The Security Engineer is responsible for the group's information assets against evolving threats, ensuring data confidentiality, integrity, and availability.
Core duties include:
- Evaluating and implementing new security solutions and AI services
- Proactively assessing the security posture across on-premises networks and multi-cloud environments
- Managing Microsoft 365 security and enterprise data compliance strategies
- Architecting and deploying robust security controls
- Monitoring network activities and spearheading security incident response
- Raising employee security awareness
Responsibilities
Scope of Role
Infrastructure & Network Security
- Assess the security of information systems and networks, consistently identifying potential risks, vulnerabilities, and zero-day threats.
- Design and implement advanced security controls, including Firewalls, DLP, XDR, WAF and SOC operations etc.
- Monitor network traffic and activity for suspicious behavior and coordinate threat hunting operations.
Cloud & Microsoft Security
- Plan, manage, and optimize O365 enterprise security services, including Conditional Access, Intune, and Entra ID Protection.
- Implement data protection strategies using Microsoft Purview (e.g., managing sensitivity labels.
- Understand multi-cloud environments (Azure, AWS, GCP) and provide strategic planning and recommendations for cloud security.
Security Solutions Evaluation & Implementation
- Assist in the evaluation, planning, and implementation of new security solutions, ensuring secure adoption, seamless integration, and strict alignment with enterprise security architecture (Secure by Design).
- Lead Proof of Concept (PoC) phases for emerging cybersecurity technologies to address evolving business needs and threat landscapes.
Incident Response & SecOps Automation
- Investigate and respond to security incidents, determine the root cause, assess the impact, and execute swift corrective actions.
- Develop and integrate automated SecOps workflows using customized scripts (Python, PowerShell).
Security Culture
- Raise employee security awareness and conduct targeted security education and training.
Job Challenges
- The ever-evolving nature of security threats requires continuous learning and updating of knowledge.
- High-pressure work environment when dealing with incidents.
- Need to collaborate with people from different departments.
Requirements
- Bachelor’s degree in information security or a related field
- At least 3 years of relevant work experience.
- Hands-on experience with application, system, and network security
- Familiarity with cloud computing, Linux administration, and TCP/IP protocols
- Strong knowledge of security fundamentals and best practices
- Familiarity with network security, system security, application security, etc.
- Experienced in any of Microsoft Security solutions, EDR, SIEM, DLP, Firewall, SOC, Email Security, Vulnerability Assessment, WAF will be a plus.
- Strong analytical and problem-solving skills
- Excellent communication skills in English (TOEIC 700+ preferred) and teamwork skills
- Certificates: Candidates with Security or M365 related certifications (e.g. CISSP, CISM, CISA, ISO27001, MS-102, SC-100, MD-102) will be a plus.