M01 - Cyber Platform Engineer
Responsibilities
- Operate, maintain, and support enterprise cybersecurity platforms, including Palo Alto Firewalls, Carbon Black EDR, Cloudflare DDoS/WAF, and CyberArk PAM.
- Perform preventive maintenance, system health checks, patching, firmware upgrades, configuration changes, and troubleshooting across cybersecurity platforms.
- Manage Palo Alto Firewalls, including firewall policies and rules, NAT, routing, security profiles, logs, configuration backups, and vulnerability remediation.
- Maintain and troubleshoot Carbon Black EDR, including servers, endpoint sensors, PostgreSQL/Solr components, application services, logs, and endpoint onboarding.
- Administer Cloudflare DDoS/WAF, including website onboarding/offboarding, security rules, IP whitelisting/blacklisting, SSL certificates, access reviews, and log reviews.
- Administer CyberArk PAM, including privileged account onboarding/offboarding, access reviews, password management, service requests, and audit activities.
- Monitor cybersecurity platforms and investigate system, security, application, and audit logs for anomalies and operational issues.
- Support vulnerability management, security assessments, audits, incident investigations, and remediation activities.
- Manage backup and restoration activities, including configuration backups, restoration testing, and maintenance of backup records.
- Raise and manage change requests in accordance with established change management processes.
- Maintain technical documentation, including SOPs, asset inventories, configuration records, troubleshooting guides, security trackers, and maintenance reports.
- Work closely with internal security teams, vendors, OEMs, and technical stakeholders to resolve platform issues.
- Ensure cybersecurity platforms comply with organisational security policies, the Cybersecurity Act, and Cybersecurity Code of Practice (CCoP).
- Provide onsite support at secure premises for scheduled maintenance and ad-hoc troubleshooting when required.
Requirements
- Strong knowledge of enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.
- Hands-on experience with Palo Alto Networks Next-Generation Firewalls or equivalent enterprise firewall platforms.
- Experience managing firewall policies, NAT, routing, security profiles, logs, firmware upgrades, patching, and configuration backup/restoration.
- Hands-on experience with Carbon Black EDR or equivalent Endpoint Detection and Response (EDR) platforms.
- Experience with Cloudflare or equivalent DDoS mitigation/WAF solutions, including security rules, SSL certificates, IP whitelisting/blacklisting, and log management.
- Experience with CyberArk PAM or equivalent Privileged Access Management solutions.
- Good understanding of vulnerability management, security hardening, patch management, change management, and cybersecurity incident response.
- Understanding of highly secured network environments, including air-gapped networks, restricted connectivity, offline patch/file transfers, and data diodes/unidirectional gateways.
- Familiarity with PKI and TLS/SSL certificate lifecycle management is advantageous.
- Experience supporting cybersecurity platforms within CII, highly secured, segregated, or air-gapped environments is advantageous.
- Able to provide onsite support and undergo the required security clearance.
PreferredCertifications
- CCNA or equivalent networking certification.
- Relevant Palo Alto Networks firewall certification.
- CyberArk Defender – PAM; CyberArk Sentry – PAM is advantageous.
- Relevant Cloudflare WAF/DDoS certification or training is advantageous.