Scope of Work
The Cyber Platform Engineer will be responsible for the operational administration, maintenance, and lifecycle management of the Board's key cybersecurity platforms: Carbon Black EDR, Palo Alto Perimeter Firewalls deployed across the Board's Critical Information Infrastructure (CII) sites, the Cloudflare DDoS Mitigation Services (DMS) protecting the Board's internet-facing web assets, and the CyberArk Privileged Access Management (PAM) platform governing privileged account access across the Board's environment.
The engineer will execute routine and ad-hoc maintenance activities to ensure the continuous functioning, security compliance, and operational integrity of these platforms. This includes performing scheduled preventive maintenance, managing onboarding and offboarding of assets and accounts, conducting access and log reviews, supporting security assessments and audits, and coordinating with relevant contractors and internal teams. The engineer shall also produce maintenance reports according to Board requirements for every maintenance cycle. This role requires strong discipline around cybersecurity, change management, and documentation, and the engineer shall ensure all activities are compliant with the Board's cybersecurity policies and the Cybersecurity Code of Practice (CCoP).
Roles and Responsibilities
Palo Alto Firewall Operations & Maintenance
- Perform comprehensive quarterly preventive maintenance of all onsite perimeter firewalls, meaning onsite visits to all Board's sites, covering health checks, software patching and firmware updates, and diagnostic checks.
- Conduct quarterly log and account reviews to detect anomalies and ensure compliance with the Board's cybersecurity policies.
- Perform patching and mitigations based on the Board's patch management timeline: Critical vulnerabilities within 45 days, High and Medium within 60 days, and Low within 90 days.
- Perform annual firewall configuration and rules reviews, annual review of hardware and software application lists, and other periodic security reviews as required by the Board's cybersecurity policy.
- Perform ad-hoc onsite maintenance including graceful shutdown of firewalls when required by the Board (not more than thrice per quarter), and replacement of faulty devices or parts such as ethernet cables.
- Perform configuration services for existing perimeter firewalls across CII sites, including signature updates and CVE patching on an ad-hoc basis, log backup extraction, firewall shifting and cabling services, firewall rules whitelisting and configuration, and system configuration.
- Assist the Board during cybersecurity assessments and audits related to the firewall infrastructure.
- Ensure firewall rules, configurations, and operations comply with the Board's cybersecurity policies and requirements throughout the entire contract period.
- Raise change requests according to the Board's Change Management process for all maintenance works and system changes.
EDR Platform Operations & Maintenance
- Maintain and operate Carbon Black EDR servers hosted on RHEL 8, including OS, database, application, backup, health check, patching, and service maintenance activities.
- Monitor and troubleshoot Carbon Black application services, PostgreSQL/Solr components, log forwarding services, and indexing or queue‑related issues, including review of system, security, and audit logs not centrally forwarded.
- Monitor endpoint sensor health, connectivity, and deployment status; troubleshoot offline or faulty sensors, collect diagnostics, and support sensor recovery or redeployment.
- Support onboarding of new endpoints, validate sensor records against asset inventories, and coordinate with the OEM for advanced troubleshooting, configuration, integration, and professional support when required.
Cloudflare DMS Administration
- Serve as the first point of contact for all DMS‑related enquiries from internal stakeholders.
- Perform monthly user access reviews, log reviews, and report reviews from the managed services vendor for Cloudflare DMS platform.
- Manage onboarding of new websites onto the DMS platform and offboarding of websites when required, ensuring all changes are documented in the Board's enterprise cloud repository.
- Update and maintain DMS‑related documentation, templates, and default configurations in the Board's enterprise cloud repository as required.
- Manage software and hardware maintenance and warranty tracking for DMS components.
- Process service requests and change requests including security policy changes such as IP whitelisting and blacklisting, log extraction, and notification alert updates.
- Manage SSL certificate renewals for protected websites and update website maintenance pages as required.
- Review and optimise DMS rules and notifications in coordination with the vendor and PUB SOC team.
- Perform continuous monitoring and review of the DMS solution every six months to ensure ongoing effectivenes