripting or automation.
  • Experience with Azure security and infrastructure; AWS or other cloud-platform experience is also valuable.
  • Experience with Windows Server, Active Directory, virtualization platforms such as VMware/Hyper-V, firewall technologies, and network troubleshooting.
  • Understanding of CIS benchmarks, security hardening standards, Zero Trust principles, and configuration drift monitoring.
  • Experience supporting vulnerability remediation and technical aspects of vCISO or managed security programs.
  • Experience with scripting or automation using technologies such as PowerShell, APIs, or RMM platforms.
  • Security certifications such as Security+, CySA+, SC-200, SC-300, AZ-500, GCIH, GCIA, or similar are a plus.
  • Infrastructure/network certifications or equivalent practical experience, such as CCNA, Microsoft infrastructure certifications, Azure Administrator, or similar, are also valuable.

Success in This Role Looks Like

  • Security incidents and technical escalations are handled quickly, accurately, calmly, and with strong technical discipline.
  • The engineer can troubleshoot across security, identity, endpoint, server, network, and cloud layers rather than relying solely on security tools or another technical team.
  • Alerts and risks surfaced by the toolstack are investigated and acted on consistently.
  • Client security remediation items are executed thoroughly, validated, and completed on time.
  • Vulnerabilities are evaluated based on actual risk and business context, and remediation is followed through to completion.
  • gShield tooling is tuned, effective, and operationally reliable.
  • Clients and internal stakeholders receive clear, concise updates during incidents and technical escalations, even when the root cause has not yet been determined.
  • Technical problems are approached methodically, with appropriate investigation, testing, documentation, and escalation when necessary.
  • The engineer demonstrates ownership, curiosity, sound technical judgment, and willingness to learn unfamiliar technologies rather than being limited to a narrow security specialty.
  • Documentation, SOPs, troubleshooting procedures, and response playbooks are clear, useful, and continuously improving.
  • Internal and client security posture improves through strong technical follow-through.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.