Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Thank you. Your report has been submitted and will be reviewed shortly.
https://bayt.page.link/v1TUmrkCw1dqRip19
Back to the job results

Security Engineer

Yesterday 2026/09/17 ·Application closes in 58 days
Full time
100-499 Employees · IT Services

Get the Bayt App

Download the Bayt App to manage your real time conversation with the recruiter

Download App
Create a job alert for similar positions
Job alert turned off. You won’t receive updates for this search anymore.

Job description

Avertra's mission is to Simplify Life — automating complex decision-making for customer-centric industries including Utilities, Financial Services, Logistics, and Commerce, while directly improving the employee and customer experience.


What We Promise You:

  • A global family building a sustainable, scalable ecosystem guided by logic and empathy.
  • A clearly-scoped, high-impact mandate, ship real controls, not just reports.
  • Genuine investment in your growth and mastery of your domain.

The Security Engineer is responsible for building the runtime, detection, and application-security layers that carry Avertra into SOC 2 and PCI DSS 4.0 compliance, partnering with the in-house DevOps team on Avertra’s Azure / AKS platform (TypeScript / React / Node application landscape, including billing and guest-payment flows in PCI scope).


The role owns security design, detections and rules, application-security testing, the vulnerability management program, vendor remediation, and control evidence. DevOps owns the CI/CD pipeline, AKS, and infrastructure execution; a fractional vCISO and GRC platform own the audit itself, this role supplies and maintains the evidence for the controls it builds.



Main Job Responsibilities

  • Application Security Testing
  • Introduces and tunes DAST against running applications; triages findings and drives fixes.
  • Deploys and owns a semantic SAST engine tuned for TypeScript / React / Node; owns the rules, triage, and merge-block policy.
  • Detection Engineering & Response
  • Builds the detection layer on the SIEM: correlation rules, alerts, and incident playbooks.
  • Defines and tunes runtime workload detection in AKS and file-integrity monitoring.
  • Owns what is detected and how the organization responds, while DevOps stands up SIEM infrastructure, log shipping, and agent deployment.
  • Edge & Network Controls
  • Owns the WAF ruleset: tunes the OWASP ruleset, defines exceptions, and confirms Prevention mode and that logs reach the SIEM.
  • Vulnerability Management as a Program
  • Stands up a vulnerability aggregator: dedups across scanners, assigns owner and risk-based SLA per finding, drives ticketing, and surfaces SLA breaches on a dashboard.
  • Defines secret-scanning policy (pre-commit and history sweep) and unifies the release gate across all scanners.
  • Assurance & Evidence
  • Manages the ASV scan and annual penetration-test vendors; triages results and drives remediation.
  • Produces and maintains evidence for owned controls, alongside the vCISO and GRC platform, to support SOC 2 Type II and PCI DSS 4.0 assessments (supports, but does not run, the audit).



This job post has been translated by AI and may contain minor differences or errors.
You’ve reached the maximum limit of 15 job alerts. To create a new alert, please delete an existing one first.
Job alert created for this search. You’ll receive updates when new jobs match.
Are you sure you want to unapply?

You'll no longer be considered for this role and your application will be removed from the employer's inbox.