Operate, maintain, and support enterprise cybersecurity platforms including Palo Alto Firewalls, Carbon Black EDR, Cloudflare DDoS/WAF, and CyberArk PAM.
Perform preventive maintenance, system health checks, patching, firmware upgrades, configuration changes, and troubleshooting for cybersecurity platforms.
Maintain and troubleshoot Carbon Black EDR, including servers, endpoint sensors, PostgreSQL/Solr components, application services, logs, and endpoint onboarding.
Administer Cloudflare DDoS/WAF services, including website onboarding/offboarding, security rules, IP whitelisting/blacklisting, SSL certificates, access reviews, and log reviews.
Administer CyberArk PAM, including privileged account onboarding/offboarding, access reviews, password management, service requests, and audit activities.
Monitor cybersecurity platforms and investigate system, security, application, and audit logs for anomalies or operational issues.
Support vulnerability management, security assessments, audits, incident investigations, and remediation activities.
Manage backup and restoration activities, including configuration backups, restoration testing, and maintenance of backup records.
Raise and manage change requests in accordance with established change management processes.
Maintain technical documentation including SOPs, asset inventories, configuration records, troubleshooting guides, security trackers, and maintenance reports.
Work closely with internal security teams, vendors, OEMs, and other technical stakeholders to resolve platform issues.
Ensure cybersecurity platforms comply with organisational security policies, the Cybersecurity Act, and Cybersecurity Code of Practice (CCoP).
Provide onsite support at secure premises when required for scheduled maintenance and ad-hoc troubleshooting.
Requirements
Strong knowledge of enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.
Hands-on experience with Palo Alto Networks Next-Generation Firewalls or equivalent enterprise firewall platforms.
Hands-on experience with Carbon Black EDR or equivalent Endpoint Detection and Response platforms.
Experience with Cloudflare or equivalent DDoS mitigation/WAF solutions, including security rules, SSL certificates, IP whitelisting/blacklisting, and log management.
Experience with CyberArk PAM or equivalent privileged access management solutions.
Good understanding of vulnerability management, security hardening, patch management, change management, and cybersecurity incident response.
Understanding of highly secured network environments, including air-gapped networks, restricted connectivity, offline patch/file transfers, and data diodes/unidirectional gateways.
Familiarity with PKI and TLS/SSL certificate lifecycle management is advantageous.
Experience supporting cybersecurity platforms within CII, highly secured, segregated, or air-gapped environments is advantageous.
Able to provide onsite support and undergo the required security clearance.