
Search by job, company or skills
Job Overview
We seek a hands-on Security Engineer with proven experience deploying and operationalizing enterprise security solutions. You will implement EDR, NDR, SIEM, CSPM, IAM, and PAM technologies for commercial/government clients while ensuring alignment with MITRE ATT&CKand compliance frameworks (NIST, ISO 27001, IM8). This role requires deeptechnical execution skills and solution integration expertise.
Core Responsibilities
Solution Deployment & Integration:
a) Endpoint: Deploy/manage CrowdStrike/Sentinel One (policy tuning, threat hunting packages)
b) NDR: Implement Darktrace/Vectra NDR with network segmentation enforcement
c) SIEM: Architect Splunk/Sumo Logic deployments(on-prem/cloud) with SOAR playbooks
d) Cloud Security: Configure CSPM (Wiz, Lacework), CNAPP(Prisma Cloud), and IaC scanning
e) IAM/PAM: Rollout CyberArk/Okta/Ping Identity (privileged session monitoring, RBAC workflows)
Technical Optimization:
a) Develop detection rules (Sigma, YARA) for APT groups targeting SEA Integrate solutions into CI/CD pipelines (Jenkins, GitLab)
b) Conduct solution hardening using CIS benchmarks
Client Delivery & Handover:
a) Lead, Develop, Conduct UAT & SSAT for assigned projects
b) Create operational runbooks, Design Documents, Configuration guide
c) Train client staff on solution management
Technical Requirements:
Solution Deployment Experience
a) EDR/XDR: CrowdStrike, Sentinel One, Microsoft Defender or equivalent
b) NDR: Darktrace, Vectra, Extra Hop or equivalent
c) SIEM/SOAR: Splunk ES, Radar, Chronicle, Torq - Use case development, SOAR playbook automation
d) Cloud Security: Wiz, Prisma Cloud, AWS Security Hub -CSPM policy packs, cloud asset inventory
e) IAM/PAM: CyberArk, Okta, Azure AD PIM - Privileged access workflows, RBAC policy enforcement
Technical Competencies:
a) Scripting: Python/PowerShell for API integrations (e.g.,SIEM-EDR correlation)
b) Networking: TCP/IP stack, Zero Trust segmentation(Zscaler, Illumio)
c) Cloud Platforms: AWS IAM, Azure Sentinel, GCP SecurityCommand Center
d) Compliance: Implement controls for NIST 800-53, ISO27001, IM8
Certifications:
Prefer: CISSP, vendor certs (e.g., CrowdStrike CCSF,Splunk Power User)
Cloud: AWS Security Specialty/Azure SC-200
IAM: CyberArk Defender/Okta Certified Professional
Experience & Qualification Requirements:
a) Bachelor's degree in IT, Cyber Security or equivalent
b) 1+ years deploying cybersecurity solutions:
c) Excellent communication and interpersonal skills.
d) Ability to work independently and within a team
Job ID: 151979953
Skills:
Scripting, Windows Server, Networking, Ldap, Cyberark, Linux RHEL, Venafi, Active Directory, Zero Trust Methodologies, 2FA solutions, Cisco Duo, RSA SecurEnvoy, IAM Security Best Practices
Skills:
Scripting, Vulnerability Management, Dlp, Automation, Network Infrastructure, Siem, Waf, PAM, XDR, EDR, Cloud Security Best Practices, System Security Hardening
Skills:
antivirus software , Java, C, Operating Systems, Ips, Windows, Firewalls, Encryption, Linux, Networking Protocols, Php, Ids, Siem, Python, OWASP TOP 10 vulnerabilities, Go
Skills:
Github, Typescript, Pulumi, Datadog, AWS, Okta, Semgrep
Skills:
GDPR Art. 28, Zscaler, Microsoft Defender for Cloud Apps, AWS security fundamentals, Microsoft Purview, DLP policy authoring, KQL, Netskope