Introduction
Techvify Corporation is an End to End AI-Powered Digital Transformation Partner.
At Techvify, we don’t just build software.
We engineer breakthroughs.
We innovate with AI, craft with code, and scale with cloud.
We partner with startups, enterprises, and even competitors on a shared mission:
To turn bold ideas into real-world impact.
If you’re looking to lead digital transformation through intelligent software, we’re ready to build with you.
Let’s create the future – together.
Key Responsibilities
- Lead the development and operation of a unified security monitoring & response platform, bridging DevOps and Security Operations.
- Maintain and scale a High-Availability (HA) dual-pipeline architecture:
- Wazuh (with OpenSearch indexer backend)
- OpenObserve (parallel log analytics pipeline)
- Apache Kafka for high-volume log streaming
- Deploy and manage Wazuh Agents across Windows & Linux to ensure full endpoint visibility.
- Manage and optimize network monitoring tools (Suricata IDS, ntopng) for traffic analysis (NetFlow/IPFIX).
- Build automated dashboards, alerts, and monitoring systems for security audits and real-time system integrity.
- Orchestrate vulnerability scanning and integrate results into centralized dashboards for tracking & remediation.
- Develop custom decoders and detection rules to support Threat Hunting activities.
- Ensure Incident Response (IR) readiness, maintaining log integrity and enabling forensic investigations.
- Develop automation scripts (Python/Bash) for log enrichment, data correlation, and operational workflows.
Requirements
Core Technical Skills- Strong expertise in:
- Wazuh (EDR/SIEM)
- Suricata (IDS)
- Experience with network flow analysis tools (ntopng or equivalent NetFlow/IPFIX tools).
- Hands-on experience with vulnerability scanning tools (OpenVAS, Nessus, or Wazuh module).
- Experience working with:
- Apache Kafka (3-node cluster)
- Nginx HA (active/standby with VIP)
- Advanced log management skills:
- OpenSearch (Wazuh indexer backend)
- OpenObserve (parallel pipeline)
- → Must understand and operate dual-pipeline architecture, not treat them as alternatives.
- Strong Linux/Unix administration skills.
- Experience with PostgreSQL HA (replication & failover).
Log Integration & Security Knowledge- Experience integrating multiple log sources:
- Windows event logs (via Wazuh agents)
- Linux syslog/auditd
- Suricata alerts
- ntopng flow data
- Firewall, application, and cloud logs
- Familiarity with security standards/frameworks:
- ISO 27001, SOC2, NIST
Automation- Proficiency in Python & Bash for:
- Log enrichment
- Threat hunting queries
- Data correlation
- System orchestration
Preferred Qualifications- Experience in Incident Response (attack analysis, lateral movement, persistence).
- Knowledge of forensic tools and evidence handling.
- Experience with SOAR or automated response systems.
- Certifications: OSCP, GCIH, CISSP (or similar).
- Experience with container security & IaC tools (Ansible, Terraform).
Benefits
- Salary: Negotiation
- Join a global team and work directly with many talents around the world.
- Work and grow in a dynamic, creative, and professional environment.
- Healthcare: Premium Health Insurance TECHVIFY Care
- 13 months’ salary per year.
- Annual salary evaluation.
- Sponsor and encourage staff to study courses by covering tuition fees, such as Udemy, Coursera.