Senior Cyber Security Engineer
Posted 2 months ago
Project Description:
BAU/Project/Risk Assessment in the areas of information and cyber security across the business
Responsibilities:
- Understand and work with the business as well as with the Cyber Security team to identify, define and implement cyber security requirements for the organization
- Knowledge of cloud architecture to support the infrastructure and software engineering team in the design and implementation of secure architectures
- Support and further development our SOC
- Manage vulnerability assessment and work closely with stakeholders to fix detected vulnerabilities to maintain a high security standard
- Perform in-depth analysis of security related monitoring events and define follow up activities
- Engage in and coordinate cyber reviews and penetration tests
- Ensure that the company knows as much as possible, as quickly as possible about security threats and incidents (internal/ external)
- Perform maintenance, deployment and enhancement of the security infrastructure in line with best practices
- Knowledge of security governance frameworks for managing cyber risk and reporting
- Conduct and follow up for phishing campaigns
- Provide guidance to IT resources on secure configuration of systems, permissions, new projects, products & relationships
- Scripting and automation of common tasks/procedures
- Participation in industry led events and keeping up-to-date with industry trends
Mandatory Skills:
- Bachelor’s degree in related field from red brick university
- Strong understanding of Information Security within an enterprise environment
- Responsive and adaptive in a dynamic, collaborative work environment
- Service oriented, accurate, effective and independent working style, even under pressure
- Driven and self-motivated person with the ability to maintain the highest level of confidentiality
ESSENTIAL
-
- Knowledge of security systems including proxy servers, firewalls, intrusion detection systems, authentication systems, log management, content filtering, data leakage protection, endpoint tools, etc.
- Knowledge of coordinating responses to security incidents, or operating in a SOC environment
- Knowledge of IT infrastructure (virtualization, security and network services)
- Strong scripting/programming language experience (e.g. Python/Powershell)
- Conduct vulnerability assessment and remediation to a high security standard
- Strong understanding of identity management, supporting protocols and applied cryptography
- Intrusion analyst skills (traffic analysis, event correlation) and analysis/tuning of IPS/IDS/SIEM/DLP/EDR deployments
- Ability to analyse and interpret network, system, security and application logs in order to diagnose faults and spot abnormal behavior
- Excellent understanding of information security principles and practices
- The ability to express yourself clearly and logically both orally and in writing (English)
- The ability to produce high quality, written security documentation
Nice-to-Have Skills:
- DevSecOps skills for reviewing and support Infrastructure as Code (IaC) or CI/CD piplelines is a plus Experience in DLP analysis and tuning
- Security related certifications is a plus
- Master’s degree in Cyber Security
- Desire to work in a financial/regulated environment.