Senior Cyber Security Engineer
Position Overview
We are seeking a highly skilled Senior Cybersecurity Engineer to join our dynamic team. The ideal candidate will have a strong foundation in cybersecurity principles and a willingness to learn and grow in a fast‑paced environment. This role is hands‑on and technical, covering SIEM, EDR, PAM, DLP, firewalls, IPS/WAF, web filtering, and identity/access management. The engineer will actively defend the organization against threats, conduct advanced threat hunting, and ensure the secure operation of critical systems.
Key Responsibilities
- Administer, tune, and optimize SIEM platforms (Azure Sentinel, QRadar) including alerting, dashboards, and automated playbooks.
- Manage Microsoft Defender for endpoints, servers, and cloud workloads.
- Perform advanced threat hunting across SIEM, EDR, and cloud telemetry.
- Develop and maintain incident response playbooks integrated with SOAR for automated and rapid response.
- Implement and manage SSO, MFA, conditional access, and enforce Zero Trust principles.
- Deploy, monitor, and optimize Privileged Access Management (PAM) solutions for critical accounts.
- Conduct access reviews and enforce role‑based access controls.
- Deploy and manage Data Loss Prevention (DLP) across endpoints, email, and cloud platforms.
- Implement data classification, labeling, and encryption frameworks to protect sensitive data.
- Manage and maintain firewalls, IPS, WAF, and web filtering/proxy solutions.
- Harden servers, network devices, and cloud workloads according to security best practices.
- Perform segmentation and intrusion prevention to reduce exposure to attacks.
- Conduct vulnerability scanning, patch validation, and attack surface management.
- Collaborate with IT and DevOps teams to remediate identified risks promptly.
- Map detection and response activities to the MITRE ATT&CK framework.
- Develop automation scripts (Python, PowerShell, Bash) for monitoring, threat detection, and incident response.
- Integrate security tools into SOAR workflows to improve operational efficiency.
- Support business continuity processes through continued documenting and testing of infrastructure environment.
- Liaise and maintain appropriate relationships with third‑party vendors.
Technical Profile
- Required Knowledge and Experience
- 6+ years in cybersecurity engineering or security operations roles.
- Strong hands‑on experience with SIEM: Azure Sentinel, QRadar, or equivalent.
- EDR/XDR: Microsoft Defender, CrowdStrike, or equivalent.
- Privileged Access Management (PAM): Delinea, CyberArk, BeyondTrust, ARCOS.
- DLP: Forcepoint, Microsoft Purview, Symantec, or equivalent.
- Firewall/IPS/WAF/Web filtering: Fortinet, Palo Alto, F5, Cisco, Forcepoint.
- SSO/MFA/Identity & Access Management.
- Data classification, labeling, and encryption.
- Experience with multi‑cloud (Azure, AWS, GCP) security, cloud security posture management (CSPM) and workload protection.
- Proficiency in Python, PowerShell, or Bash for automation and tooling.
- Familiarity with MITRE ATT&CK, ISO 27001:2022, and NIST CSF frameworks.
- Experience with threat intelligence feeds and proactive threat hunting.
- Desirable Knowledge and Experience
- Azure SC‑200, SC‑100, CISA, CCNP Security or any equivalent certification.
- Certified networking credential (CCNA or equivalent) is a plus.
- Solid understanding of cybersecurity architectures such as ZTA, SASE, SDP.
- Experience with threat intelligence feeds and proactive threat hunting.
- Exposure to red/blue team exercises.
Collaboration
- Passion for building scalable, reliable, and secure systems in a fast‑paced environment.
- Ability to translate complex technical concepts into clear, actionable insights for technical teams.
- Strong interpersonal skills with the ability to work effectively across cross‑functional teams.
- Excellent problem‑solving and analytical skills.