Cyber Security Engineer
Bectran's infrastructure is central to enterprise credit and financial operations, and ensuring its security is a responsibility we regard with utmost seriousness. We are in search of a highly motivated and proactive Cybersecurity Engineer who takes pride in helping safeguard the systems, data, and personnel that underpin our platform. The successful candidate will possess a strong foundation in cloud security, application security, and endpoint protection, along with a genuine curiosity for identifying and mitigating security risks. This individual will work closely with DevOps, Engineering, and Leadership teams, applying developing technical skills, a collaborative mindset, and effective communication to help strengthen Bectran's security posture.
What You Will Do:
- Assist with administering CrowdStrike Falcon and Microsoft Defender across endpoints and email. Monitor security alerts, help maintain DLP policies, and support employee phishing awareness initiatives and security best practices.
- Support the implementation and maintenance of SAST, DAST, SCA, and CSPM tools within CI/CD pipelines. Participate in secure code reviews and learn secure development practices while collaborating with engineering teams.
- Monitor AWS security services including CloudTrail, GuardDuty, VPC Flow Logs, WAF, and Security Hub. Assist with reviewing suspicious activity and implementing security controls such as IAM permissions, IP allowlists, and WAF rule updates under guidance.
- Review and triage findings from AWS Security Hub, Inspector, and IAM Access Analyzer. Assist with certificate renewals, VPN maintenance, and validating encryption configurations following established procedures.
- Monitor SIEM and IDS/IPS alerts for suspicious activity and escalate potential security incidents. Assist with rule tuning and documentation to improve alert quality and visibility.
- Use Datadog to review security logs, investigate alerts, and assist with monitoring cloud and application environments for unusual activity.
- Track security vulnerabilities (CVEs) affecting the technology stack, assist with remediation efforts, participate in vulnerability assessments, and support incident response activities following documented procedures.
- Support SOC 2 compliance efforts by maintaining documentation, gathering audit evidence, updating security controls, and assisting with security tooling administration and reporting.