Skip to main content
Semaphore

Security Engineer

RemoteSerbia only
Published
Role
Security
Employment
Full-time
Salary not disclosed
Check eligibility

Open to RS only. Set where you work from to check your eligibility.

No BS summary

You will be the technical owner of information security across our infrastructure and internal systems. You will work closely with Engineering, Infrastructure, and our Compliance Manager to turn security and compliance requirements into practical, reliable controls. This is a hands-on role. You will investigate vulnerabilities, operate security monitoring, improve infrastructure and access controls, automate recurring work, and lead technical remediation.

Core skills

Linuxsecuritycloud security

Required skills

PythonBashinfrastructure-as-codeSIEMsecurity-monitoring

Optional skills

WazuhTeleportPAMjust-in-time access systemsSecurity+CISSPCISMGIAC

Required languages

English unknown

What you'll do

  • Run the vulnerability-management lifecycle: scanning, triage, prioritization, remediation, exceptions, and verification.
  • Operate and improve security monitoring and SIEM tooling, including alert quality, dashboards, detection rules, and integrations.
  • Investigate security alerts and lead the technical response to security incidents.
  • Improve the security of Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services.
  • Own technical controls for identity and access management, least privilege, just-in-time access, secrets, and certificates.
  • Automate patching, evidence collection, recurring control checks, and other security operations.
  • Coordinate penetration tests and drive technical findings through remediation and verification.
  • Translate SOC 2 and ISO 27001 control requirements into effective technical implementations.
  • Produce clear technical evidence for internal and external audits in partnership with the Compliance Manager.
  • Maintain security runbooks, system documentation, risk-based priorities, and operational metrics.
  • Help engineering teams make practical security decisions without adding unnecessary process.

What they require

  • Proven ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment.
  • Strong Linux systems, networking, and cloud-security fundamentals.
  • Hands-on experience with vulnerability management, patching, hardening, and remediation at scale.
  • Experience operating SIEM or security-monitoring systems and investigating security events.
  • Practical understanding of IAM, privileged access, secrets management, certificates, and network controls.
  • Ability to automate operational work using Python, Bash, infrastructure-as-code, or similar tools.
  • Experience participating in incident response and communicating clearly during high-pressure situations.
  • Working knowledge of ISO 27001, SOC 2, or similar security-control frameworks.
  • Strong written and spoken English and comfort working independently in a remote, asynchronous team.
  • Good risk judgment: the ability to distinguish urgent security problems, acceptable exceptions, and low-value processes.
  • Experience with Wazuh or a comparable SIEM/security-monitoring platform.
  • Experience with Teleport, PAM, or just-in-time access systems.
  • Experience securing large Linux server fleets or hybrid cloud/on-premise environments.
  • Familiarity with CI/CD systems, build infrastructure, containers, and software supply-chain security.
  • Experience supporting SOC 2 or ISO 27001 audits from the technical-control side.
  • Relevant certifications such as Security+, CISSP, CISM, GIAC, or ISO 27001, although certification is not required.

Benefits

  • Technical security operations have a clear owner, documented priorities, and reliable response expectations.
  • Vulnerability findings are consistently triaged, remediated, or explicitly accepted based on risk.
  • Security monitoring is stable, actionable, and connected to an effective incident-response process.
  • Recurring patching, access-control, and evidence-collection work is increasingly automated.
  • Engineering and Infrastructure teams receive clear, practical guidance and security issues reach closure.
  • Technical controls and audit evidence are reliable enough that compliance work does not depend on senior engineers doing manual follow-up.

Semaphore is a remote-first software company helping engineering teams build, test, and deliver software with confidence. Our customers rely on Semaphore Cloud and our self-hosted enterprise products to run critical development workflows securely and reliably. We maintain SOC 2 Type 2 and ISO 27001:2022 compliance and are hiring a Security Engineer to own the technical side of our security program.

Software
Salary not disclosed