Cybersecurity Platform Engineer
Summary
Operate and maintain cybersecurity platforms including Palo Alto NGFW, Carbon Black EDR, Cloudflare DDoS/WAF, and CyberArk PAM, handling firewall rules, patching, log reviews, incident support and compliance with CSA Cybersecurity Act requirements.
Key Responsibilities
- Operate and maintain Palo Alto firewalls, including firewall rules/policies, patching, firmware upgrades, health checks, log reviews, configuration changes and troubleshooting.
- Maintain Carbon Black EDR, including RHEL-hosted servers, endpoint sensors, application services, logs, patching, endpoint onboarding and troubleshooting.
- Administer Cloudflare DDoS/WAF, including website onboarding/offboarding, WAF/security rules, IP whitelist/blacklist changes, SSL certificates, access/log reviews and vendor coordination.
- Administer CyberArk PAM, including privileged account onboarding/offboarding, access reviews, password management, service/change requests and audit logs.
- Perform vulnerability remediation, patch management, security reviews and preventive maintenance.
- Support cybersecurity incidents, investigations, assessments and audits.
- Maintain and test platform backup and restoration processes.
- Raise and manage change requests for system/configuration changes.
- Maintain SOPs, asset inventories, configuration records, security trackers and maintenance reports.
- Ensure compliance with organisational cybersecurity policies, CSA Cybersecurity Act requirements and CCoP.
Mandatory Technical Skills
- Strong enterprise networking fundamentals: TCP/IP, VLAN, routing, NAT, DNS, network segmentation and troubleshooting.
- Hands-on experience with: Palo Alto NGFW or equivalent Carbon Black EDR or equivalent Cloudflare DDoS/WAF or equivalent CyberArk PAM or equivalent
- Experience with firewall policies, patching, log analysis, endpoint/security platform administration and troubleshooting.
- Understanding of secure/segregated or air-gapped environments, including controlled offline patch/file transfers.
Good to Have
- Vulnerability management, security hardening, incident response and change management experience.
- PKI / TLS / SSL certificate management.
- Experience supporting highly secured or CII environments.
- Certifications such as CCNA, Palo Alto, CyberArk Defender/Sentry or Cloudflare-related certification.