As our client continues to mature their internal technology stack and develop commercial cyber security products and services they recognize the value of formal information security architecture & engineering processes as key enablers of such activities as such are looking for a skilled and experienced Security Operations Engineer to join their team in a highly technical role.
Key Responsibilities:
- Improve and rationalise distributed SIEM deployments made of offtheshelf and bespoke tools/platforms for events and flow monitoring
- Scale and deploy the Vulnerability Management infrastructure to cover 50 remote sites
- Management and enhancement of event indexing normalisation and visualisation tools on a global scale
- Design and deployment of scalable AV EDR and HIPS platform
- Test build and document systemtosystem integrations using a combination of bespoke software and offtheshelf HTTPbased API
- Carry out major system upgrades and supervise the Junior Engineers in defining system operations such as: backup/restore DR simulations updates/upgrades EndofLife hardware/software refresh
- Provide support to the Security Operations Engineering Team Lead in establishing a robust resilient redundant enterprisegrade architecture for the CSOC tools stack including associated change management processes
- Act as an escalation point for issues associated with all the tools and platform troubleshooting and escalate to the Vendors when required
Essential Knowledge and Skills:
- Thorough understanding of the latest security principles techniques and protocols
- Proven work experience as a System Security Engineer and/or Administrator
- Handson experience in building and maintaining a wide portfolio of Security tools like SIEM platforms vulnerability management tools and systems integrations
- Detailed technical knowledge of Linux and Windows operating systems
- Experience with network security and networking
- Experience with IaaS / PaaS / SaaS Cloud providers and associated security offering
- Handson knowledge of the systems API principles and integration techniques
- Handson knowledge of Bash scripting and Python programming languages
- Familiarity with webrelated technologies (Web applications Web Services ServiceOriented Architectures) and of network/web related protocols
- Detailed understanding of Public Key Infrastructure and Key Management
- Knowledge or exposure to Cloud technologies such as IaaS SaaS & PaaS deployments with detailed knowledge of Azure AWS and GCP being highly desirable
- Experience with implementing Privileged Access Management solutions ideally CyberArk
- 3 years working as a Security Engineer or can demonstrate equivalent experience
- Experience working in Security Operations is highly desirable