This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
10Pearls is looking for a Security Engineer to lead platform security through policy-as-code and modern security practices. You will drive Kubernetes security, supply chain protection, and compliance alignment. You will work with cross-functional teams to embed security across the development lifecycle.
Job Responsibility:
Implement, manage ISO 27001, and update information security policies and procedures
Monitor network and endpoint security, investigate issues, and respond to breaches
Perform vulnerability assessments, identify security gaps in networks and websites, and conduct penetration testing
Conduct internal audits and reporting related to ISO 27001 and technical compliance
Manage Windows Server Security, PowerShell, and Linux system administration
Ensure 100% deployment of endpoint security, email security, phishing, and malware protection
Continuously audit systems to ensure implementation of approved security controls
Coordinate with IT teams and other stakeholders
Analyze IT requirements and provide objective security recommendations
Lead tasks to completion and ensure timely execution of security operations
Stay updated on the latest security threats, trends, and technologies
Demonstrate adaptability and a creative approach to problem-solving
Perform additional duties as assigned
Requirements:
3–6 years of experience in Application Security, Platform Security, or Security Engineering roles
Hands-on experience with OPA and Rego, including policy authoring, bundle distribution, and admission controller integration
Strong understanding of Kubernetes security, including RBAC, Network Policies, Pod Security, and admission controllers
Experience working with Vault, including policies, transit secrets engine, PKI, and dynamic secrets
Hands-on experience with container and dependency scanning tools such as Trivy, Grype, Snyk, or Dependency-Track
Knowledge of supply chain security, including image signing (Cosign or Sigstore) and SBOM generation
Proficiency in Python and/or Go for building security tooling and automation
Strong documentation and communication skills, including experience writing threat models, policy design documents, and incident reports
Nice to have:
Experience with tamper-evident audit systems, WORM storage, or hash-chained architectures
Familiarity with ABAC or ReBAC frameworks such as OPA, OpenFGA, or Cedar
Experience with compliance frameworks such as ISO 27001, SOC 2, or regional sovereign frameworks (Pakistan, UAE, Saudi Arabia)
Background in offensive security (penetration testing, red teaming, CTFs)
Relevant certifications such as CISSP, OSCP, or CKS