Responsibilities
Purpose of the role
As the Security Engineer, you will support the design, implementation, integration and continuous improvement of enterprise security controls across corporate, cloud and hybrid environments. You will strengthen the organisation's security posture through hands-on engineering of enterprise security platforms, secure logging and monitoring, endpoint protection, access management, email and web security, and security operations enablement.
Scope of the role
The major focus of this role is to provide hands-on security architecture and engineering support for the enterprise security stack, including (but not limited to) SIEM, endpoint detection and response, secure web gateway, email security, log onboarding, cloud security integrations, vulnerability and exposure management tooling and access management execution support. The role works closely with security operations, IAM, infrastructure, cloud, application, workplace technology and vendors to ensure security controls are implemented, integrated, documented and operationally sustainable.
Key Responsibilities
- Security Architecture & Engineering
- Design, implement and support enterprise security controls across endpoint, identity integration, network, email, web, cloud and monitoring domains.
- Support engineering and integration of enterprise security platforms such as SIEM, EDR/XDR, secure web gateway, email security, vulnerability and exposure management, and related security tooling.
- Develop secure integration patterns between security platforms, infrastructure, cloud services and security operations workflows.
- Support solution design reviews and translate security requirements into practical implementation plans, technical designs and handover documentation.
- Security Monitoring, Logging & Detection Enablement
- Coordinate onboarding of security logs from enterprise, cloud, application, infrastructure, network and critical systems into central monitoring platforms.
- Ensure log sources are complete, reliable, correctly parsed and aligned with detection, audit and compliance requirements.
- Work with security operations teams to support detection use case testing, alert validation, tuning and incident response readiness.
- Track and resolve log onboarding gaps, data quality issues and integration defects.
- Privileged Access Management Support
- Support implementation, migration and operational management of privileged access management controls in alignment with the IAM architecture and strategy.
- Work with the IAM Architect, infrastructure, application and operations teams to onboard systems, accounts and privileged workflows into the PAM platform.
- Support PAM-related testing, migration planning, user acceptance, operational handover, documentation and issue resolution.
- Assist with privileged access hygiene activities, including privileged account reviews, service account onboarding, access key rotation support and exception tracking.
- Security Platform Delivery & Operational Support
- Support implementation, upgrade, migration and enhancement activities across the enterprise security stack.
- Perform technical testing, validation and troubleshooting of security platform integrations.
- Coordinate with vendors, managed service providers, infrastructure teams and application owners to resolve security platform issues.
- Maintain technical documentation covering architecture decisions, configurations, integration flows, risks, dependencies and operational procedures.
- Risk, Remediation & Stakeholder Management
- Support security assessments for new systems, cloud services, vendor solutions and technology changes.
- Identify security risks, control gaps and remediation options, and communicate them clearly to technical and non-technical stakeholders.
- Track security remediation actions, operational follow-ups and exceptions through to closure.
- Provide security advisory support to project teams to help ensure secure-by-design implementation.
Foundation Competencies
- Strong analytical, problem-solving and critical thinking skills.
- Effective communication and stakeholder management skills across technical and non-technical teams.
- Self-driven team player capable of working independently and managing multiple priorities.
- Strong documentation discipline and ability to produce clear technical decisions, risks and remediation actions.
- Willingness to support urgent security issues or implementation activities when required.
Functional Competencies
- Good working knowledge of SIEM, log management, EDR/XDR, secure web gateway, email security, PAM, IAM concepts, cloud security and security assessments.
- Experience supporting security platform implementation, migration, integration or enhancement activities.
- Good understanding of security logging, monitoring, detection use cases, privileged access controls and infrastructure security.
- Ability to analyse technical issues and translate them into practical security actions.
- Ability to work effectively with security operations, IAM, infrastructure, cloud, application, vendors and managed service providers.
Experience
- Relevant experience in cybersecurity engineering, security operations, infrastructure security, cloud security or security architecture.
- Experience supporting enterprise security platforms, security monitoring, IAM/PAM, endpoint security, email security, web protection or security review processes.
- Experience in regulated, critical infrastructure, media, technology, telecommunications or large enterprise environments will be advantageous.
- Experience working with managed security service providers or outsourced security operations teams will be advantageous.
Qualifications
- Bachelor's degree or equivalent experience in Cybersecurity, Information Technology, Computer Science, Engineering or a related field.
- Relevant certifications such as CISSP, CISM, CCSP, GIAC, Microsoft Security, AWS Security, Azure Security or equivalent will be advantageous.