Lead Operational Engineer L3 -Platform and Endpoint Security
Emirates
- United Arab Emirates
- Permanent
- Full-time
- Manage critical incidents and challenges as the focal point of contact for major incidents. Coordinate with other departments during critical incidents and drive post-incident reviews and formulate preventive strategies.
- Detect, identify, and respond to possible cyber-attacks, intrusions, anomalous and misuse activities as well as evaluate incident triage activities to ensure optimum incident resolution including the ownership of escalated incidents.
- Analyse network traffic and system data to detect potential threats to resources and provide recommendations for remediation. Conduct analysis that encompasses defining the scope, urgency, and potential impact.
- Perform correlation of security incidents and events to build threat detection and prevention capabilities, baselining network traffic and host activity across the enterprise.
- Manage and document the incident throughout its cycle, including tracking and documenting incidents from initial detection through final resolution and the update the knowledge bases, preventative controls, and standards operating procedures.
- Executing incident trend analysis, reporting and assessing the impact on data and infrastructure as a result of cyber incidents as well as leading security operations, responding to feedback from internal IT departments, business and audit operational performance against the defined metrics and goals.
- Collaborate with intelligence analysts to correlate threat assessment data and recommend methods to enhance defence capabilities as well as liaising with the content Engineering Team to identify and implement automation and service improvement programs to manage security operations efficiently.
- Designing and architecting robust security infrastructure that integrates endpoint firewalls, CASB, and mail filtering solutions seamlessly across the organization's network.
- Creating advanced and granular security policies for endpoint firewalls, CASB, and mail filtering systems, customizing rules to protect against evolving threats and compliance requirements.
- Employing advanced monitoring tools and techniques to analyse traffic, logs, and events generated by endpoint firewalls, CASB, and mail filtering systems, conducting sophisticated analysis for threat detection.
- Leading incident response efforts related to these security platforms, conducting in-depth forensic analysis, understanding attack vectors, and formulating strategies to prevent future occurrences.
- Ensuring seamless integration and compatibility between endpoint firewalls, CASB, and mail filtering solutions within the broader security ecosystem, including SIEM and other security tools.
- Ensuring configurations, policies, and activities across these platforms align with industry standards, regulatory compliance (such as GDPR, HIPAA), and organizational security requirements.