{"id":1250227,"url":"https://alion.io/job/onapp-security-engineer-middle","title":"Security Engineer, Middle","company":{"id":2128220,"name":"Onapp","domain":"onapp.com","url":"https://alion.io/company/onapp","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"BambooHR","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"contractor","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Bash","optional":false},{"name":"Bitbucket","optional":false},{"name":"CI/CD","optional":false},{"name":"Jenkins","optional":false},{"name":"Linux","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Okta","optional":false},{"name":"OpenVAS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"Semgrep","optional":false},{"name":"SIEM","optional":false},{"name":"Snyk","optional":false},{"name":"SOC 2","optional":false},{"name":"SonarQube","optional":false},{"name":"Splunk","optional":false},{"name":"TCP/IP","optional":false},{"name":"Trivy","optional":false},{"name":"Wazuh","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-08-11T00:00:00Z","employer_posted_date":"2026-08-11","last_verified_at":"2026-10-07T00:22:52Z","board_verified":true,"closed_at":null,"days_open":57,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":57},"description":"Security Engineer\nMid-level\nType of work: Remote\nOpen for candidates contracting from Serbia, Bulgaria, Georgia, Armenia, Romania\nAbout Virtuozzo\nVirtuozzo is a leader in infrastructure software and services for AI and the cloud. The company offers a next-generation OS, orchestration, management, automation, and protection for cloud service providers, SaaS, AI, and the enterprise. Virtuozzo provides mainframe-like efficiency, reliability, and versatility while dramatically lowering cost and complexity.\nAbout the Role\nWe are seeking a mid-level Security Engineer to help protect Virtuozzo’s networks, systems, and data from cyber threats. You will work with global Virtuozzo team members, physical infrastructure, and SaaS systems. You will also play a hands-on role in our ISO/IEC 27001 certification program by operating security controls and producing evidence that demonstrates they are working effectively. You will join an existing team, adding capacity to help us continue supporting the needs of our growing global organization.\nResponsibilities\nOperate and improve vulnerability management by running and tuning scans, triaging findings, tracking remediation with system owners, and maintaining scan evidence.\nMonitor security systems and logs, including SIEM and EDR platforms, to detect, investigate, and respond to security incidents.\nMaintain and configure security tooling, including EDR, SIEM, firewalls, intrusion detection and prevention systems, and MFA and SSO policies.\nSupport identity and access management, including access provisioning, privileged access, and documented periodic access reviews.\nContribute to ISO/IEC 27001 operations, including control implementation, evidence collection, risk register input, and support for internal and external audits.\nAssist with security assessments, penetration-test coordination, and remediation follow-up.\nSupport application security across the software development lifecycle by integrating and operating SAST, DAST, dependency scanning, and container scanning within CI/CD pipelines.\nTriage application-security findings with R&D teams and track remediation.\nHelp secure the build and release chain, including source-repository access, secrets management, artifact signing, and pipeline hardening.\nHelp maintain security policies, procedures, and standards, and track exceptions.\nTrack endpoint fleet security posture across Windows, macOS, and Linux, including MDM enrollment, EDR coverage, and disk encryption.\nParticipate in security-awareness training and educate end users on security best practices.\nTroubleshoot security-related outages and incidents, producing root-cause or post-incident documentation where required.\nWork with the wider IT and Security team to build, document, and implement internal processes and workflows.\nStay up to date with the latest security threats, trends, and technologies.\nRequired Qualifications and Experience\nAt least three years of experience in security engineering, security operations, or systems administration with a strong security focus.\nWorking knowledge of security concepts and tooling, including firewalls, IDS/IPS, SIEM, EDR, and vulnerability scanners.\nSolid networking fundamentals, including TCP/IP, VLANs, routing, VPNs, and firewalling, ideally with hands-on experience.\nExperience with identity and access management, including Active Directory or Microsoft Entra ID and SSO/MFA platforms such as Okta or similar.\nWorking experience with Microsoft 365 and Exchange Online.\nComfortable working with Windows, macOS, and Linux systems.\nUnderstanding of application-security fundamentals, including the OWASP Top 10, secure-coding practices, and vulnerability triage in code and dependencies.\nUnderstanding of security and compliance frameworks such as ISO/IEC 27001, SOC 2, or similar, including what constitutes suitable audit evidence.\nStrong problem-solving skills and attention to detail.\nAbility to work collaboratively within a team.\nStrong written and verbal communication skills in English.\nThe Following Would Be an Advantage\nSecurity certifications such as Security+, SSCP, CEH, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or similar.\nExperience with Qualys, Greenbone/OpenVAS, Wazuh, Splunk, or similar tools.\nExperience with MDM tools such as Hexnode or similar, as well as endpoint hardening.\nSecurity automation experience using Python, Bash, or PowerShell.\nHands-on experience with application-security tools such as SonarQube, Semgrep, Snyk, OWASP ZAP, Trivy, or similar.\nExperience with CI/CD security using Bitbucket Pipelines, Jenkins, or similar tools.\nExperience with secure-SDLC practices, including threat modelling, security code reviews, and secrets scanning.\nExposure to cloud and virtualization platforms and their security models.\nPrevious participation in an ISO/IEC 27001 certification program or customer security audits.\nWhat We Offer\nA role at the forefront of cloud technology with real impact and growth opportunities\nA collaborative environment where your ideas are valued and shipped\nOther perks and engagement opportunities\nShare options\nReferral bonuses\nCertifications and learning opportunities in line with interest and role requirements","description_format":"text","description_chars":5227,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Growth opportunities","Stock options"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-09-25T18:18:03Z"}],"visa":[],"liveness":{"score":60,"band":"ok","label":"Likely open","p_open":1,"p_active":0.805,"p_room":0.75,"age_days":56,"expected_fill_days":71,"reasons":["conf:0","velocity","win:late"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/onapp-security-engineer-middle","json_url":"https://alion.io/job/onapp-security-engineer-middle.json","meta":{"generated_at":"2026-10-07T00:58:37Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1616,"day_limit":5000,"remaining_today":3384,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2128220},"rest":"https://alion.io/mcp/rest/get_company?id=2128220"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fonapp-security-engineer-middle"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fonapp-security-engineer-middle"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fonapp-security-engineer-middle"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/onapp-security-engineer-middle\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fonapp-security-engineer-middle"}]}