Senior Cyber Security Engineer
Job Summary
Role Overview:
Senior technical owner of the companys cybersecurity controls with particular responsibility for application security and for security audit and compliance.
Key Responsibilities:
- Application security: embed security into the SDLC threat modelling secure code review and remediation follow-up.
- Penetration testing: scope and manage internal and third-party application and infrastructure tests and drive findings to closure.
- Security audit: lead internal and external audits customer assessments and certification cycles; prepare evidence and close findings.
- Compliance and frameworks: maintain controls policies and standards against ISO 27001 NIST CSF / CIS Controls and applicable regulation.
- Risk management: identify assess and report information security risks and track treatment plans.
- Vulnerability management: run the scanning and patching cycle with risk-based prioritization and SLAs.
- SIEM and monitoring: maintain log coverage correlation rules and alert tuning; ensure critical systems are monitored.
- EDR / endpoint security: administer and tune the EDR/XDR platform maintain coverage and perform threat hunting.
- Network and perimeter security: manage Fortinet FortiGate firewall policies IPS and web filtering SSL inspection VPN and rule recertification.
- Identity and access management: govern authentication MFA SSO privileged access and periodic access reviews.
- Cloud security: define and verify hardening baselines and configuration for Azure.
- Data protection: set standards for encryption key management data classification and DLP.
- Incident response: act as senior responder; maintain and exercise playbooks and lead post-incident reviews.
- Third-party security: assess vendors and SaaS providers and set contractual security requirements.
- Awareness and reporting: deliver security training and phishing simulations; report metrics to management.
Qualifications :
Qualifications and Experience:
- Degree in Computer Science Information Security or Engineering or equivalent experience.
- 68 years in cybersecurity including a senior or lead role.
- Hands-on application security experience: secure SDLC threat modelling SAST/DAST/SCA secure code review OWASP Top 10 / ASVS.
- Proven experience leading security audits and compliance work (ISO 27001 NIST CSF CIS or SOC 2).
- Solid command of cybersecurity essentials: risk IAM network cloud endpoint cryptography vulnerability management and incident response.
- Hands-on SIEM experience (e.g. Forti SIEM) log onboarding use cases alert tuning.
- Hands-on EDR/XDR experience (e.g. Defender for Endpoint CrowdStrike).
- Hands-on Fortinet FortiGate firewall administration (policies IPS VPN FortiManager / FortiAnalyzer).
- Experience with at least one major cloud platform and modern CI/CD toolchains.
- Ability to read code in at least one mainstream language and engage credibly with developers.
- Preferred certifications: CISSP CISM CISA CSSLP ISO 27001 Lead Auditor Fortinet NSE 4 OSCP or SC-200.
Additional Information :
Soft skills:
- Excellent organizational skills (ability to prioritize plan tasks and respect deadlines).
- Good interpersonal skills.
- Teamwork skills/team spirit.
- Ability to work under stress and respond to tight deadlines.
- High level of autonomy/self-discipline.
- Proactiveness.
- Curious keen to learn and ready for new challenges.
- Ability to work independently.
Languages:
- Excellent verbal and written communication skills in English
- Knowledge of any other language is a plus (French)
Remote Work :
No
Employment Type :
Full-time
About Company
Jobs for Humanity paves the way to a fairer future for all by connecting historically underrepresented talent to welcoming employers. Through the combination of cutting-edge recruiting technology and expert D&I consultation, Jobs for Humanity makes inclusive hiring seamless, scalable, ... View more