📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

This job is no longer available

This job expired on 06/09/2026. It no longer accepts applications.

Security Engineer

avertra · Amman

🇬🇧 English
Azure TypeScript React SAST DAST SCA OWASP ZAP Semgrep CodeQL Microsoft Sentinel Wazuh Elastic WAF vulnerability management

Job description

About the role

Avertra is looking for a Security Engineer to design, implement, and maintain the security controls that will bring the platform to SOC 2 Type II and PCI DSS 4.0 compliance. You will work closely with the DevOps team on Azure/AKS and own the detection, application‑security, and vulnerability‑management programs.

Key responsibilities

  • Introduce and tune DAST tools, triage findings and drive remediation.
  • Deploy and maintain a semantic SAST engine for TypeScript/React/Node, manage rules and merge‑block policies.
  • Build SIEM detection layers, create correlation rules, alerts and incident playbooks.
  • Define and tune runtime workload detection and file‑integrity monitoring in AKS.
  • Own WAF rule set, customize OWASP rules, ensure logs flow to the SIEM.
  • Establish a vulnerability aggregation platform, assign owners, set risk‑based SLAs and surface breaches.
  • Manage ASV scans and annual penetration‑test vendors, produce evidence for SOC 2 and PCI DSS audits.

Required profile

  • Proven experience integrating security scanners into CI/CD pipelines (Azure DevOps preferred).
  • Hands‑on knowledge of Azure, AKS and cloud‑native environments.
  • Experience supporting compliance frameworks such as SOC 2 and PCI DSS.

Required skills

  • Azure, Azure Kubernetes Service (AKS)
  • TypeScript, React, Node.js
  • SAST, DAST, SCA, secrets scanning, IaC security
  • OWASP ZAP (or equivalent) and semantic SAST tools (Semgrep, CodeQL)
  • SIEM platforms – Microsoft Sentinel, Wazuh, Elastic
  • WAF configuration and OWASP rule tuning
  • Vulnerability management and aggregation tools

What we offer

  • A global, purpose‑driven family focused on sustainable, scalable ecosystems.
  • High‑impact, clearly scoped mandate with real control delivery.
  • Strong investment in personal growth and mastery of the security domain.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec avertra.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 2 months ago

31 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

avertra

Amman