Senior Information & Network Security Engineer
Own and continuously improve the organization's information security and network security controls.
Monitor networks, servers, endpoints, applications, cloud environments, and security logs for suspicious activity and threats.
Configure, manage, and periodically review firewalls, VPNs, routers, switches, network access controls, WAF, IDS/IPS, and related security technologies where applicable.
Design and maintain secure network architecture, segmentation, remote access, and internet-facing service protection.
Perform vulnerability assessments, prioritize findings by risk, and coordinate remediation with infrastructure, software, DevOps, and external vendors.
Manage security hardening and patching requirements for servers, operating systems, databases, endpoints, network devices, and cloud services.
Implement and review Identity and Access Management (IAM), Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), Least Privilege, and privileged access controls.
Perform periodic user and privileged-access reviews and identify excessive, orphaned, or unnecessary permissions.
Operate or support SIEM, EDR/XDR, endpoint protection, security monitoring, and alerting tools.
Investigate cybersecurity incidents and coordinate containment, eradication, recovery, Root Cause Analysis, evidence/documentation, and corrective actions.
Maintain incident response procedures and escalation paths for critical security events.
Review application, API, infrastructure, and integration security requirements with development and DevOps teams.
Coordinate vulnerability remediation, penetration testing, and security assessments with internal teams and external cybersecurity providers.
Assess security risks introduced by third-party vendors, outsourcing partners, external integrations, and cloud services.
Support backup, disaster recovery, business continuity, and recovery-security controls.
Develop and maintain security policies, standards, procedures, risk registers, technical documentation, and remediation tracking.
Support security audits, compliance assessments, awareness initiatives, and management reporting.
Provide clear management reports covering incidents, vulnerabilities, risks, remediation status, control gaps, and priority actions.
NETWORK SECURITY RESPONSIBILITIES
- Secure LAN, WAN, Wi-Fi, remote connectivity, VPNs, and internet-facing network services.
- Configure and review firewall rules, access control lists, routing/security rules, and network segmentation.
- Detect abnormal traffic, unauthorized access attempts, scanning, brute-force activity, and other suspicious network behavior.
- Troubleshoot security-related network incidents while maintaining availability and operational continuity.
- Work with infrastructure teams to ensure secure configuration, monitoring, and lifecycle management of network devices.
INFORMATION SECURITY RESPONSIBILITIES
- Maintain and implement information security policies, standards, and technical controls aligned with recognized security practices.
- Support asset inventory, access governance, data classification, data protection, and periodic security reviews.
- Perform and document security risk assessments and remediation plans.
- Support business continuity, disaster recovery, compliance, and audit readiness.
- Promote practical security awareness and secure working practices across the organization.
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, Network Engineering, or a related field.
4+ years of practical experience in Information Security, Cybersecurity, Network Security, or a closely related role.
Strong knowledge of TCP/IP, routing, switching, DNS, DHCP, VPNs, firewalls, network segmentation, and secure remote access.
Hands-on experience with Windows and/or Linux security and system hardening.
Practical experience with vulnerability management, patching coordination, endpoint protection, and security monitoring.
Good understanding of IAM, MFA, authorization, RBAC, Least Privilege, and privileged account security.
Understanding of common cyber threats, vulnerabilities, attack vectors, incident response, and security investigation techniques.
Good understanding of web application and API security fundamentals, including OWASP concepts.
Strong troubleshooting, analytical, documentation, communication, and risk-prioritization skills.
PREFERRED EXPERIENCE & CERTIFICATIONS
- SIEM platforms, Microsoft Defender, EDR/XDR, WAF, IDS/IPS, vulnerability scanners, or SOC operations.
- Microsoft Azure Security, AWS Security, or other cloud security environments.
- ISO 27001, NIST Cybersecurity Framework, CIS Controls, OWASP, DevSecOps, DLP, Business Continuity, or security audit experience.
- Relevant certifications are an advantage, including Security+, CCNA/CCNP Security, Cisco CyberOps, CEH, ISO 27001, Fortinet certifications, Microsoft Security certifications, or CISSP for more experienced candidates.