Tech Stack
AWSAzureCloudCyber SecurityFirewallsGoogle Cloud PlatformJamfPythonSplunkSwift
About the role
- Email security platforms (e.g., Proofpoint, Mimecast, Google Workspace Email Security)
- Endpoint Detection & Response (EDR) solutions (e.g., CrowdStrike, SentinelOne, Sophos)
- Web Application Firewalls (WAF) (e.g., Cloudflare WAF) for internal and public-facing services
- Mobile Device Management (MDM) tools (e.g., Jamf, Kandji, Intune) for secure device provisioning and compliance
- Manage integrations between security tools and core infrastructure (e.g., Azure AD, Okta, SAML/OAuth).
- Operate and tune Security Information and Event Management (SIEM) systems (e.g., Splunk, Google Chronicle, Wazuh), including log source onboarding, alerting, and correlation rules.
- Performing vulnerability scanning of cloud services and internal assets using tools such as Nessus, Qualys, and Trivy.
- Coordinating with engineering teams to prioritize and track remediation efforts.
- Monitor security events, analyze alerts, investigate incidents, and perform root cause analysis.
- Create and maintain security documentation, including architecture diagrams, playbooks, and operational runbooks.
- Provide security guidance across teams, participate in architecture reviews, and support audit readiness.
- Stay informed on current threats and industry best practices in enterprise and cloud security.
Requirements
- 5+ years of experience in cybersecurity engineering or security operations roles.
- Strong experience with enterprise email security and EDR platforms.
- Experience in securing cloud environments (GCP or AWS), including IAM, encryption, and audit logging.
- Working knowledge of SIEM platforms and experience in incident response.
- Hands-on experience with Vulnerability Management programs and related tooling.
- Familiarity with MDM platforms and endpoint policy enforcement.
- Scripting and automation proficiency (e.g., Python, Bash, PowerShell).
- Solid understanding of networking, firewalling, TLS, and access control principles.
- Effective communication skills and the ability to work cross-functionally with IT, DevOps, and engineering.
- Preferred: CISSP, AWS Security Specialty, GCP Security Engineer, Security+.
- Familiarity with compliance standards such as ISO 27001, SOC 2, and GDPR.