Product & Infrastructure Security Engineer

UltaHost

Dubai

On-site

AED 180,000 - 260,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UltaHost is seeking a Senior Product & Infrastructure Security Engineer to own the security of hosting products and the underlying infrastructure. You will work hands-on across Linux security, virtualization, networks, and incident response to protect multi-tenant environments.

Key responsibilities include threat modeling, security testing, secure release practices, and remediation coordination with Product, Engineering, DevOps, and QA teams.

Qualifications

  • 5+ years hands-on hosting security experience.
  • Advanced Linux administration skills.
  • Experience with multi-tenant hosting environments (VPS, shared, dedicated).
  • Proxmox, KVM, VMware, Ceph or similar virtualization experience.
  • Solid knowledge of TCP/IP, DNS, routing, firewalls, VPNs, segmentation, and traffic analysis.
  • Experience with vulnerability scanners, SAST/DAST, and log analysis.
  • Understanding of secure release practices and tenant isolation.

Responsibilities

  • Review the security of VPS, hosting products, and related platforms.
  • Assess authentication, authorization, session security, and data exposure risks.
  • Perform threat modeling, architecture reviews, and security testing.
  • Define security requirements and release checks for new products and features.
  • Collaborate with Product, Engineering, DevOps, and QA to remediate vulnerabilities.
  • Define secure baselines for Linux servers, hypervisors, network devices, and management interfaces.
  • Investigate brute-force attacks, malware, and abnormal traffic.
  • Own DDoS/DoS response including mitigation and post-incident reviews.
  • Lead vulnerability management and incident response activities.

Skills

5+ years hosting security
Advanced Linux administration
Multi-tenant hosting
Proxmox
KVM
VMware
Ceph
Containers virtualization
TCP/IP & DNS
Firewalls & VPNs
DDoS mitigation
OWASP Top 10 & API security
Vulnerability scanners & SAST/DAST
Log analysis & tcpdump/Wireshark

Job description

Product & Infrastructure Security Engineer

Dubai

Full-Time

Job Overview

UltaHost is looking for a Senior Product & Infrastructure Security Engineer to take ownership of the security of our hosting products and the infrastructure that delivers them. This is a deeply technical, hands-on position combining product security, application security, Linux/server security, virtualization, network security, vulnerability management, and DDoS incident response. We are looking for someone who understands security not only from a testing perspective, but from the realities of operating and protecting production hosting infrastructure.

What You’ll Own
Hosting Product & Application Security
  • Review the security of VPS, VDS, dedicated servers, shared hosting, WordPress, cloud, Mac hosting, email hosting, game hosting, customer portals, control panels, APIs, and internal hosting platforms.
  • Assess authentication, authorization, session security, tenant isolation, secrets handling, privileged operations, and data-exposure risks.
  • Perform threat modeling, architecture reviews, security testing, API security reviews, and release risk assessments.
  • Define security requirements and release checks for new products, major features, and sensitive platform changes.
  • Work with Product, Engineering, DevOps, and QA teams until vulnerabilities are remediated, retested, and closed.
  • Define secure baselines for Linux servers, hypervisors, control panels, network devices, firewalls, storage systems, and management interfaces.
  • Review SSH configurations, exposed ports and services, routing, DNS, firewall rules, segmentation, management access, and privilege boundaries.
  • Secure environments involving Proxmox, KVM, VMware, Ceph, containers, VPS nodes, dedicated infrastructure, and data‑center connectivity.
  • Investigate brute‑force attacks, malware, suspicious processes, privilege escalation, lateral movement, data exfiltration, and abnormal traffic.
  • Own technical DDoS/DoS response, including traffic analysis, mitigation, provider escalation, evidence collection, and post‑incident reviews.
Vulnerability & Technical Incident Management
  • Run vulnerability scanning, configuration audits, patch‑risk assessments, and targeted penetration testing.
  • Prioritize vulnerabilities according to actual customer and infrastructure risk.
  • Assign remediation owners and deadlines and verify that fixes are effective.
  • Lead product and infrastructure security incidents.
  • Support internal security incidents when servers, networks, or applications are involved.
What We’re Looking For
  • 5+ years of hands‑on experience in hosting security, infrastructure security, Linux security, network security, product security, cloud security, or a closely related role.
  • Advanced Linux administration skills.
  • Real‑world experience with VPS, dedicated servers, shared hosting, control panels, hypervisors, storage, or large multi‑tenant environments.
  • Experience with Proxmox, KVM, VMware, Ceph, containers, or equivalent virtualization and cluster technologies.
  • Strong knowledge of TCP/IP, DNS, routing, firewalls, VPNs, segmentation, and traffic analysis.
  • Hands‑on experience detecting and mitigating DDoS attacks.
  • Strong understanding of OWASP Top 10, API security, authentication, authorization, session security, tenant isolation, secrets management, and secure release practices.
  • Experience with vulnerability scanners, penetration‑testing tools, SAST/DAST, dependency scanning, configuration reviews, tcpdump, Wireshark, and log analysis.
  • Ability to investigate compromised servers, malware, brute‑force attacks, web attacks, privilege escalation, and abnormal network behavior.
Preferred Background

Direct experience in a web hosting company, cloud provider, ISP, CDN, data center, infrastructure vendor, or MSSP is highly preferred. Preferred certifications include OSCP, OSWA, CCNP Security, GIAC, Security+, CISSP, cloud‑security certifications, or equivalent practical expertise. Certifications are valuable, but real production experience is more important.

What Success Looks Like

You will help us achieve:

  • Earlier detection of critical vulnerabilities before release or exploitation
  • Faster containment of product, server, network, and DDoS incidents
  • Reduction of exposed high‑risk services and unsafe configurations
  • Reduction of overdue vulnerabilities
  • Secure baseline coverage across Linux, virtualization, network, and hosting products
  • Stronger product‑security reviews and remediation verification
  • Prevention of recurring security weaknesses
Important

This is not a general penetration‑testing position. We need someone who can secure and investigate real production hosting infrastructure not someone whose experience is limited to vulnerability testing and producing penetration‑test reports. You will work closely with our Internal Security & Security Operations Engineer and collaborate with Product, Engineering, DevOps, Network, QA, Support, Abuse, and executive management. If Linux, networks, virtualization, hosting infrastructure, product security, and incident response are where you do your best work, we’d like to hear from you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer - Product & Infrastructure
Lead Security Engineer - Product & Infrastructure

UltaHost • Dubai

On-site
AED 180,000 - 260,000
Internal Security & Security Operations Engineer
Internal Security & Security Operations Engineer

UltaHost • Dubai

On-site
AED 350,000 - 520,000
Cloud Security Engineer - Hybrid Platforms
Cloud Security Engineer - Hybrid Platforms

AlFuttaim • Dubai

Hybrid
Application Security Engineering Service at VaporVM
Application Security Engineering Service at VaporVM

VaporVM • Dubai

On-site
AED 180,000 - 320,000
Product Security Engineer
Product Security Engineer

AMD CyberSec • Dubai

On-site
AED 246,000 - 402,000
Senior Penetration Tester — Offensive Security & DevSecOps
Senior Penetration Tester — Offensive Security & DevSecOps

Toptal • Dubai

On-site
AED 350,000 - 600,000
Cloud Security Engineer
Cloud Security Engineer

DiceTek UAE • Dubai

On-site
Opportunity for career growth in cloud security
Work on enterprise-level security projects
Network & Information Security Engineer | Reach Group | UAE
Network & Information Security Engineer | Reach Group | UAE

Reach Group • United Arab Emirates

On-site
AED 120,000 - 180,000
Senior Linux Administrator
Senior Linux Administrator

DiceTek UAE • Dubai

On-site
Exposure to cutting-edge technology
Opportunity for career advancement
Dynamic work environment
Abuse and Compliance Manager
Abuse and Compliance Manager

UltaHost • Dubai

On-site
AED 160,000 - 220,000