Security Engineer (Infrastructure and Cloud) – Relocation provided at Wypoon Technologies

on-site · permanent · Visa sponsorship

Apply for this role at Wypoon Technologies

Responsibilities:
- Own the end-to-end vulnerability management lifecycle for cloud and infrastructure assets: discovery, scanning, triage, prioritisation and closure.
- Define scanning scope, validate findings, assign owners, track remediation and verify fixes; manage exceptions and compensating controls.
- Design, implement and maintain secure configuration baselines and hardening standards for Azure, AWS, Windows, Linux, network devices and security appliances.
- Produce configuration checks, operational playbooks, evidence requirements and runbooks to support remediation and audits.
- Monitor control deployment and telemetry; work with SOC/IR to ensure alerts and logs support detection and investigation.
- Review infrastructure and cloud changes, conduct technical risk assessments and drive security projects to reduce exposure.
- Maintain asset records in CMDB/asset management tools and collaborate with architects to align controls with security architecture.

Requirements:
- 5+ years' hands-on experience in enterprise security, cloud or infrastructure security with proven vulnerability management expertise.
- Practical experience with Azure and AWS, vulnerability scanning tools and secure configuration frameworks (CIS, ISO27001, NIS2 desirable).
- Strong scripting/automation skills (PowerShell, Python, KQL) and familiarity with IaC (Terraform) to automate checks and remediations.
- Experience integrating with SIEMs, ticketing/ITSM tools (e.g. ServiceNow) and security solutions (Qualys, Microsoft Defender, Sentinel).
- Good communication and stakeholder-management skills to translate technical findings into actionable remediation plans.
- Ability to work across hybrid environments (on-prem/cloud) and support audits and compliance activities.