The Security Operations Engineer is responsible for the day-to-day operation, monitoring and maintenance of cybersecurity services within a 24/7 Security Operations environment. The role ensures the availability, effectiveness and security of deployed technologies and supports the timely resolution of incidents and service requests in accordance with established processes and Service Level Agreements (SLAs).
The role works closely with Team Leads, Security Managers, clients and other technical teams to maintain service quality, resolve operational issues and continuously improve the effectiveness and efficiency of security operations.
Key Responsibilities
Security Operations & Monitoring
- Provide day-to-day operational support, monitoring and maintenance of cybersecurity services within a 24/7 Security Operations environment.
- Monitor the health, availability and performance of security infrastructure and deployed security solutions.
- Perform regular health checks and proactively identify potential issues that may impact service availability or security effectiveness.
- Monitor security events, alerts and operational activities, escalating potential security incidents in accordance with established procedures.
- Ensure security operations are conducted in accordance with defined processes, operational standards and client requirements.
Incident & Service Management
- Manage and respond to security incidents, alerts and service requests in accordance with established procedures and SLAs.
- Ensure incidents and escalations are accurately recorded, tracked, communicated and resolved within the agreed timelines.
- Perform initial troubleshooting and investigation of operational and security-related issues, escalating complex issues to the appropriate technical teams when required.
- Work closely with Team Leads, Managers and relevant technical teams to drive timely resolution of incidents and minimise service disruption.
- Ensure proper incident closure, including accurate documentation of resolution actions and relevant findings.
Security Technology Administration
- Perform configuration changes and implement approved service requests in accordance with change management processes.
- Maintain and administer security policies and configurations across relevant security technologies.
- Perform device tuning, optimisation and patching activities to maintain the effectiveness and security of deployed solutions.
- Support the onboarding, configuration and maintenance of security devices and technologies where required.
- Conduct routine checks to ensure security controls and technologies are functioning as intended.
Operational Excellence & Documentation
- Maintain accurate and up-to-date operational documentation, procedures, runbooks and knowledge articles.
- Ensure changes to systems, configurations and processes are properly documented and reflected in operational procedures.
- Identify recurring operational issues and recommend improvements to processes, workflows and security controls.
- Participate in operational reviews and continuous improvement initiatives to enhance service reliability and efficiency.
- Maintain clear and accurate records of operational activities, incidents, changes and service requests.
Team & Stakeholder Collaboration
- Work closely with Team Leads and Managers to ensure operational tasks, incidents and service requests are executed effectively and within agreed timelines.
- Collaborate with internal technical teams, clients and relevant stakeholders to resolve operational issues and fulfil service requirements.
- Provide timely and clear updates on incident status, operational issues and service requests.
- Contribute to team knowledge sharing and support the development of operational capabilities within the team.
Qualifications & Skills
- Diploma or Degree in Information Technology, Computer Science, Cybersecurity or a related discipline.
- Basic understanding of IT infrastructure, including operating systems, networks and common enterprise technologies.
- Basic understanding of cybersecurity concepts and technologies, such as firewalls, endpoint protection, antivirus, device control, intrusion prevention or other security solutions.
- Experience in a Security Operations Centre (SOC), Network Operations Centre (NOC), IT Operations or similar environment will be an advantage.
- Strong troubleshooting and analytical skills with the ability to investigate and resolve operational issues systematically.
- Good written and verbal communication skills, with the ability to communicate effectively with both technical teams and stakeholders.
- Meticulous, organised and able to work effectively in a fast-paced operational environment.
- Self-motivated, proactive and willing to take ownership of assigned tasks and incidents.
- Strong team player with a positive attitude and willingness to learn new technologies and security practices.
- Cybersecurity certifications such as Security+, SC-200, CySA+, or other relevant certifications will be an advantage.
Other Working Conditions
- This is a 24/7 Security Operations role requiring 12-hour rotating shift duties.
- Working hours:AM Shift: 8:00 AM - 8:00 PMPM Shift: 8:00 PM - 8:00 AM
- Candidates must be comfortable working weekends and public holidays as part of the rotating shift roster.