The Cyber Security Engineer at IT Horizons will play a crucial role in safeguarding IT Horizons and her client's technical systems by defining, operating, and enhancing security controls and monitoring systems.
This hands-on position requires collaboration with the Dev and CloudOps teams to secure production and corporate environments.
The Cyber Security Engineer will also be responsible for threat and vulnerability management and work with technical teams on remediation activities.
This is an excellent opportunity for an individual passionate about cybersecurity to make a significant impact in a dynamic and growing organisation.
Job Responsibilities
Operate and Enhance Security Monitoring Tools: Utilize and improve IT Horizons and client security monitoring tools to provide valuable intelligence to the business.
Support pre-sales engineers to create proposal documents, Bills of Material, and other technical
documents in response to RFQ, RFP, etc from ITH client
Manage the design, implementation and documentation of security systems (NextGen Firewalls, Intrusion Detection/Prevention Systems, Web Filtering, Application Firewall, Security Information and Information Management
Automate Audits and Monitoring: Automate the auditing and monitoring of technical systems to minimize manual activities within the security program.
Collaborate with CloudOps/Development/IT Support: Interface with these teams on findings and drive them to a conclusion as directed by the Head of Cyber Security.
Assist with Training: Provide support in training initiatives to enhance the cybersecurity knowledge within the organisation.
Compliance Support: Assist with the administrative process for current and future compliance standards.
Conduct Audits: Support the Security Lead in conducting audits of IT Horizons and her client systems, processes, and third parties.
Acquisition Integration: Take a lead role in the integration of newly acquired entities into IT Horizons and her client's security framework.
Skills and Experience
Strong communication skills
Experience in Vulnerability Management, including configuring, running, and analysing scans (Nessus preferred)
Experience in Web Vulnerability Management (OWASP Top 10, CWE Top 25)
Experience in SIEM configuration, analysis, and reporting
Experience with IPS/IDS and Data Loss Prevention tools, configuration, and analysis
Experience with threat analysis and reporting
Desirable Skills:
Community-recognised security certificates such as CEH, CISM, SANS (GSEC, GCIA, GCED, GCIH), CISSP
Minimum of 4 years experience
Exposure to compliance standards such as ISO 27001, Cyber Essentials, and/or PCI compliance
Exposure to DevOps/Agile development methodologies
Incident Response/Forensics experience, including evidence/artefact preservation
Experience integrating security checks and validation into a CI/CD pipeline