Job Summary
Position Summary
We are seeking a Security Operations Engineer with 5+ years of experience supporting enterprise security technologies. This role will be responsible for day-to-day operational support, incident management, troubleshooting, vulnerability remediation, and administration of security platforms. The primary objective of this role is to help manage daily operational activities and provide Tier 2/Tier 3 support for security services while ensuring high availability, compliance, and operational excellence.
Key Responsibilities
- Manage day-to-day security operations through Incident, Request (RITM), Change, and Problem Management processes using ServiceNow.
- Investigate and resolve operational issues related to VPN connectivity, email delivery, certificate services, web application security, endpoint security, and network segmentation technologies.
- Support enterprise security platforms including:
- Secure Remote Access / Zero Trust Network Access (e.g., Zscaler ZIA, ZPA, ZDX)
- Email Security (e.g., Mimecast, Varonis Email Security)
- Public Key Infrastructure (PKI) and Certificate Management (e.g., DigiCert, CyberArk PKI)
- Web Application Firewall (e.g., F5 WAF)
- Microsegmentation (e.g., Illumio)
- Endpoint Privilege Management and Application Control (e.g., CyberArk EPM)
- Perform troubleshooting and root cause analysis for user-impacting issues and service disruptions.
- Support certificate lifecycle management activities including certificate issuance, renewal, replacement, revocation, inventory management, and expiration tracking.
- Assist with endpoint application allow/block requests, policy administration, and exception management.
- Monitor platform health, endpoint coverage, policy compliance, and operational effectiveness across supported security tools.
- Partner with infrastructure, network, endpoint, and application teams to resolve cross-functional issues.
- Coordinate with vendors for escalations, troubleshooting, and issue resolution.
- Develop and maintain operational documentation, runbooks, and knowledge articles.
- Identify opportunities for process improvements and operational efficiencies.
Key Responsibilities
Vulnerability Management Responsibilities
- Own vulnerability management activities for all supported security platforms.
- Review vulnerability scan results, vendor advisories, and security bulletins affecting security technologies.
- Assess risk, coordinate remediation activities, and track vulnerabilities through closure.
- Partner with platform owners, infrastructure teams, and vendors to validate fixes and remediation plans.
- Ensure supported security tools remain compliant with internal security standards and patch management requirements.
- Provide reporting and metrics on vulnerability remediation status and risk reduction efforts.
Skill Requirements
Required Qualifications
- 5+ years of experience in Security Operations, Security Engineering, or Information Security.
- Experience supporting one or more of the following security domains:
- Zero Trust Network Access (ZTNA), VPN, or Secure Remote Access
- Email Security
- PKI and Certificate Management
- Web Application Security
- Microsegmentation
- Endpoint Security and Privileged Access Management
- Hands-on experience with security technologies such as Zscaler (ZIA, ZPA, ZDX), Mimecast, Illumio, F5 WAF, DigiCert, CyberArk PKI, CyberArk EPM, or similar enterprise security platforms.
- Strong troubleshooting and problem-solving skills with the ability to perform root cause analysis.
- Strong understanding of networking concepts including TCP/IP, DNS, HTTP/HTTPS, SMTP, SSL/TLS, VPN technologies, authentication protocols, GRE, and IPSec.
- Experience using troubleshooting tools such as Wireshark, packet captures, and log analysis tools.
- Experience managing vulnerability remediation activities for enterprise security technologies.
- Experience working within ServiceNow or similar ITSM platforms.
- Experience supporting Incident, Request (RITM), Change, and Problem Management processes.
- Strong communication and stakeholder management skills.
Other Requirements
Preferred Qualifications
- Experience supporting large-scale enterprise security environments.
- Experience with certificate lifecycle automation and security tool integrations.
- Experience with PowerShell, Python, APIs, or operational automation.
- Industry certifications such as Security+, CISSP, GSEC, Network+, or equivalent.