Sobre este puesto de Infrastructure Cybersecurity Engineer en Assurity Trusted Solutions
As an Infrastructure Cybersecurity Engineer, you will be embedded within the Infrastructure division as the subject matter expert (SME) for all cybersecurity-related matters, playing a critical role in safeguarding the organisation's enterprise IT infrastructure against security threats and vulnerabilities. You will serve as the go-to resource for the infrastructure team on security guidance, standards, and best practices, while contributing to the overall security posture of the organisation and protecting sensitive data and assets from potential breaches and attacks across network, applications, systems, and cloud environments. A key aspect of this role involves applying offensive security knowledge and penetration testing expertise to proactively identify and address weaknesses before they can be exploited.
You will be working on:
- Serving as the cybersecurity SME within the Infrastructure division, providing expert guidance and advisory to infrastructure teams on security-related decisions, designs, and operations.
- Designing and implementing secure architecture for the organisation's IT infrastructure, including network segmentation, secure configurations, and access controls to establish a robust security foundation.
- Conducting and coordinating penetration testing and vulnerability assessments across network and infrastructure environments, translating findings into actionable remediation plans.
- Identifying, assessing, and remediating vulnerabilities across servers, network devices, and cloud services to reduce the risk of exploitation and maintain a strong security baseline.
- Implementing and managing security monitoring tools and technologies — including intrusion detection systems and SIEM solutions — to detect, investigate, and respond to security incidents in a timely manner.
- Managing user access and privileges within the infrastructure, implementing strong authentication mechanisms, and enforcing least privilege principles as part of a comprehensive Identity and Access Management framework.
- Ensuring that the organisation's infrastructure complies with relevant security standards, regulations, and industry best practices, such as CIS benchmarks, NIST guidelines, and ISO 27001.
- Participating in incident response activities related to infrastructure security incidents, covering analysis, containment, eradication, and recovery.
- Implementing and managing security tools and technologies such as firewalls, endpoint protection, and encryption solutions to enhance the overall infrastructure security posture.
- Securing cloud environments through configuration management, data encryption, and adherence to cloud security best practices across public cloud platforms.
- Promoting security awareness and best practices among IT teams and stakeholders, fostering a culture of security across the organisation.
Requirements
- Minimum 2 years of relevant experience in a security engineering role, with a focus on infrastructure security, network security, or systems security.
- Offensive Security Certified Professional (OSCP) is required.
- Hands-on experience conducting network or infrastructure penetration testing, including scoping, execution, and reporting of findings to both technical and non-technical audiences.
- Demonstrated ability to function as a cybersecurity SME, advising and influencing technical teams on security matters and translating complex security concepts for non-technical stakeholders.
- Additional professional certifications such as CISSP, CEH, CISM, CCSP, or equivalent are an advantage.
- Proficient in network security, system security, cloud security, and infrastructure security best practices.
- Hands-on experience with security technologies including firewalls, intrusion detection and prevention systems, VPNs, endpoint security, and encryption.
- Experience with security tools and platforms including SIEM solutions, vulnerability scanners, penetration testing tools (e.g. Metasploit, Nmap, Burp Suite), and security monitoring systems.
- Familiarity with risk assessment and risk management principles, including the ability to identify, assess, and mitigate security risks within complex infrastructure environments.
- Working knowledge of security standards and frameworks such as ISO 27001, NIST, CIS benchmarks, and relevant compliance requirements.
- Experience securing cloud environments across public cloud platforms such as AWS, Azure, or Google Cloud.
- Strong communication and collaboration skills, with the ability to articulate security requirements and provide guidance to both technical teams and non-technical stakeholders.
- Strong analytical and problem-solving skills to identify and address security challenges across the infrastructure landscape
Benefits
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programmes.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.