Role Summary
The Senior Cybersecurity Engineer is responsible for the design and technical security of our multi-cloud and hybrid infrastructure. This role focuses on building scalable security architectures across cloud and on-prem environments, ensuring security technical controls are integrated into the network design from the start.
Key Responsibilities
- Security Architecture & Design
- Design and implement secure network architectures across multi-cloud (AWS, AliCloud, OCI) and hybrid environments.
- Embed security controls (Zero Trust, IAM, Encryption) into the cloud infrastructure design to mitigate technical risks.
- Develop and maintain technical design artefacts (HLD/LLD) that define security principles for enterprise-wide systems.
- Infrastructure Security & Auditing
- Conduct technical reviews and periodic audits of cloud and on-premises security configurations to ensure compliance with internal standards.
- Establish and document security baselines, operational procedures, and network security policies.
- Oversee the deployment of core security services, including Cloud Firewalls, WAF, and identity management systems.
- Network Security Engineering
- Design and manage secure connectivity between on-premises data centers and cloud platforms (Direct Connect, VPN).
- Act as the technical lead for firewall platforms (Palo Alto, Fortinet) and network security toolchains.
- Lead cloud migration projects from a security perspective, ensuring all technical deliverables meet governance requirements.
- Monitoring & Incident Response
- Define technical requirements for security monitoring using CSPM, SIEM, and CloudWatch.
- Lead technical Root Cause Analysis (RCA) for complex network or security incidents and implement remediation architecture.
Experience
- 10+ years of infrastructure engineering experience, with at least 5 years dedicated to network and cloud security.
- Minimum 3 years of experience in a Cybersecurity Architect or ICT Security Engineering capacity, focusing on secure system design.
- Proven track record in designing security controls for large-scale multi-cloud (AWS, AliCloud, OCI) and hybrid environments.
Technical Skills
- Architecture: Expert in designing network security hardening, micro-segmentation, IAM policies, and encrypted transit networking (VPN/Direct Connect).
- Engineering: Hands-on with Next-Gen Firewalls (Palo Alto, Fortinet), IDS/IPS, and WAF implementation.
- Compliance: Strong ability to translate ISO27001, SOC2, and local regulatory requirements into technical security blueprints.
- Ops & Tools: Proficient in security monitoring (SIEM/CSPM) and automated vulnerability scanning.
Certifications & Education
- Education: Bachelor’s or Master’s degree in Computer Science, IT, or related Science/Engineering fields.
- Certifications: Professional security credentials such as CISSP, CCSP, CCIE Security, or PCNSE are highly valued.