6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores
Strong understanding of identity and access management and data access governance principles
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders
Excellent written and verbal communication skills in English
Proactive, detail-oriented, and ownership-driven
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management)
Experience building or scaling a security program from the ground up in a growing organization
Experience with cloud-native security services (AWS, Azure, Google)
Knowledge of privacy and regulatory frameworks (GDPR, ISO 27001, SOC 2)
Scripting or automation skills (Python, PowerShell)
Relevant certifications such as CISSP, CISM
BSc in Computer Science, Information Security, or a related field
Project & people management experience