Lead Technical Engineer
Role details
Job location
Tech stack
Job description
We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills, to act as Lead Technical Engineer to lead high and low level design work for Security Operations Centre solutions delivered to customers. This is a mid level role and the individual will be expected to lead technology designs utilising small teams.
- Leading the design of a range of security and security related solutions across High level designs, Low level design and Deployment Level Designs, including specification of interfaces between solution components.
- Support the design and configuration of a range of security tools, such as: Splunk and Sentinel SIEM, Nessus Vulnerability management, Microsoft XDR and other as appropriate
- Specify infrastructure requirements (RAM, Disk, CPU, Network bandwidth) for security tools.
- Support the creation and establishment of both cloud hosting and containers, and OnPrem hosted VM's and containers, apply security controls and compliance frameworks.
- Support the design and configuration of network security devices, network routers and switches, establishment of VLANs, DNS and identity management capability
- Support deployment of security tools to both cloud hosting and containers, and OnPrem hosted VM's and containers
- Develop test procedures to test solutions meet functional and non-functional requirements
- Support creation and maintenance of requirements and user stories and ensuring that all user stories and requirements are tracked and traceable to solution components.
- Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
- Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
- The role is a cyber technical specialist with knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures.
- Develop test procedures to test solutions meet functional and non-functional requirements
- Generalist Technical SME to support deployment and configuration of various tools including Jira and Cribl
Requirements
Do you have experience in WAN?, * Knowledge and experience of design, build, deployment and operation of SOC technology including at least two of SIEM, SOAR, EDR, Vulnerability Management, Threat Intelligence, to identify signs of an intrusion.
- Experience deploying and configuring applications in a performant manner on cloud and / or OnPrem to support high data ingest rates.
- Proven delivery and experience leading conducting onboarding activities onto a SIEM
- Knowledge of OnPrem architectures & design including:
- Security controls and detection tools.
- Networking and Secure network architectures
o Understanding of OSI and TCP/IP models. o IP addressing, subnetting, and routing protocols. o Knowledge of LAN/WAN configurations and network security (ACLs, VLANs).
- Compute Services
- Storage Services
- Understanding of security best practices (least privilege, encryption).
- Understanding how to design scalable and resilient architectures.
- OS installation and administration (Windows and Linux).
- Cybersecurity Fundamentals
- Understanding of common threats (malware, phishing, DDoS) and mitigation techniques.
- Proficiency in risk assessment and vulnerability management.
- Security Systems Administration
- Experience managing endpoint security solutions (antivirus, EDR tools).
- Proficiency in user access control (Active Directory, LDAP).
- Ability to configure and maintain secure system policies (hardening servers).
- Other
- Understanding of typical Security Operations Organisation Structures, Policy and Processes.
- Good knowledge and experience of common Enterprise ICT services.
- Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.