This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Senior Associate Security Platform Engineer is a developing subject matter expert, responsible for facilitating problem resolution and mentoring for the overall team. This role performs operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). The Senior Associate Security Platform Engineer is responsible for detecting and monitoring escalated threats and suspicious activity affecting the organization's technology domain (servers, networks, appliances and all infrastructure supporting production applications for the enterprise, as well as development environments).
Job Responsibility:
Works as part of a 24/7 team working on rotational shifts
Works as part of Platform and Content Engineering handling tunings, stake holder requests, escalations, reporting, trainings
Administers the organization's security tools to gather security logs from environment
Lifecycle management of the supported security tools/technologies, Break-fix, Patching, Live update
Adheres to SOPs and notify stake holders on log flow/log format issues
Documents best practices
Identifies opportunities to make automations which will help the incident response team
Performs security incident handling and response from several vectors including End Point Protection and Enterprise Detection and response tools, attack analysis, malware analysis, network forensics, computer forensics, and a broad range of skills in LAN technologies, Windows and Linux O/S’s, and general security infrastructure
Carries out agreed maintenance tasks
Ensures usage of knowledge articles in incident diagnosis and resolution and assist with updating as and when required
Performs defined tasks to monitor service delivery against service level agreements and maintains records of relevant information
Investigates causes of incidents and seeks resolution
Escalates unresolved incidents and follow up until incident is resolved
Provides service recovery, following resolution of incidents
Document and close resolved incidents according to agreed procedures
Requirements:
Bachelor's degree or equivalent in Information Technology or related field
Relevant level of Networking certifications such as CCNA, JNCIA, ACCA, PCNSA, CCSA etc. preferred
Relevant level of Security certifications such as AZ-500, SC-200, Security+, CEH, CISSP, CISM etc. will be added advantage
Moderate level experience in Security technologies like (Firewall, IPS, IDS, Proxy etc.)
Moderate level experience in technical support to clients
Moderate level experience in diagnosis and troubleshooting
Moderate level experience providing remote support in Security Technologies
Moderate level experience in SOC/CSIRT Operations
Moderate level experience in handling security incidents end to end
Knowledge on networking, Linux and security concepts
Moderate level experience in configuring/managing security controls such as Firewall, IDS/IPS, EDR, NDR, UTM, Proxy, SOAR, HoneyPots and other security tools
Knowledge on log collection mechanism such as Syslog, Log file, DB API
Knowledge in security architecture
Moderate level experience in Security engineering
Nice to have:
Working knowledge on implementation and monitoring of any SIEM or security tools/technologies
Knowledge on security architecture, worked across different security technologies
Customer service orientated and pro-active thinking
Problem solver who is highly driven and self-organized
Great attention to detail
Good analytical and logical thinking
Excellent spoken and written communication skills
Team player with the ability to work well with others and in group with colleagues and stakeholders