Product & Infrastructure Security Engineer

منذ 2 ساعات

dubai, dubai, الإمارات العربية المتحدة UltaHost دوام كامل
Product & Infrastructure Security Engineer

Dubai

Full-Time

Job Overview

UltaHost is looking for a Senior Product & Infrastructure Security Engineer to take ownership of the security of our hosting products and the infrastructure that delivers them. This is a deeply technical, hands-on position combining product security, application security, Linux/server security, virtualization, network security, vulnerability management, and DDoS incident response. We are looking for someone who understands security not only from a testing perspective, but from the realities of operating and protecting production hosting infrastructure.

What You’ll OwnHosting Product & Application Security
  • Review the security of VPS, VDS, dedicated servers, shared hosting, WordPress, cloud, Mac hosting, email hosting, game hosting, customer portals, control panels, APIs, and internal hosting platforms.
  • Assess authentication, authorization, session security, tenant isolation, secrets handling, privileged operations, and data-exposure risks.
  • Perform threat modeling, architecture reviews, security testing, API security reviews, and release risk assessments.
  • Define security requirements and release checks for new products, major features, and sensitive platform changes.
  • Work with Product, Engineering, DevOps, and QA teams until vulnerabilities are remediated, retested, and closed.
  • Define secure baselines for Linux servers, hypervisors, control panels, network devices, firewalls, storage systems, and management interfaces.
  • Review SSH configurations, exposed ports and services, routing, DNS, firewall rules, segmentation, management access, and privilege boundaries.
  • Secure environments involving Proxmox, KVM, VMware, Ceph, containers, VPS nodes, dedicated infrastructure, and data‑center connectivity.
  • Investigate brute‑force attacks, malware, suspicious processes, privilege escalation, lateral movement, data exfiltration, and abnormal traffic.
  • Own technical DDoS/DoS response, including traffic analysis, mitigation, provider escalation, evidence collection, and post‑incident reviews.
Vulnerability & Technical Incident Management
  • Run vulnerability scanning, configuration audits, patch‑risk assessments, and targeted penetration testing.
  • Prioritize vulnerabilities according to actual customer and infrastructure risk.
  • Assign remediation owners and deadlines and verify that fixes are effective.
  • Lead product and infrastructure security incidents.
  • Support internal security incidents when servers, networks, or applications are involved.
What We’re Looking For
  • 5+ years of hands‑on experience in hosting security, infrastructure security, Linux security, network security, product security, cloud security, or a closely related role.
  • Advanced Linux administration skills.
  • Real‑world experience with VPS, dedicated servers, shared hosting, control panels, hypervisors, storage, or large multi‑tenant environments.
  • Experience with Proxmox, KVM, VMware, Ceph, containers, or equivalent virtualization and cluster technologies.
  • Strong knowledge of TCP/IP, DNS, routing, firewalls, VPNs, segmentation, and traffic analysis.
  • Hands‑on experience detecting and mitigating DDoS attacks.
  • Strong understanding of OWASP Top 10, API security, authentication, authorization, session security, tenant isolation, secrets management, and secure release practices.
  • Experience with vulnerability scanners, penetration‑testing tools, SAST/DAST, dependency scanning, configuration reviews, tcpdump, Wireshark, and log analysis.
  • Ability to investigate compromised servers, malware, brute‑force attacks, web attacks, privilege escalation, and abnormal network behavior.
Preferred Background

Direct experience in a web hosting company, cloud provider, ISP, CDN, data center, infrastructure vendor, or MSSP is highly preferred. Preferred certifications include OSCP, OSWA, CCNP Security, GIAC, Security+, CISSP, cloud‑security certifications, or equivalent practical expertise. Certifications are valuable, but real production experience is more important.

What Success Looks Like

You will help us achieve:

  • Earlier detection of critical vulnerabilities before release or exploitation
  • Faster containment of product, server, network, and DDoS incidents
  • Reduction of exposed high‑risk services and unsafe configurations
  • Reduction of overdue vulnerabilities
  • Secure baseline coverage across Linux, virtualization, network, and hosting products
  • Stronger product‑security reviews and remediation verification
  • Prevention of recurring security weaknesses
Important

This is not a general penetration‑testing position. We need someone who can secure and investigate r