Cyber Security GRC Engineer
الوصف الوظيفي
About the Role
We are looking for a dedicated and experienced Cyber Security GRC Engineer to join our team and play a pivotal role in safeguarding our organization’s digital infrastructure. In this position, you will be responsible for implementing, managing, and optimizing cybersecurity solutions to protect our systems, networks, and applications from an ever-evolving landscape of cyber threats. Your expertise will be critical in maintaining the integrity, confidentiality, and availability of our information assets while ensuring compliance with industry standards and regulatory requirements.
Key Responsibilities
As a Cyber Security GRC Engineer, your core responsibilities will include:
- Security Solution Deployment and Management: Implement, configure, and maintain a robust suite of cybersecurity solutions, including Firewalls, Endpoint Detection and Response (EDR), Web Application Firewalls (WAF), Vulnerability Management platforms, and Email Security Gateways. Ensure these solutions are optimized for maximum effectiveness and aligned with organizational security policies.
- Threat Monitoring and Incident Response: Proactively monitor security events and alerts to identify potential threats. Conduct thorough investigations into security incidents, analyze root causes, and implement corrective actions to mitigate risks. Your vigilance will be instrumental in minimizing the impact of cybersecurity breaches.
- Vulnerability Assessment and Remediation: Perform regular vulnerability assessments using industry-leading tools such as Tenable, Nessus, and Qualys. Collaborate with cross-functional teams to prioritize and remediate vulnerabilities, ensuring timely resolution to reduce exposure to cyber threats.
- Network and Application Security: Oversee network security controls, including DDoS protection mechanisms, to safeguard against disruptive attacks. Implement and enforce security best practices for web applications, ensuring robust protection against common vulnerabilities and exploits.
- Compliance and Reporting: Develop and maintain comprehensive security documentation, including policies, procedures, and incident reports. Prepare detailed security reports and actionable recommendations to support continuous improvement initiatives. Ensure adherence to relevant regulatory frameworks and industry standards.
- Collaboration and Training: Work closely with IT, development, and operations teams to integrate security best practices into business processes. Provide guidance and training to stakeholders on security awareness and compliance requirements.
Qualifications and Skills
To excel in this role, you should possess the following qualifications and experience:
- Education: A Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field is required.
- Experience: Minimum of 3 years of hands-on experience in cybersecurity operations, security engineering, or a related field. Proven expertise in deploying and managing security solutions is essential.
- Technical Proficiency: In-depth knowledge of cybersecurity technologies and platforms, including:
- Fortinet / FortiGate Firewalls
- CrowdStrike EDR for advanced threat detection and response
- Cloudflare for WAF and DDoS Protection
- Email Security Gateways to prevent phishing and malware attacks
- Vulnerability Management platforms such as Tenable, Nessus, and Qualys
- Security Expertise: Strong understanding of network security principles, threat detection methodologies, incident response protocols, and security best practices. Familiarity with security frameworks such as NIST, ISO 27001, or CIS Controls is highly desirable.
- Certifications: Relevant industry certifications such as Security+, NSE (Fortinet Network Security Expert), CEH (Certified Ethical Hacker), CISSP, or equivalent are preferred and will be considered a significant advantage.
Why Join Us?
As a Cyber Security GRC Engineer, you will have the opportunity to work in a dynamic and collaborative environment where your contributions directly impact the security posture of our organization. You will engage with cutting-edge technologies, tackle complex challenges, and play a key role in protecting our digital assets. We offer competitive compensation, professional development opportunities, and a supportive culture that values innovation, integrity, and excellence.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.