Point your AI agent at freehire and let it find you a job.

Get the CLI →

Название скрыто (Fintech)

NewBe an early applicant

Jun/Mid Information Security Engineer

Discussion

Summary

A proprietary algorithmic trading firm (200+ staff, 70% technical) is hiring a junior/mid Information Security Engineer to own day-to-day vulnerability management (scanning, triage, remediation tracking) and security monitoring (log pipeline, detection rules, alert triage, on-call, incident support). Linux, networking, Python/Bash and Git are core; SIEM/scanner experience is a plus.

We are a proprietary algorithmic trading firm. Our team manages the full trading cycle, from software development to creating and coding strategies and algorithms.

Our trading operations cover key exchanges. The firm trades across a broad range of asset classes, including equities, equity derivatives, options, commodity futures, rates futures, etc. We employ a diverse and growing array of algorithmic trading strategies, utilizing both high- and medium-frequency trading approaches.

We’re a team of 200+ professionals, with a strong emphasis on technology—70% are technical specialists in development, infrastructure, testing, and analytics spheres. The remaining part of the team supports our business operations, such as Risks, Compliance, Legal, Operations, and more.

With a strong focus on innovation and performance, BHFT is actively expanding its presence in traditional financial markets. We value a results-driven culture, emphasizing collaboration, transparency, and constant improvement, all while offering the flexibility of remote work and a globally distributed team.

Job Description

We're looking for an Information Security Engineer to join our security team and take ownership of two core operational functions: vulnerability management and security monitoring. You'll be the person who keeps our detection and remediation processes running day-to-day — triaging findings, tuning alerts, chasing fixes, and helping the team respond when something goes wrong.

What You'll Do

Vulnerability Management

  • Operate our vulnerability scanner: maintain coverage, manage scan schedules, and keep agents/engines healthy.
  • Run weekly triage of findings — assess severity × exposure, deduplicate results, and assign issues to owning teams.
  • Track remediation against SLAs, follow up with teams, verify fixes, and re-scan to confirm closure.
  • Monitor vulnerability feeds and vendor advisories (GitLab, Ubuntu, network equipment, key dependencies) and flag time-critical patches.
  • Maintain vulnerability metrics: open criticals, finding age, and mean time to patch.

Security Monitoring

  • Operate our central log pipeline: onboard new log sources, monitor shipper health, and manage retention.
  • Maintain and tune detection rules and alerts (authentication anomalies, firewall changes, privileged actions, exchange-account events).
  • Triage security alerts, escalate according to playbooks, and participate in the on-call duty rotation.
  • Support incident response: evidence collection, timeline reconstruction, and post-incident follow-up.

Qualifications

  • 1–3 years of experience in a security, DevOps, or systems administration role.
  • Solid Linux fundamentals: processes, users/permissions, logs, systemd, SSH.
  • Networking basics: TCP/IP, DNS, firewalls, VPN concepts.
  • Understanding of the vulnerability lifecycle: CVE, CVSS, patching vs. mitigating.
  • Scripting ability in Python or Bash (automating a report, parsing a log, calling an API).
  • Comfortable working with Git and merge-request workflows.

Nice to Have

  • Hands-on experience with a vulnerability scanner (Rapid7, Nessus, OpenVAS, Qualys).
  • Hands-on experience with a log/SIEM stack (Graylog, ELK, Wazuh, Splunk).
  • Experience with Ansible or another configuration-management tool.
  • Basic familiarity with containers/Kubernetes.

Additional Information

We Offer

Work in a modern IT company — no bureaucracy or legacy systems. Real opportunities for professional growth and to make your mark. Fully remote work from anywhere in the world, on a flexible schedule. Compensation for health insurance, sports, professional development, and more.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available