Overview
Responsibilities:
- Audit and technically harden on-premises infrastructure (Windows Server, Linux, Active Directory, hypervisors, network appliances) based on CIS Benchmarks and industry best practices
- Design and implement architectural security controls, including network microsegmentation, tiered administrative models (Active Directory Tiering Model), Privileged Access Management (PAM), and secure configurations for reverse proxies and internal services
- Analyze low-level security events: parse raw packet captures (pcap), trace system calls, and audit raw event telemetry across Windows Event Logs, Sysmon, and Linux auditd
- Onboard and normalize log sources, author custom detection logic, and fine-tune SIEM/EDR alerting rules beyond out-of-the-box templates
- Lead technical incident triage, conduct Root Cause Analysis (RCA), and isolate attack vectors to prevent recurrence.
- Execute infrastructure vulnerability scans, manually validate findings to eliminate false positives, and build actionable technical remediation roadmaps with IT operations
- Maintain attack surface visibility and technical asset inventory
Required Qualifications:
- Hands-on Infrastructure Background: 3+ years of direct experience in Systems Administration (Windows/Linux), Network Engineering, or SecOps / L2+ SOC engineering
- Deep Networking Knowledge: Strong understanding of the TCP/IP stack, DNS, DHCP, routing protocols, VLANs, TLS/SSL, and packet-level inspection tools (Wireshark, tcpdump)
- Operating Systems & Identity Architecture: In-depth knowledge of Active Directory internals (Kerberos, NTLM, Group Policy Objects, DACLs/SACLs), authentication protocols, OS-level service hardening, and privilege separation
- Scripting & Automation: Proven ability to write scripts in PowerShell, Python, or Bash for system administration, log analysis, and API integrations
- Security Tooling & Log Analysis: Practical experience with vulnerability assessment tools (Nmap, Nessus/OpenVAS) and hands-on log analysis in SIEM/EDR environments
- Systems Administration
- Network Engineering
- SecOps
- Active Directory
- Scripting
- Automation
- Log Analysis
- Vulnerability Assessment
Technologies:
- Windows Server
- Linux
- Active Directory
- Windows Event Logs
- Sysmon
- Linux auditd
- SIEM
- EDR
- Wireshark
- tcpdump
- PowerShell
- Python
- Bash
- Nmap
- Nessus
- OpenVAS
Note:
✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.
Please clearly mention that you have heard of this job opportunity on https://ijob.am.

