Security Engineer
Security Engineer
Job Purpose
Responsible for supporting the design, implementation, and governance of enterprise cybersecurity controls to protect the organization's applications, infrastructure, cloud environments, networks, and information assets. Conducts security architecture reviews, evaluates identity and access management controls, administers network and endpoint security technologies, performs third-party and cloud security assessments, and supports threat monitoring, incident response, and compliance activities. Collaborates with cross-functional teams to embed security-by-design principles into projects, strengthen the organization's security posture, ensure regulatory and policy compliance, and support the secure delivery of business and technology initiatives.
Key Result Responsibilities
- Conduct security architecture reviews for new applications, SaaS platforms, APIs, cloud services, integrations, and infrastructure changes.
- Review application data flows, authentication, authorization, encryption, logging, secrets management, retention, and third-party integrations.
- Assess security controls including SSO, MFA, RBAC, API security, WAF protection, session management, data masking, and audit logging.
- Provide security approvals, remediation requirements, and risk-based recommendations.
- Embed security-by-design principles and threat modeling into project and change processes.
- Review Microsoft Entra ID application registrations, OAuth 2.0, OpenID Connect, SAML, Microsoft Graph API permissions, and service accounts.
- Review privileged access, service accounts, application secrets, conditional access, MFA, and role-based access controls.
- Enforce least-privilege and periodic access recertification across privileged and service identities.
- Manage and maintain enterprise firewalls, VPNs, SD-WAN, routing, NAT, web filtering, application control, and IPsec tunnels.
- Perform firewall health checks, firmware upgrades, rule reviews, policy optimization, and security hardening.
- Troubleshoot firewall, VPN, routing, DNS, certificate, and connectivity-related issues.
- Manage and support WAF platforms such as Cloudflare WAF, HAProxy WAF, FortiWeb, or similar technologies.
- Tune WAF rules, custom signatures, rate limiting, and bot mitigation to protect public-facing applications.
- Support SSL/TLS certificate purchase, deployment, renewal, and troubleshooting.
Key Result Responsibilities-Continued
- Administer and improve Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Attack Surface Reduction rules, exclusions, indicators, and endpoint security policies.
- Tune anti-phishing, anti-spoofing, and anti-malware policies, including SPF, DKIM, and DMARC alignment. [added]
- Investigate endpoint, email, firewall, WAF, SIEM, and cloud security alerts.
- Support security incident investigations and coordinate containment and remediation activities.
- Contribute to threat hunting and align detection with MITRE ATT&CK where applicable.
- Assess SaaS solutions, cloud platforms, AI tools, browser extensions, APIs, and other third-party services.
- Review supplier security documentation including SOC 2 reports, ISO 27001 certifications, data-processing agreements, privacy documents, incident response procedures, and business continuity arrangements.
- Support internal and external audits by providing security documentation, access-control evidence, firewall review records, and remediation updates.
- Maintain documentation for security approvals, exceptions, risk acceptances, architecture decisions, and security assessments.
- Support cybersecurity projects including firewall upgrades, new site deployments, WAF migrations, SIEM integrations, endpoint protection, cloud security, and identity security improvements.
- Coordinate with internal teams, business owners, suppliers, and security vendors to ensure timely closure of security actions.
Qualifications (Academic, training, languages)
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
- Fluent in English Language
- Strong analytical and risk-based decision-making skills.
- Excellent written documentation and clear communication with technical and business stakeholders.
- Ability to manage multiple priorities and coordinate across teams, suppliers, and vendors.
- Scripting/automation skills (PowerShell, Python, or Bash) for security tasks and integrations.
- Proficient in MS Office.
- Exposure to VAPT concepts and secure code review to inform architecture decisions.
- Working knowledge of Microsoft Entra ID, OAuth 2.0, OpenID Connect, SAML, and Microsoft Graph API permissions.
- Detail-oriented, with a proactive and continuous-learning mindset for evolving threats.
- Ability to work both independently and within cross-functional teams.
- Familiarity with security frameworks and standards: ISO 27001, NIST, OWASP, and MITRE ATT&CK.
Work Experience
- With 4-6 years of hands-on experience in security engineering, network security, or security architecture. Industry certifications such as CISSP, CCSP, SC-100 / SC-200, Security+, CCNP Security, Fortinet NSE, or PCNSE are preferred.
- Experience with SIEM/SOAR platforms and log correlation for threat detection.
- Experience administering Microsoft Defender for Endpoint and Defender for Office 365.
- Practical experience with enterprise firewalls (e.g., Palo Alto, FortiGate, Cisco), VPNs, SD-WAN, routing, and NAT.
- Experience with WAF platforms (Cloudflare, HAProxy, FortiWeb, or similar).
- Experience assessing third-party and SaaS security (SOC 2, ISO 27001, DPAs).