GRADION

Security Engineer, Blue Team

GRADION

full-time

Posted on:

Location Type: Hybrid

Location: Ho Chi Minh CityVietnam

Visit company website

Explore more

AI Apply
Apply

About the role

  • Implement defensive controls for web applications based on red team pentest findings (WAF configuration, secure headers, input validation).
  • Monitor web application logs to detect exploitation attempts and anomalies.
  • Execute incident response for web security incidents, perform root cause analysis, and validate vulnerability remediations.
  • Harden cloud infrastructure configurations (IAM policies, encryption, network controls) from cloud security assessment results.
  • Develop and maintain security monitoring playbooks, alerting rules, and remediation procedures for web/cloud environments.
  • Collaborate with red team during purple team exercises to validate defensive effectiveness.

Requirements

  • At least 2 years of experience in defensive security operations or SOC analyst roles.
  • Strong understanding of web application security defenses (WAF, secure coding, API protection).
  • Experience with a SIEM platform and log analysis for threat detection.
  • Proficiency in cloud security services (AWS GuardDuty, Config, IAM ...or Azure/GCP equivalents).
  • Skilled in scripting for security automation (Python, Bash) and basic Linux/Windows administration.
  • Familiarity with MITRE ATT&CK framework and NIST/CIS compliance standards.
  • Professional certifications like CompTIA CySA+, GCIH, or cloud security certs are advantageous.
Benefits
  • Competitive Compensation
  • Performance bonus (up to 2-month salary)
  • Performance review 2 times/ year
  • Extra Premium Healthcare & Annual Health-check
  • 15 days of annual leave
  • A laptop is provided.
  • Community Tech activities.
  • A fun & dynamic environment and freedom to be creative.
  • Modern office with a flexible, relaxing zone.

Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard skills
WAF configurationsecure codingAPI protectionlog analysiscloud security servicesAWS GuardDutyPythonBashLinux administrationWindows administration
Soft skills
incident responseroot cause analysiscollaboration
Certifications
CompTIA CySA+GCIH