استخدام Senior DevSecOps Engineer (Security Infrastructure)
شرح موقعیت شغلی
About the Role
TAPSI is looking for a Senior DevSecOps Engineer to own the security infrastructure that protects our applications, our privileged access, and our endpoints. This is a hands-on role focused on the implementation, tuning, and day-to-day operation of the core defensive controls our business relies on: Web Application Firewalls (WAF), Privileged Access Management (PAM), Endpoint Protection, and Data Loss Prevention (DLP).
You will be the technical owner who makes these platforms genuinely effective — not just deployed, but well-configured, well-tuned, and continuously maintained. You will reduce our attack surface, control who can access what and how, keep our endpoints defended, and prevent sensitive data from leaving the organization. You will work closely with infrastructure, IT, and application teams to roll out and operate these controls without getting in the way of the business.
Responsibilities
Web Application Firewall (WAF):
- Implement, configure, and maintain the WAF across our web applications and APIs, protecting against the OWASP Top 10 and other application-layer threats.
- Design and continuously tune WAF rule sets, custom rules, and rate-limiting policies to maximize protection while minimizing false positives and business impact.
- Perform virtual patching to rapidly mitigate newly discovered vulnerabilities ahead of code fixes.
- Onboard new applications and services behind the WAF, and manage WAF policy as part of the deployment lifecycle.
- Monitor WAF alerts and logs, investigate blocked and suspicious traffic, and continuously improve detection efficacy.
Privileged Access Management (PAM):
- Implement, configure, and maintain the PAM platform
- Onboard privileged accounts across servers, databases, network devices, and applications, and manage their full lifecycle.
- Enforce least-privilege and just-in-time (JIT) access models, and approval workflows for privileged sessions.
- Enable privileged session monitoring and recording, and support investigations and audits with reliable access records.
- Integrate PAM with identity providers and directory services, and continuously reduce standing privileged access.
Endpoint Protection:
- Maintain and operate the Endpoint Protection (EPP/EDR) solution across the organization’s endpoints and servers.
- Manage protection policies, exclusions, agent health, and coverage, ensuring endpoints are consistently protected and up to date.
- Triage and respond to endpoint alerts and detections, escalating and coordinating containment for confirmed threats.
- Continuously tune detection and prevention policies to balance security with performance and usability.
Data Loss Prevention (DLP):
- Maintain and operate the DLP solution, keeping data-protection policies aligned with the organization’s classification and compliance requirements.
- Tune DLP rules and detection patterns to accurately identify sensitive data while minimizing false positives.
- Triage DLP incidents, investigate potential data-exfiltration events, and coordinate response and remediation.
- Report on DLP and data-protection posture, and recommend improvements to policies and controls over time.
Cross-cutting & Operations:
- Integrate WAF, PAM, Endpoint, and DLP telemetry into central monitoring/SIEM, and support alerting, dashboards, and incident response.
- Maintain configuration standards, runbooks, and documentation for all owned platforms, and manage upgrades, patching, and vendor coordination.
- Support compliance and audit activities with evidence, reporting, and control validation.
- Partner with infrastructure, IT, and application teams to roll out controls smoothly and keep them effective as the environment evolves.
Requirements
- 5+ years of experience in security engineering, security operations, or infrastructure security, with hands-on ownership of enterprise security tooling. WAF administration experience is main requirement.
- Strong hands-on experience implementing and maintaining a WAF (e.g. F5 and Fortiweb), including rule tuning and false-positive management.
- Solid experience with a PAM solution
- Experience operating an Endpoint Protection / EDR platform at scale.
- Experience maintaining a DLP solution, including policy tuning and incident triage.
- Strong understanding of networking, web protocols, identity and access management, and common application-layer attacks.
- Comfort with scripting/automation (e.g. Python, Bash, PowerShell) to operate and integrate these platforms.
- A methodical, operations-minded approach with strong incident-handling and troubleshooting skills, and clear communication.
Nice to Have
- Experience integrating security controls with a SIEM/SOAR and building detection and response workflows.
- Familiarity with cloud environments, Kubernetes, and securing containerized/microservices workloads.
- Exposure to identity providers and directory services (e.g. Keycloak/Authentik, LDAP, SSO) and to compliance frameworks (e.g. ISO 27001, SOC 2).
- Experience with secrets management and integrating PAM with DevOps pipelines.
مهارتهای مورد نیاز
- WAF
- siem
- Python
حداقل سابقه کار
- سه تا شش سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست