Product & Infrastructure Security Engineer
احفظ هذه الوظيفة وحافظ على تنظيم بحثك
قم بإنشاء حساب مجاني لحفظ الوظائف وإنشاء التنبيهات والعودة إلى هذه القائمة من لوحة التحكم الخاصة بك.
Product & Infrastructure Security Engineer
Dubai
Full-Time
Job Overview
UltaHost is looking for a Senior Product & Infrastructure Security Engineer to take ownership of the security of our hosting products and the infrastructure that delivers them. This is a deeply technical, hands-on position combining product security, application security, Linux/server security, virtualization, network security, vulnerability management, and DDoS incident response. We are looking for someone who understands security not only from a testing perspective, but from the realities of operating and protecting production hosting infrastructure.
What You’ll Own
Hosting Product & Application Security
- Review the security of VPS, VDS, dedicated servers, shared hosting, WordPress, cloud, Mac hosting, email hosting, game hosting, customer portals, control panels, APIs, and internal hosting platforms.
- Assess authentication, authorization, session security, tenant isolation, secrets handling, privileged operations, and data-exposure risks.
- Perform threat modeling, architecture reviews, security testing, API security reviews, and release risk assessments.
- Define security requirements and release checks for new products, major features, and sensitive platform changes.
- Work with Product, Engineering, DevOps, and QA teams until vulnerabilities are remediated, retested, and closed.
- Define secure baselines for Linux servers, hypervisors, control panels, network devices, firewalls, storage systems, and management interfaces.
- Review SSH configurations, exposed ports and services, routing, DNS, firewall rules, segmentation, management access, and privilege boundaries.
- Secure environments involving Proxmox, KVM, VMware, Ceph, containers, VPS nodes, dedicated infrastructure, and data‑center connectivity.
- Investigate brute‑force attacks, malware, suspicious processes, privilege escalation, lateral movement, data exfiltration, and abnormal traffic.
- Own technical DDoS/DoS response, including traffic analysis, mitigation, provider escalation, evidence collection, and post‑incident reviews.
Vulnerability & Technical Incident Management
- Run vulnerability scanning, configuration audits, patch‑risk assessments, and targeted penetration testing.
- Prioritize vulnerabilities according to actual customer and infrastructure risk.
- Assign remediation owners and deadlines and verify that fixes are effective.
- Lead product and infrastructure security incidents.
- Support internal security incidents when servers, networks, or applications are involved.
What We’re Looking For
- 5+ years of hands‑on experience in hosting security, infrastructure security, Linux security, network security, product security, cloud security, or a closely related role.
- Advanced Linux administration skills.
- Real‑world experience with VPS, dedicated servers, shared hosting, control panels, hypervisors, storage, or large multi‑tenant environments.
- Experience with Proxmox, KVM, VMware, Ceph, containers, or equivalent virtualization and cluster technologies.
- Strong knowledge of TCP/IP, DNS, routing, firewalls, VPNs, segmentation, and traffic analysis.
- Hands‑on experience detecting and mitigating DDoS attacks.
- Strong understanding of OWASP Top 10, API security, authentication, authorization, session security, tenant isolation, secrets management, and secure release practices.
- Experience with vulnerability scanners, penetration‑testing tools, SAST/DAST, dependency scanning, configuration reviews, tcpdump, Wireshark, and log analysis.
- Ability to investigate compromised servers, malware, brute‑force attacks, web attacks, privilege escalation, and abnormal network behavior.
Preferred Background
Direct experience in a web hosting company, cloud provider, ISP, CDN, data center, infrastructure vendor, or MSSP is highly preferred. Preferred certifications include OSCP, OSWA, CCNP Security, GIAC, Security+, CISSP, cloud‑security certifications, or equivalent practical expertise. Certifications are valuable, but real production experience is more important.
What Success Looks Like
You will help us achieve:
- Earlier detection of critical vulnerabilities before release or exploitation
- Faster containment of product, server, network, and DDoS incidents
- Reduction of exposed high‑risk services and unsafe configurations
- Reduction of overdue vulnerabilities
- Secure baseline coverage across Linux, virtualization, network, and hosting products
- Stronger product‑security reviews and remediation verification
- Prevention of recurring security weaknesses
Important
This is not a general penetration‑testing position. We need someone who can s