5 дней назад
Principal Cybersecurity Engineer (Windows)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Cybersecurity Engineer (Windows): Securing and hardening Syniverse’s Windows Server, endpoint, Active Directory, DLP, and DSPM environments with an accent on CIS Benchmarks, identity security, incident response, and sensitive-data protection. Focus on building Splunk detections, automating remediation with PowerShell and Python, investigating endpoint incidents, and reducing Windows attack-surface and data-exfiltration risks.
Location: Hybrid role in San Jose, Costa Rica
Company
provides connectivity and communications technology for vehicles, travelers, financial institutions, technology companies, and communications providers.
What you will do
- Own the security architecture, hardening, and risk remediation strategy for Windows Server, endpoints, Active Directory, Group Policy, DNS, and certificate services.
- Design secure CIS Benchmark baselines and drive compliance through configuration management and automation.
- Investigate Windows and endpoint security incidents, including forensic triage, containment, root-cause analysis, and remediation.
- Design and operate DLP controls and mature DSPM capabilities across endpoints, email, cloud repositories, file systems, and databases.
- Build and maintain Splunk detections, correlation searches, dashboards, alerts, and lookup-generating pipelines for Windows and identity telemetry.
- Mentor security engineers, support threat modeling and risk acceptance reviews, document technical procedures, and communicate remediation status to technical and non-technical stakeholders.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
- 8+ years of information security or systems engineering experience, including at least 5 years focused on Windows security engineering or infrastructure hardening.
- Deep expertise in Windows Server and Active Directory security, including Group Policy, Kerberos/NTLM, PKI, lateral movement, credential theft, and Kerberoasting.
- Proficiency with Entra ID, Microsoft Defender, Microsoft Purview, Azure security services, Splunk SPL, DLP solutions, DSPM practices, EDR platforms, and CIS Benchmarks.
- PowerShell scripting and automation experience plus at least one additional language, preferably Python.
- Knowledge of Zero Trust, MITRE ATT&CK, security frameworks, log aggregation, event correlation, and technical risk communication.
Nice to have
- Certifications such as GCWN, CISSP, CRTP, CRTE, CompTIA Security+, Microsoft SC-100, or SC-400.
- Experience with hybrid identity, threat modeling, coverage-matrix risk assessment, or formal security risk acceptance processes.
- Experience mentoring engineers or leading technical workstreams without formal management authority.
- Telecommunications industry experience.
Culture & Benefits
- Flexible and remote-work options within the role’s hybrid arrangement.
- Inclusive, collaborative, and transparent organizational culture.
- Competitive total compensation and support from an experienced leadership team.
- Focus on diversity, equity, and inclusion in recruitment, development, and retention.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →