logo

Senior Blue Team Engineer

Tehran | Engineering | Full-time

We are looking for a Senior Security Engineer to strengthen our defensive security capabilities across cloud-native infrastructure, Linux systems, applications, and networks.

This is a hands-on role focused on Security Operations, Threat Hunting, Incident Response, Detection Engineering, Security Hardening, and Cloud Security. You will work closely with Infrastructure, Platform, Network, and Development teams to improve security visibility, detection capabilities, and the overall security posture of our environment.
 

Key Responsibilities

  • Monitor, analyze, and investigate security events and coordinate incident response and remediation activities
  • Perform proactive threat hunting across cloud infrastructure, Linux systems, endpoints, networks, and applications
  • Develop and improve SIEM use cases, correlation rules, detection logic, and dashboards
  • Work with technical teams to onboard log sources and improve log collection, parsing, normalization, and security telemetry
  • Identify detection and visibility gaps, reduce false positives, and continuously improve detection coverage
  • Perform security hardening and configuration reviews across Linux systems, infrastructure, applications, and cloud workloads
  • Review authentication, authorization, privileged access, logging, auditing, and network exposure
  • Support vulnerability assessment, prioritization, remediation, and validation activities
  • Translate attacker techniques and TTPs into practical preventive and detective security controls
  • Develop and improve SOC and Blue Team processes, incident response playbooks, and security baselines
  • Use scripting and automation to improve investigation, enrichment, response, and operational efficiency
  • Collaborate with Infrastructure, Platform, Network, and Development teams to identify and remediate security weaknesses

Requirements

  • Proven experience in Security Engineering, SOC, Blue Team, or a similar defensive security role
  • Strong hands-on experience with SIEM platforms, including log onboarding, log pipelines, parsing, security telemetry, and detection engineering
  • Solid understanding of incident investigation, incident response, and proactive threat hunting
  • Strong understanding of Linux security, system hardening, and common security misconfigurations
  • Good understanding of network security, authentication, authorization, IAM, and privileged access concepts
  • Familiarity with cloud-native environments and security challenges across cloud infrastructure and workloads
  • Good understanding of common attacker techniques and the ability to investigate security issues across different layers of the technology stack
  • Experience with scripting or automation using Python, Bash, or similar languages
  • Strong troubleshooting, analytical, and cross-team collaboration skills

Nice to Have

  • Experience with Splunk or other enterprise SIEM platforms
  • Familiarity with MITRE ATT&CK and its practical use in threat hunting and detection engineering
  • Experience with EDR/XDR, SOAR, or security automation
  • Familiarity with CIS Benchmarks or similar security hardening frameworks
  • Experience with Kubernetes and container security
  • Experience with cloud security controls, IAM, or cloud-native security services

Benefits

  • Supplementary health insurance for you and your family (supports most treatments, including psychotherapy).
  • Competitive salary with regular promotion opportunities.
  • Reimbursement for educational courses, internet, and even programs for self-development. (like art classes or learning a new language, etc.)
  • Flexible working hours, including remote work opportunity.
  • An exciting work environment with talented colleagues and an open environment for new ideas.
  • We provide everything you need to work comfortably, such as laptops, equipment for remote work, etc.
  • Various on-site meals and snacks.