Business Alliance HRis recruiting aCybersecurity Engineer (Security Specialist)for a High Tech Company offering digital healthcare solutions, located inRamallah, Palestine.
Job Summary:
We are seeking a Cybersecurity Engineer (Security Specialist) to lead and execute all cybersecurity-related activities across the company infrastructure, applications, and cloud environments. The role focuses heavily on penetration testing, vulnerability management, security hardening, and incident response, ensuring compliance with security best practices and regulatory standards.
Essential Duties and Responsibilities:
Perform penetration testing (network, web applications, APIs, cloud environments) and document findings clearly.
Conduct vulnerability assessments, risk analysis, and remediation follow-ups.
Own and manage security tools (SIEM, EDR, vulnerability scanners, WAF, etc.).
Review system, cloud, and application architectures for security weaknesses.
Implement and maintain security policies, procedures, and controls.
Monitor security alerts, investigate incidents, and lead incident response and remediation.
Work closely with DevOps and engineering teams to embed security into CI/CD pipelines.
Perform security hardening for servers, containers, Kubernetes, and cloud resources.
Ensure compliance with standards such as ISO 27001, SOC 2, HIPAA, or equivalent.
Prepare security reports, risk assessments, and executive summaries.
Support internal and external security audits and penetration tests.
Stay updated on emerging threats, vulnerabilities, and security best practices.
Requirements
Special Requirements & Skills:
Hands-on experience in cybersecurity and security operations.
Strong hands-on experience in penetration testing and ethical hacking.
Solid knowledge of network security, web security, and cloud security.
Experience with tools such as:
Burp Suite, Metasploit, Nessus/OpenVAS.
SIEM tools (e.g., Wazuh, Splunk, ELK).
EDR/Endpoint Security solutions.
Strong understanding of Linux security.
Familiarity with cloud platforms (AWS, OCI, Azure, or GCP).
Knowledge of containers and Kubernetes security is a strong plus.
Ability to write clear technical reports and remediation plans.
Strong troubleshooting and analytical skills.
Preferred Requirements:
Security certifications (CEH, OSCP, Security+, CISSP, or similar).
Experience in DevSecOps practices.
Experience in healthcare, fintech, or regulated environments.
Familiarity with threat modeling and secure SDLC.
Years of experience:
Minimum 3 years of experience in a similar role.
Education:
Bachelor’s degree in Computer Science, Information Technology, Computer Engineering or a related field.