Senior SecOps Engineer Offline
Description:
Our client is a global leader in rail signalling, train control systems, telecommunications, supervision, and fare collection technologies. It operates across 42 countries with approximately 9,000 employees, delivering advanced digital signalling and integrated communication solutions for mainline and urban railways. The company specializes in creating scalable, secure, and efficient railway infrastructure, supporting over 26,000 km of mainline railways and 4,600 km of metro systems globally.
Requirements:
We expecting Senior Security Engineer will take a leadership role in designing, implementing, and managing project’s security framework to ensure the integrity, confidentiality, and availability of application, infrastructure and information assets. This role requires advanced technical expertise and strategic oversight to handle complex security challenges.
Responsibilities:
- Design and implement advanced security solutions across all aspects of the projects’s infrastructure, including networks, applications, and endpoints.
- Lead security risk assessments, vulnerability management, and penetration testing initiatives.
- Architect, implement, and manage identity and access management (IAM) solutions.
- Develop and enforce existing security policies up to standards, and best practices in compliance with regulatory frameworks (ISO 27001, GDPR, NIST, etc.).
- Investigate security incidents, conduct RCA, and lead the development of incident response plans.
- Collaborate with DevOps and development teams to integrate security into CI/CD pipelines and software development processes.
- Deploy and manage advanced security tools such as SIEMs, firewalls, IDS/IPS, endpoint detection and response (EDR), and data loss prevention (DLP) solutions.
- Monitor and analyze security threats, vulnerabilities, and trends to proactively defend against potential attacks.
- Oversee encryption, PKI, and secure key management solutions to safeguard sensitive data.
- Provide mentorship and technical guidance to junior security engineers and dev team.