Internal Security & Security Operations Engineer

UltaHost

Santander

Presencial

COP 120.000.000 - 200.000.000

Jornada completa

hace 13 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Descripción de la vacante

UltaHost is seeking a Senior Internal Security & Security Operations Engineer to own internal security across IAM, monitoring, and incident response. You will secure identities, privileged access, endpoints, VPN, and cloud/SaaS environments while implementing robust controls.

This hands-on role requires hands-on experience with RBAC, MFA, SSO, PAM, SIEM, EDR, and a structured, cross-functional approach to risk reduction as you lead detection and response, governance, and collaboration with HR,

Formación

  • 5+ years of hands-on experience in internal security, IAM, SOC/security operations, incident response, IT security, or a closely related role.

Responsabilidades

  • Design and maintain RBAC across departments, roles, and critical systems.
  • Manage MFA, SSO, PAM, password vaults, API keys, SSH keys, recovery codes, and secrets.
  • Own security controls around onboarding, role changes, temporary access, contractor access, and offboarding.
  • Identify and remove shared, dormant, unnecessary, and excessively privileged accounts.
  • Conduct regular access reviews and maintain approval and audit evidence.
  • Monitor and investigate alerts from SIEM, EDR, IDS/IPS, authentication systems, cloud/SaaS platforms, internal applications, and endpoints.
  • Investigate suspicious logins, compromised accounts, credential leaks, malware, privilege abuse, insider risk, and unauthorized access.
  • Collect evidence, contain threats, coordinate recovery, and drive corrective actions through closure.
  • Maintain detection rules, alert quality, incident records, escalation paths, and response playbooks.
  • Lead internal security incidents and support infrastructure/product incidents involving identities or credentials.
  • Define security requirements for laptops, VPN and remote access, email, code repositories, support platforms, finance tools, and administrative systems.
  • Work closely with HR and IT on joiner/mover/leaver processes and internal security investigations.
  • Support security awareness, phishing prevention, and secure handling of sensitive information and credentials.

Conocimientos

RBAC
MFA
SSO
PAM
Identity Providers
Access Auditing
SOC Operations
Incident Response
SIEM
EDR
Cloud/SaaS
Linux Access
VPN Access
Email Security
Remote-Workforce Security

Herramientas

SIEM
EDR
IDS/IPS
Centralized Logging

Descripción del empleo

UltaHost is looking for a Senior Internal Security & Security Operations Engineer to take ownership of internal security and help strengthen the protection of our workforce, identities, systems, and day-to-day operations.

This is a senior, hands-on technical role with responsibility across Identity & Access Management (IAM), internal security, security monitoring, SOC operations, and incident response. The position requires someone who can combine strong technical security expertise with a structured and operational approach to access control, monitoring, investigation, and risk reduction.

You will be responsible for securing employee and contractor identities, privileged access, credentials, internal systems, endpoints, VPN and remote access, while ensuring that appropriate security controls are implemented and maintained throughout the account and access lifecycle.

A key part of the role will also involve actively monitoring security events and investigating suspicious activity across authentication systems, endpoints, internal applications, and cloud/SaaS environments. You will take an active role in identifying potential threats, investigating security incidents, collecting evidence, containing risks, coordinating remediation, and ensuring corrective actions are followed through to closure.

You will work closely with HR, IT, system owners, and other technical teams to improve access governance, strengthen internal security controls, enhance detection and response capabilities, and reduce security risks across UltaHost’s internal environment.

We are looking for someone who is comfortable taking end-to-end ownership — from implementing preventive controls and improving security monitoring to investigating real incidents and driving security improvements across the organization.

What You’ll Own
Identity, Access & Credential Security
  • Design and maintain RBAC across departments, roles, and critical systems.
  • Manage MFA, SSO, PAM, password vaults, API keys, SSH keys, recovery codes, and secrets.
  • Own security controls around onboarding, role changes, temporary access, contractor access, and offboarding.
  • Identify and remove shared, dormant, unnecessary, and excessively privileged accounts.
  • Conduct regular access reviews and maintain approval and audit evidence.
Security Monitoring & Incident Response
  • Monitor and investigate alerts from SIEM, EDR, IDS/IPS, authentication systems, cloud/SaaS platforms, internal applications, and endpoints.
  • Investigate suspicious logins, compromised accounts, credential leaks, malware, privilege abuse, insider risk, and unauthorized access.
  • Collect evidence, contain threats, coordinate recovery, and drive corrective actions through closure.
  • Maintain detection rules, alert quality, incident records, escalation paths, and response playbooks.
  • Lead internal security incidents and support infrastructure/product incidents involving identities or credentials.
Internal Systems & Workforce Security
  • Define security requirements for laptops, VPN and remote access, email, code repositories, support platforms, finance tools, and administrative systems.
  • Work closely with HR and IT on joiner/mover/leaver processes and internal security investigations.
  • Support security awareness, phishing prevention, and secure handling of sensitive information and credentials.
What We’re Looking For
  • 5+ years of hands-on experience in internal security, IAM, SOC/security operations, incident response, IT security, or a closely related role.
  • Practical experience with RBAC, MFA, SSO, PAM, identity providers, password management, account lifecycle management, and access auditing.
  • Hands-on experience with SIEM, EDR, IDS/IPS, centralized logging, authentication logs, alert triage, and case management.
  • Proven ability to investigate compromised accounts, malware, credential leaks, suspicious authentication activity, insider risk, and unauthorized access.
  • Strong understanding of Linux access, SSH, VPN, endpoints, cloud/SaaS administration, email security, and remote-workforce security.
  • Strong organizational skills and the ability to enforce security controls while collaborating with HR, IT, managers, and system owners.
Preferred Background

Experience in web hosting, cloud infrastructure, data centers, SaaS, fintech, MSSP, or another distributed technology environment is highly valuable. Preferred certifications include Security+, CySA+, GCIH, SC-200, IAM/PAM vendor certifications, CISSP, or equivalent practical expertise. Certifications are a plus — hands-on experience matters more.

What Success Looks Like

You will help us improve:

  • MFA and privileged-access coverage
  • Joiner/mover/leaver security and access-removal speed
  • Control of shared, dormant, and excessive access
  • Alert response and incident-resolution times
  • Access-review coverage and security evidence
  • Internal security standards, procedures, and playbooks
Important

We are not looking for a policy/compliance-only profile. The successful candidate must have real hands-on experience administering access controls, operating security tooling, investigating logs, and responding to security incidents.

You will work closely with our second cybersecurity specialist, the Product & Infrastructure Security Engineer, as well as DevOps, Network, Product, Engineering, Support, Abuse, HR, Finance, Legal, and executive management.

If you enjoy taking ownership, building security controls, investigating real incidents, and improving security in a large-scale technology environment, we’d like to hear from you.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Internal Security & Security Operations Engineer
Internal Security & Security Operations Engineer

UltaHost • Colombia

Presencial
COP 120.000.000 - 185.000.000
Internal Security & Security Operations Engineer
Internal Security & Security Operations Engineer

UltaHost • La Guajira

Presencial
COP 120.000.000 - 240.000.000
Senior Internal Security & IAM Operations Engineer
Senior Internal Security & IAM Operations Engineer

UltaHost • Colombia

Presencial
COP 120.000.000 - 185.000.000
Senior Internal Security & IAM Operations Engineer
Senior Internal Security & IAM Operations Engineer

UltaHost • La Guajira

Presencial
COP 120.000.000 - 240.000.000
IAM Security Engineer
IAM Security Engineer

EXL • Colombia

Presencial
COP 60.000.000 - 110.000.000
null
Senior Security Engineer
Senior Security Engineer

Arionkoder • Colombia

Presencial
COP 183.002.000 - 256.204.000
Competitive USD salary
20 business days of vacation
Family Leave
+1
Senior Information Security Operations Analyst
Senior Information Security Operations Analyst

Mastercard • Bogotá ciudad

Presencial
COP 108.000.000 - 156.000.000
Security Engineer - SR
Security Engineer - SR

Arionkoder • Bogotá, Distrito Capital

Presencial
COP 218.762.000 - 328.144.000
20 business days of vacation
Family Leave
Dynamic remote work culture
Cyber Security Solutions Architect
Cyber Security Solutions Architect

Cognizant • Colombia

Híbrido
COP 60.000.000 - 120.000.000
IAM Security Engineer
IAM Security Engineer

GFT Technologies • Colombia

Presencial
COP 111.193.000 - 185.323.000