Cyber Platform Engineer

Summary

Operate and maintain the Board's core cybersecurity platforms (Carbon Black EDR, Palo Alto firewalls, Cloudflare DDoS mitigation, CyberArk PAM), performing preventive maintenance, patching, log/account reviews, audits, and reporting across Critical Information Infrastructure sites.

The Cyber Platform Engineer will be responsible for the operational administration, maintenance, and lifecycle management of the Board’s key cybersecurity platforms: Carbon Black EDR, Palo Alto Perimeter Firewalls deployed across the Board's Critical Information Infrastructure (CII) sites, the Cloudflare DDoS Mitigation Services (DMS) protecting the Board's internet-facing web assets, and the CyberArk Privileged Access Management (PAM) platform governing privileged account access across the Board's environment.

The engineer will execute routine and ad-hoc maintenance activities to ensure the continuous functioning, security compliance, and operational integrity of these platforms. This includes performing scheduled preventive maintenance, managing onboarding and offboarding of assets and accounts, conducting access and log reviews, supporting security assessments and audits, and coordinating with relevant contractors and internal teams. The engineer shall also produce maintenance reports according to Board requirements for every maintenance cycle.

This role requires strong discipline around cybersecurity, change management, and documentation, and the engineer shall ensure all activities are compliant with the Board's cybersecurity policies and the Cybersecurity Code of Practice (CCoP).

Roles and Responsibilities

Palo Alto Firewall Operations & Maintenance

  • Perform comprehensive quarterly preventive maintenance of all onsite perimeter firewalls, meaning onsite visits to all Board's sites, covering health checks, software patching and firmware updates, and diagnostic checks.
  • Conduct quarterly log and account reviews to detect anomalies and ensure compliance with the Board's cybersecurity policies.
  • Perform patching and mitigations based on the Board's patch management timeline: Critical vulnerabilities within 45 days, High and Medium within 60 days, and Low within 90 days.
  • Perform annual firewall configuration and rules reviews, annual review of hardware and software application lists, and other periodic security reviews as required by the Board's cybersecurity policy.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available