Job Description
We are seeking a Cybersecurity Engineer to support the day-to-day operations and maintenance of organization’s cybersecurity infrastructure and security services. The role focuses on firewall and WAF administration, SIEM operations, vulnerability management, and security monitoring.
The successful candidate will maintain security platforms, monitor the health of security controls, coordinate remediation with stakeholders, and prepare operational reports and dashboards. They will also assist in troubleshooting firewall, WAF, and network security issues as needed.
Key Responsibilities
- Administer, maintain, and support on-premises firewalls, cloud-based network security controls, and related security infrastructure, including policy implementation, rule reviews, software upgrades, patching, and lifecycle management.
- Perform health monitoring, preventive maintenance, and operational support for firewall platforms to ensure optimal performance, availability, and security.
- Execute firewall policy changes, troubleshoot firewall-related issues, and resolve network connectivity issues arising from security configurations and policies.
- Configure, administer, and maintain Web Application Firewall (WAF) platforms, including policy deployment, rule management, policy tuning, signature updates, virtual patching, false-positive reviews, and ongoing operational support.
- Monitor and analyse firewall, WAF, and security monitoring logs to identify operational issues, suspicious activities, and potential security concerns, escalating issues where necessary.
- Monitor SIEM agent health across servers, coordinate with stakeholders to resolve issues, onboard new systems, and perform completeness checks to validate log coverage.
- Support SIEM operations, including log onboarding, data source integration, log coverage validation, alert monitoring, dashboard maintenance, and operational support.
- Develop and maintain security dashboards, reports, and operational metrics using SIEM and security management tools to support operational monitoring and management reporting.
- Monitor and track security alerts generated from security platforms and coordinate with relevant stakeholders to ensure timely investigation and remediation.
- Manage the end-to-end Vulnerability Management lifecycle, including vulnerability assessments, remediation tracking, consolidation of remediation status, stakeholder follow-up, and preparation of management reports.
- Review vulnerability assessment findings affecting infrastructure and web applications and collaborate with stakeholders to implement remediation measures or compensating controls through firewall and WAF technologies where appropriate.
- Assist in periodic reviews of firewall and WAF policies, configurations, logs, and rule bases, and prepare operational reports and recommendations for stakeholders.