Enterprise Security Engineer
Job Overview
The Enterprise Security Engineer is responsible for implementing, maintaining, and optimizing the organization’s security infrastructure with a focus on Data Loss Prevention (DLP), cloud security, endpoint protection, and Identity and Access Management (IAM). This role requires expertise in Netskope, Crowdstrike, and EntraID Governance solutions to ensure comprehensive protection of enterprise data and systems.
Key Responsibilities
Data Loss Prevention (DLP)
- Design, implement, and maintain enterprise DLP solutions to protect sensitive data across all environments (on-premises, cloud, and hybrid)
- Develop and enforce DLP policies based on regulatory requirements and business needs
- Monitor and respond to DLP incidents and data exfiltration attempts
- Perform regular audits of DLP configurations and effectiveness
- Create and maintain documentation for DLP policies, procedures, and incidents
Netskope Administration
- Deploy and manage Netskope cloud security platform across the enterprise
- Configure and tune Netskope policies for CASB, SWG, and ZTNA capabilities
- Monitor cloud application usage and enforce security policies
- Generate and analyze Netskope reports to identify security gaps and recommend improvements
- Stay current with Netskope features and implement new capabilities as appropriate
Crowdstrike Management
- Deploy, configure, and maintain Crowdstrike Falcon platform for endpoint protection
- Monitor endpoint security events and respond to incidents
- Tune Crowdstrike policies to balance security requirements with operational needs
- Manage Crowdstrike updates and ensure optimal configuration
- Analyze Crowdstrike telemetry data to identify potential security threats
EntraID Governance for IAM
- Implement and manage Microsoft EntraID (formerly Azure AD) Governance for IAM
- Design and enforce role-based access control policies
- Conduct regular access reviews and certification processes
- Implement Privileged Identity Management (PIM) and Just-In-Time access
- Automate identity lifecycle management processes
- Create and maintain IAM documentation and procedures
General Security Responsibilities
- Participate in security incident response activities
- Contribute to the development of security policies and standards
- Provide technical guidance to IT teams on security best practices
- Stay current with emerging security threats and mitigation strategies
- Collaborate with compliance teams to ensure security controls meet regulatory requirements
- Conduct periodic security assessments and remediate identified vulnerabilities
Required Qualifications
Technical Skills
- Minimum 5 years of experience in IT security with at least 3 years specializing in enterprise security technologies
- Proven experience implementing and managing DLP solutions
- Hands-on experience with Netskope cloud security platform
- Demonstrated expertise with Crowdstrike Falcon endpoint protection
- Experience with Microsoft EntraID (Azure AD) and IAM governance solutions
- Strong understanding of cloud security principles and best practices
- Experience with security monitoring, incident response, and threat hunting
- Knowledge of secure network architectures and protocols
Certifications
- One or more of the following certifications will be added advantage
- Certified Cloud Security Professional (CCSP)
- Certified Security, Compliance, and Identity Fundamentals
- Crowdstrike Certified Falcon Administrator
- Netskope Certified Cloud Security Administrator
Education
- Bachelor’s degree in Computer Science, Information Security, or related field
- Advanced degree or additional certifications preferred
Preferred Qualifications
- Experience with SIEM solutions (SISA)
- Knowledge of scripting and automation (PowerShell, Python)
- Experience with DevSecOps practices and tools
- Familiarity with compliance frameworks (ISO 27001, NIST etc.)
- Experience with cloud platforms (AWS, Azure)
Personal Attributes
- Strong analytical and problem-solving skills
- Excellent written and verbal communication abilities
- Ability to translate complex technical concepts to non-technical stakeholders
- Detail-oriented with strong documentation skills
- Self-motivated and proactive approach to security challenges
- Team player with ability to collaborate across departments
Working Conditions
- May require occasional after-hours work for incident response or planned changes
- May require on-call rotation for security incident response
- Primarily office-based with potential for hybrid work arrangements