Responsibilities:
- Designing, implementing, and managing security solutions to protect against cyber threats while ensuring seamless IT Infrastructure, Servers and Applications performance.
- Continuously optimize existing IT Infrastructure, Servers and Applications security policies and models, monitor and respond to threat detection event alerts and response handling, and enhance overall detection levels and coverage.
- Be responsible for vulnerability management (CVE, CVSS, OWASP Top 10), container, network & systems security, as well as cloud security tools and services
- Design, configure, and maintain firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and other security devices.
- Monitor and analyze security events and logs to identify potential vulnerabilities and incidents.
- Threat Prevention & Incident Response: Identify, investigate, and resolve security breaches and incidents.
- Develop and implement strategies to mitigate identified risks and vulnerabilities.
- Ensure all compliance and security control functions are performed timely and orderly.
- Drive continuous improvement of procedures and processes related to cybersecurity process and operations monitoring.
- Conduct regular audits of IT Infrastructure, Servers and Applications security to ensure compliance with security policies.
- Maintain compliance with industry standards such as ISO 27001, GDPR, or SOC 2.
- Create and maintain detailed network diagrams and security documentation.
- Work closely with IT teams to ensure robust security integration across systems.
- Educate employees on security best practices and emerging threats.
- Manage tools like SIEM, antivirus solutions, IDS/IPS and DLP software.
- Stay updated with the latest technologies, trends, and vulnerabilities in cybersecurity.
Requirements:
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Relevant certifications (e.g., CISSP, CEH, CCNP Security, Palo Alto PCNSA) are a plus but not mandatory.
- 7 to 12 years of experience in the designing, implementing, and managing of IT Infrastructure, Servers and Applications security according to industry standards such as ISO 27001, GDPR, or SOC 2.
- Expertise in one or more IT Security Engineering topics, such as Secure Browsing, PAM, PKI, or Multifactor Authentication.
- Proven ability to contribute to the development of architecture, concepts, and processes in IT security.
- Strong understanding of network protocols (TCP/IP, DNS, HTTP, etc.), firewalls, VPNs, intrusion detection / prevention systems (IDS/IPS), vulnerability management (CVE, CVSS, OWASP Top 10) and etc.
- Proficiency in firewall technologies (e.g., Fortinet, Palo Alto, Cisco ASA).
- Experience with vulnerability scanning tools and penetration testing.
- Experienced with cloud environments and cloud security principles. Knowledge in AWS/Azure cloud security tools and services.