Role Summary
As the Information Security Specialist, you will work closely with the CISO and support building and managing security tools, processes, and best practices across the organization. This is a hands-on role that spans multiple areas of cybersecurity, requiring technical expertise, adaptability, and a proactive mindset. You will play a critical role in safeguarding our infrastructure, applications, and data while enabling secure innovation in a fast-paced and innovative environment
Role Responsibilities
- Manage identities, Single Sign-On (SSO), Multi-Factor Authentication (MFA), and user lifecycle in Microsoft Entra.
- Administer role governance and privileged access management.
- Configure and maintain Intune policies for device hardening, software deployment, patching, and web content filtering.
- Manage Microsoft Defender for Endpoint and Office 365 security configurations.
- Implement and maintain labeling and Data Loss Prevention (DLP) policies in Microsoft Purview.
- Manage VPN solutions and secure remote access.
- Oversee vulnerability scanning, prioritization, and remediation processes.
- Integrate scanning tools into the development lifecycle, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency checks.
- Collaborate with engineering teams to prioritize and resolve security issues.
- Implement Cloud Security Posture Management (CSPM) solutions and monitor cloud environments for security risks.
- Deploy and integrate new security tools such as Web Application Firewalls (WAF), Security Information and Event Management (SIEM), Breach and Attack Simulation (BAS), and DAST solutions.
- Develop scripts or workflows to automate security tasks and improve efficiency.
Role Requirements
- Bachelor’s degree in Business, Computer Science, or related field.
- Relevant certifications (e.g., CISSP, CEH) are a plus.
- Minimum 5 years of hands-on experience in cybersecurity roles.
- Strong experience with AWS and Microsoft Entra or Intune.
- Familiarity with Microsoft security ecosystem (Defender, Purview).
- Knowledge of cloud security practices and tools.
- Experience with scripting or workflow automation tools.
- Critical thinker with strong problem-solving abilities.
- Eager to learn and adapt to new technologies.
- Comfortable working in a fast-paced, innovative startup environment.
- Ability to manage multiple priorities and multitask effectively.