PRIME FUNCTION
|
Administer, monitor, and optimize the enterprise security stack—spanning endpoint detection and response (EDR), data loss prevention (DLP), cloud security posture management (CSPM), vulnerability management, and Zero Trust Network Access (ZTNA). Drive incident remediation, policy tuning, and compliance reporting across a large-scale enterprise environment. |
JOB DESCRIPTION / RESPONSIBILITIES
-
Endpoint Security: Manage CrowdStrike Falcon (EDR, NGSIEM, Spotlight); fine-tune policies (AV, USB, Network) and lead threat hunting/incident response.
DLP & SASE: Design DLP rules (Forcepoint, Netskope, Zscaler) using regex/fingerprinting; drive ZTNA migration and resolve data leakage incidents.
Vulnerability Management: Run Tenable Nessus scans, track patch remediation SLAs with IT teams, and produce executive compliance reports.
Cloud Security: Monitor AWS Security Hub & Azure/Microsoft Defender; fix IAM/CSPM misconfigurations and support F5 WAF onboarding.
Email & Threat Intel: Configure email security (Forcepoint ESG, M365 EOP) and triage dark web compromised credential alerts.
Automation & SOPs: Build Python/SQL scripts to automate reporting workflows and maintain operational SOPs and audit records.
AUTHORITY
Policy Configuration: Authorized to configure and tune security policies across CrowdStrike, Forcepoint, Zscaler, Netskope, and Cloud Security tools.
Incident Containment: Authorized to execute host isolation, force password resets, terminate sessions, and enforce MFA during active security incidents.
Access Mapping: Authorized to map app segments and define granular access controls for ZTNA network migration.
JOB SPECIFICATION / COMPETENCY
-
Education: Bachelor’s degree in computer science engineering, Information Technology, Cybersecurity, or a related discipline (MBA in Information Systems is a plus).
Preferred Certifications:
- CrowdStrike Certified Falcon Administrator (CCFA) or equivalent EDR certification.
- AWS Certified Cloud Practitioner / Azure Security Engineer Associate (AZ-500).
- CompTIA Security+, Certified Ethical Hacker (CEH), or equivalent security credentials.
PERFORMANCE MEASURES
-
SLA Compliance: Percentage of security and DLP incidents triaged and resolved within operational SLAs.
Vulnerability Remediation Rate: Timely closure of high and critical vulnerabilities based on target SLAs.
False Positive Reduction: Reduction in alert noise via effective policy tuning across EDR, DLP, and Email gateways. -
Cloud Risk Reduction: Reduction of high-severity IAM and CSPM misconfiguration findings.
Audit & Documentation: Quality and up-to-date status of SOPs and investigation audit records.