Senior Security Engineer/Architect - Linux Infrastructure (On-Prem)
Summary
Design and build an on-premise Linux security stack: SIEM, logging pipeline, EDR, and SOC workflows using Grafana, Elasticsearch, and open-source tools.
Want to make an impact? We offer that
Due to continued growth, we are hiring Security Engineer/Architect with deep Linux expertise to design and build our on-premise security monitoring capability from the ground up. This is a hands-on engineering and architecture role (not a cloud role nor a Windows role).
We are seeking candidates with strong Linux expertise, experience working with SIEM platforms, and an interest in architecting scalable logging and detection solutions rather than solely maintaining existing infrastructure.
Key Responsibilities:
Design and build a centralised logging pipeline: aggregate logs from across the estate into a SIEM/SOC/NOC-style monitoring layer.
Architect and implement the security monitoring stack using Grafana and Elasticsearch (or equivalent open-source stack).
Deploy and manage EDR (Endpoint Detection & Response) across the Linux estate.
Own SIEM strategy: correlation rules, alerting thresholds, dashboards, and incident triage workflows.
Maintain and harden pure Linux systems (RHEL Derivatives, Debian Derivatives) - no Windows environments involved.
Support on-premise server infrastructure and virtualisation platforms (explicitly no cloud/hybrid-cloud scope).
Manage and configure firewalls, network segmentation, and security rules.
Lead incident response, root cause analysis, and vulnerability assessments.
Troubleshoot system-level issues across performance, networking, and configuration.
Assist with patching, upgrades, and system health checks across the fleet.
Requirements:
Strong hands-on Linux expertise (RHEL, Ubuntu, CentOS, Debian derivatives) - Windows experience not required
Proven experience building or architecting a SIEM/logging platform (Grafana, Elasticsearch/ELK stack, or similar)
Hands-on experience deploying and managing EDR solutions on Linux endpoints
Strong background in on-premise infrastructure
Working knowledge of firewalls and networking (host-based, proprietary and open-source appliances)
Solid understanding of core networking protocols (TCP/IP, DNS, DHCP, routing)
Demonstrated cybersecurity experience: patching, auditing, threat mitigation, compliance
Experience setting up or running a SOC/NOC function, or centralising logs into one
Disaster recovery experience - configuration, storage, hosts
Excellent troubleshooting skills, comfortable working independently at a senior/architect level
Opportunity type: Initial 6-month contract, Hybrid in Dublin
Start date: ASAP