Minimum 4+ years of experience in designing, implementing, and maintaining enterprise cybersecurity solutions to protect applications, networks, cloud infrastructure, and organizational data.
Expertise in Network Security, Endpoint Security, Identity & Access Management (IAM), Vulnerability Assessment, Penetration Testing, and Security Operations (SOC).
Experience with security tools and platforms such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, Carbon Black, Tenable, Nessus, Qualys, Rapid7, or Palo Alto.
Experience implementing and managing firewalls, IDS/IPS, VPNs, Web Application Firewalls (WAF), Email Security, Data Loss Prevention (DLP), and Zero Trust Security architectures.
Understanding of cloud security across AWS, Azure, or GCP, including IAM, encryption, key management, cloud security posture management, and cloud compliance best practices.
Knowledge of security frameworks and compliance standards including NIST, ISO 27001, CIS Controls, PCI-DSS, SOC 2, HIPAA, GDPR, and OWASP Top 10.
Experience securing web applications, APIs, databases, containers, Kubernetes, Docker, CI/CD pipelines, and DevSecOps environments.
Understanding of authentication, authorization, Multi-Factor Authentication (MFA), Single Sign-On (SSO), Privileged Access Management (PAM), PKI, SSL/TLS, and encryption technologies.
Experience with scripting or automation using Python, PowerShell, Bash, or PowerShell to automate security monitoring, incident response, and operational tasks.
Experience using Git, GitHub, Azure DevOps, Jenkins, and integrating security scanning tools into CI/CD pipelines while collaborating in Agile/Scrum environments