Network Security Engineer
Role Overview
The Network Security engineer will support the day-to-day operations and development of the bank security suite of products with key objective in maintain, develop and enhance the detection, prevention, response and monitoring capabilities of GSOC.
Key Responsibilities
- Support a wide array of security solutions and infrastructure deployed within the bank.
- Propose, develop, test and manage application, system and infrastructure changes, upgrades, troubleshooting, patch and improvements.
- Drive upgrades and migration to ensure solutions and or related platform are maintained in tip-top working conditions with proper documentation and RCA.
- Implement new technology and process improvements for the bank.
- Manage IDS and APT appliances, end-to-end configurations, replacement of the devices etc.
- Manage and support the log management environment.
- Manage and coordinate change process engagement with regards to current security solutions.
- Understand the security data lake of the bank.
- Provide support for all Audit requests related to IDS, NDR, CAS and APT solution.
- Knowledge on Proxy, Firewalls etc.
- Research and define requirements for new projects, perform product evaluation and technical Proof of Concept.
Others
- Work within established practices and handling guidelines to triage device outages.
- Work with internal technical teams and engineers in technical troubleshooting, exercises and forums.
- Available to respond to any requests and assist with troubleshooting activities along with proper documentation.
- Resolve standard/routine issues with no guidance and complex/unusual issues with minimal guidance.
- Communicate effectively with a variety of internal teams and external contacts including technical and executive contacts.
- Capable of juggling variety of priorities and deliverables in an operational, interrupt driven environment with minimal guidance or supervision.
- Provide Level 1 support for other log management solutions like SIEM, ASA etc.
Technical Skills
- 8+ years of relevant experience in similar capacity or candidates without relevant experience are welcome to apply. Training will be provided for selected candidates without relevant experience.
- Good knowledge in network security (i.e. Switches/Routers, Firewalls, WAF, IDS, IPS, APT, VPN, HIPS, ADS and TCP/IP protocols).
- Hands-on experience in Unix/Linux and Windows administration.
- Hands-on experience in managing Cisco Sourcefire IDS & FireEye APT solutions.
- Good understanding of policies/rules in IDS. Should be able to create & fine tune policies/rules in IDS.
- End-to-End Integration of New Segments in IDS monitoring, TAPS Integration.
- Troubleshooting IDS & FireEye APT operational issues and fixing it within SLA.
- Drive upgrades and migration of IDS, NDR, CAS & APT solutions to ensure solutions and or related platform are maintained in tip-top working conditions with proper documentation and RCA.
- Good understanding of internet concepts and technologies – internet services, search engines, open-source tools, mobile technology, LAMP, IOT, TOR etc.
- Good understanding of network forensics and packet analysis.
- Minimal 2 years of relevant working experience in a SOC environment and related processes