Security Platform Engineer @Sparix Global.
All Others
Salary 150000-155000 p..
Remote Location
Employment Type contract
Posted 1mth ago

[Hiring] Security Platform Engineer @Sparix Global.

1mth ago - Sparix Global. is hiring a remote Security Platform Engineer. 💸 Salary: 150000-155000 per year 📍Location: IST (UTC+5:30)

Role Description

We are seeking a Security Platform Engineer specializing in Tool Configuration and Data Unification to bring deep security domain expertise to the hands-on configuration of our scanning and aggregation stack. This role is responsible for unifying the output of multiple security scanners into a single, coherent vulnerability language. You will tune what each tool detects, define how findings are normalized and deduplicated, and design the data model that transforms raw scanner output into defensible, evaluated vulnerability records.

Working alongside DevSecOps engineers and GRC engineers, you will own the intelligence and structure of the security data pipeline—determining what flows through it and how it is shaped—to support FedRAMP compliance, audit evidence requirements, and actionable vulnerability management at scale.

Key Responsibilities

  • Own scanner configuration and tuning across the detection fleet:
    • Scan policies
    • Coverage scope
    • Severity mappings
    • Signal quality for:
      • Trivy
      • Semgrep
      • Qualys
      • Tenable
      • AWS Inspector
      • CrowdStrike
      • Dependabot
  • Design the deduplication and correlation strategy in DefectDojo, including:
    • Keying logic that recognizes the same vulnerability across:
      • Image scans
      • Runtime scans
      • Host scans
      • Dependency scans
    • Grouping rules that collapse duplicate findings into single actionable issues
  • Target: ~70% ticket reduction
  • Define the unified findings data model, including:
    • Field schema
    • Asset identity
    • Component mapping
  • Support the FedRAMP reporting requirements:
    • 11-field vulnerability detail schema
    • 8-field accepted-vulnerability reporting schema
  • Build the reachability signal layer using:
    • AWS Reachability Analyzer
    • Service mesh
    • eBPF-based signals
  • Feed internet-reachability determinations (IRV/NIRV) per finding.
  • Configure runtime visibility using CrowdStrike Falcon Cloud Security.
  • Reconcile runtime observations against image scan results to eliminate the rebuilt-but-not-redeployed gap.
  • Partner with GRC engineers to ensure the data model captures all information required by the:
    • LEV × IRV × PAIN evaluation engine
    • Audit evidence requirements
  • Validate detection coverage across:
    • Containers
    • Hosts
    • Serverless environments
    • Dependencies
    • External attack surface
  • Identify security blind spots.

Qualifications

  • 6+ years of Security Engineering experience with hands-on vulnerability management.
  • Strong understanding of:
    • CVEs
    • CPE/PURL identity
    • Scanner false positives
    • Scanner disagreement analysis
  • Experience configuring and tuning multiple commercial and open-source security scanners in production.
  • Strong data modeling skills for:
    • Normalization
    • Deduplication
    • Enrichment
    • Asset correlation
  • AWS cloud security expertise, including:
    • Container security
    • Image scanning
    • Registry policy
    • Runtime security
    • EKS
    • ECS
  • Working knowledge of:
    • CISA KEV
    • EPSS
    • VEX
    • Vulnerability prioritization
  • Hands-on experience with:
    • Trivy
    • Semgrep
    • Qualys
    • Tenable
    • AWS Inspector
    • CrowdStrike
    • Dependabot
  • Experience with DefectDojo for vulnerability aggregation and deduplication.

Preferred (Bonus) Skills

  • Deep DefectDojo experience, including:
    • Deduplication engine
    • Parsers
    • API
  • Experience with network reachability analysis:
    • AWS Reachability Analyzer
    • Service mesh telemetry
    • eBPF tooling
  • Familiarity with FedRAMP concepts:
    • VDR/VER
    • LEV (Likely Exploitable)
    • IRV/NIRV (Internet-Reachable / Non-Internet-Reachable)
    • PAIN ratings
    • Timeframe classes
  • Experience writing custom scanner parsers or findings transformation code in Python.
Before You Apply
️
remote Be aware of the location restriction for this remote position: IST (UTC+5:30)
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Platform Engineer @Sparix Global.
All Others
Salary 150000-155000 p..
Remote Location
Employment Type contract
Posted 1mth ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: IST (UTC+5:30)
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,845+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later