KEY ROLES AND RESPONSIBILITIES
- Achieving Zamara's ambitious strategic priorities will be complex and challenging. Its continued success will be dependent on building and retaining a world-class team.
- We are seeking a Network & Security Engineer to be responsible for establishing, implementing, and continuously improving foundational security controls across Zamara's technology landscape. The role will ensure systems, applications, and infrastructure are secured by design, compliant with regulatory requirements, and aligned to industry best practices.
Key Responsibilities Include:
Security Baseline Implementation
- Define and enforce baseline security standards across infrastructure, applications, and endpoints
- Implement controls aligned to frameworks such as ISO 27001, NIST, and CIS benchmarks
- Ensure secure configurations for servers, networks, cloud environments, and end-user devices
Access Control & Identity Management
- Enforce the principle of least privilege across systems and environments
- Implement and monitor identity and access management (IAM) controls
- Strengthen authentication mechanisms (e.g., MFA, conditional access policies)
Monitoring & Threat Detection
- Implement and manage security monitoring tools (SIEM, endpoint detection, logging)
- Detect and respond to suspicious activities, unauthorized access, and anomalies
- Establish alerts and reporting for security incidents and control breaches
Data Protection & Resilience
- Implement controls to safeguard sensitive data from unauthorized access or loss
- Support backup, disaster recovery, and ransomware protection strategies
- Ensure safeguards against data corruption, deletion, or exfiltration
Vulnerability & Risk Management
- Conduct vulnerability assessments and coordinate remediation efforts
- Support penetration testing and track closure of identified gaps
- Maintain a risk register and track mitigation actions
Security Governance & Compliance
- Support DPIAs, audits, and regulatory compliance requirements
- Develop and maintain security policies, standards, and procedures
- Ensure third-party/vendor access is controlled and compliant
Security Awareness & Continuous Improvement
- Drive security awareness across IT teams and business users
- Continuously assess and improve security posture and controls
- Embed security into DevOps and system development processes
QUALIFICATION & EXPERIENCE
- Bachelor's degree in information security, Computer Science, or related field
- 5+ years of experience in cybersecurity or IT security operations
- Experience implementing security controls in enterprise environments
- Security frameworks: ISO 27001, NIST, CIS Controls
- Identity & Access Management (IAM), Active Directory, Azure AD
- Endpoint security, SIEM tools, logging and monitoring solutions
- Vulnerability management tools and penetration testing coordination
- Cloud security (Azure preferred) and network security fundamentals
- Backup, disaster recovery, and data protection technologies
- Strong analytical and risk assessment skills
- Attention to detail and proactive mindset
- Ability to balance security with business needs
- Strong stakeholder engagement and communication
- High integrity and ownership