- Company Name
- APN Consulting Inc.
- Job Title
- Security Sr. Engineer
- Job Description
-
**Job Title:** Security Sr. Engineer
**Role Summary:**
Senior security engineer responsible for safeguarding confidentiality, integrity, and availability of customer data. Leads design, implementation, operation, and monitoring of enterprise security technologies, conducts vulnerability and risk assessments, and supports incident response and security governance.
**Expectations:**
- Deliver high‑quality security solutions under tight deadlines.
- Communicate security posture and project status to senior management.
- Collaborate with cross‑functional teams on DevSecOps, patch management, and threat intelligence.
- Maintain up‑to‑date security standards, policies, and procedures.
**Key Responsibilities:**
- Operate and administer WAFs, ADCs, vulnerability scanners, web content filters, IPS/IDS, and SIEM platforms.
- Implement and manage social media security processes.
- Oversee patch management lifecycle and reporting.
- Conduct cyber threat intelligence analysis and incident monitoring/response.
- Prepare security briefings, reports, and documentation for leadership.
- Develop and enforce security standards, policies, and procedures.
- Perform system security, vulnerability analyses, and risk assessments.
- Design, deploy, and maintain security infrastructure: reverse/forward proxies, DLP, password managers, PKI, and certificate services.
- Harden Windows desktops/servers and manage Active Directory, AD‑DS, and Azure IaaS environments.
- Administer routing, VPN, DMZ, DNS, wireless security, and RADIUS solutions.
- Apply application security practices (SDL, threat modeling, fuzzing, mitigation of XSS, CSRF, SQL injection, etc.).
- Implement enterprise hardening (Pass‑the‑Hash, LAPS, Tier‑0 protection).
- Manage PKI lifecycle, Microsoft Certificate Services, and commercial CAs.
- Deploy and operate Sonatype Nexus‑IQ/NXRM, Nexus Firewall, and provide software supply‑chain security recommendations.
- Integrate security into CI/CD pipelines; work with VCS, build tools (Jenkins), package managers, artifact repositories, configuration management (Puppet, Chef, XL Deploy), and container platforms (Docker, Kubernetes, OpenShift).
**Required Skills:**
- Strong knowledge of security technologies: WAF, IPS/IDS, SIEM, DLP, proxies, PKI, certificate management.
- Windows (8.1/10) and Server (2012+) hardening; Active Directory and Azure IaaS administration.
- Networking: routing, VPN/IPSec, DNS, firewalls, wireless (802.11, RADIUS).
- Application security: SDL, OWASP Top 10, threat modeling, fuzzing, malware analysis.
- Enterprise hardening techniques (Pass‑the‑Hash, LAPS, Tier‑0 protection).
- Cryptography and PKI implementation; experience with Microsoft Certificate Services and commercial CAs.
- Sonatype Nexus (IQ, NXRM, Firewall) deployment and software supply‑chain security.
- CI/CD tooling: Git/SVN, Jenkins, Maven/Gradle/NuGet/NPM, Puppet/Chef/XL Deploy, Docker/Kubernetes/OpenShift.
- Excellent analytical, written, and verbal communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional security certifications preferred: CISSP, CISM, CEH, OSCP, or equivalent.
- Relevant vendor certifications (e.g., Microsoft Certified: Security, Azure Security Engineer Associate; Cisco CCNP Security; Certified Kubernetes Security Specialist) are a plus.