Job description
Role Overview
- The role involves managing and supporting a suite of active and passive security tools to ensure robust protection, compliance, and operational efficiency. The emphasis is on real-time incident response, asset coverage, configuration management, and remediation of security incidents for the organization's globally distributed user base.
Key Responsibilities
Active Protection :
Tools : SentinelOne, Zscaler (ZIA, ZPA), Mimecast.
Responsibilities :
Onboard users and devices to security platforms ensuring effective coverage.Manage platform configurations, including creating and updating security policies.Drive automated and manual remediation for security incidents and violations.Perform system health checks, platform updates, and report generation.Analyse security logs using tools like Splunk.Passive Protection
Tools : Algosec, Wiz.io, Tanium, Splunk.Responsibilities :
Onboard and configure multi-vendor assets to ensure compliance.Manage and optimize platform signal-to-noise ratio for meaningful insights.Execute remediation strategies leveraging platform automation.Administer and maintain tools to track asset inventory, endpoint compliance, and vulnerabilities.Develop dashboards and reporting using Splunk.Required Skills & Competencies
Active Protection Platforms :
Proficiency in managing SentinelOne, Zscaler (ZIA, ZPA), and Mimecast, including advanced features such as endpoint posture checks, DNS control, and DMARC compliance.Familiarity with Windows, Linux, and macOS environments.Passive Protection Platforms :Experience with Algosec Firewall Analyzer, Wiz.io CSPM, and Tanium Asset Management.Proficiency in Splunk administration, including SPL and Common Information Model (CIM).General Skills
Education : Bachelor's degree in computer science, Information Security, or a related field. Relevant certifications are a plus.Strong understanding of any one of the hyperscaler environments (Azure or AWS).Familiarity with CIS security benchmarks and cloud security governance.Proficiency in scripting languages such as Bash or PowerShell.Analytical skills for log and threat analysis.Skills Required
Splunk, Dns, CSPM, Aws