AVP/VP - Network Security Assurance & Threat Detection

  • Sector: LMA Asia Technology
  • Contact: Andrew Arbatov
  • Location: Singapore
  • Salary: S$160000 - S$200000 per annum
  • Expiry Date: 02 January 2022
  • Job Ref: BBBH186997_1638523569
  • Contact Email: winnie.tan@lmarecruitment.asia


AVP / VP, Network Security Assurance & Threat Detection

This role reports into a global manager (SVP) based in US. He leads a function called network boundary protection which basically looks at all the different layers of the network which needs to be secure and protected. Currently, the team operates out of USA. This means that if there are incidents in the middle of the night, we need to wake people.
This is the reason why we are expanding to APAC to transit to a follow-the-sun model.
The specific skills we are seeking are network engineering experience and advance Splunk knowledge. Splunk is a tool used within the team and we seek and expert in Splunk.
This team is a team that focus on engineering.

Your background

Required Skills:

  • 7 to 10 years of experience in Network / Firewall Engineering
  • Advanced knowledge and ability in Splunk Search App Query development, Dashboard creation and Alert generation
  • Experience in Network (Router & Switch) Engineering
  • Working knowledge of Enterprise-grade Firewall Architecture and Engineering best practices



Desired Skills:

  • UNIX Management (i.e. Red Hat, CentOS) Experience (a strong plus)
  • Skybox Management & Compliance Check creation and maintenance (a strong plus)
  • Experience developing Regular Expressions
  • Network Web and App Proxy (i.e. BlueCoat, Palo Alto) Management experience
  • Conceptual understanding of the MITRE ATT&CK Framework
  • Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON
  • Strong scripting skills (e.g. Python, Perl, Shell script, JavaScript)
  • Knowledge of a Structured Query Language



Competencies:

  • Ability and willingness to respond to off-hour engagements
  • Exemplary communication (written & verbal) skills to interact with Senior Leaders and non-technical stakeholders
  • Ability to perceive configuration flaws from a threat actor's point of view
  • Ability to work both independently, and as part of a team, in a very large scale, on an enterprise setting
  • Intellectually curious
  • Ability to learn and apply critical thinking to a variety of situations



Qualifications:

  • BS/MS in Computer Science (or 7 to 10 years relevant work experience)
  • The Following Network Security Qualifications are preferable and a Plus:*Cisco Network Certifications (CCNA R&S, CCNA Security, CCNP)
  • CheckPoint Certfications (CCSA, CCSE)
  • Fortinet Certifications (NSE)
  • Offensive Security Certifications (OSCP, OSCE, OSWE)
  • SANS GIAC Certifications (GPEN, GWAPT)
  • Certified Ethical Hacker (CEH)



What you can expect
The Cyber Security Assurance (CSA) Organization is responsible for providing an uncompromised technology and application environment for employees, customers, clients, and shareholders through continuous and comprehensive cyber security testing. CSA consists of multiple broader teams which focus on various technologies, platforms, and stakeholders.

As a Network Security Assurance and Threat Detection SME, you will join a dynamic team of experienced security professionals whom build and manage controls for automated engineering assessments as well as dynamic traffic anomaly detection.

The right candidate will be knowledgeable with network based controls' (e.g. firewalls, routers) architecture and engineering as well as have working knowledge of vulnerabilities and threat-actor's tactics, techniques and procedures. The right candidate will be able to effectively communicate to senior leaders and non-technical stakeholders.

What you will do

  • Build traffic-based controls via the Splunk Search App
  • Build and maintain Engineering Compliance checks with the Skybox Security Suite
  • Review and decision (Approve/Deny) Firewall/Router engineering requests
  • Review of engineering implementations for Golden Configuration drift and/or Information Security Policy violations
  • Respond to and Investigate Security events and incidents via Network Security / Management tools and other Systems of Record
  • Respond to and Investigate automated Alerts and drive towards issue closure
  • Partner with DevSecOps team to automate manual processes and strive towards Continuous Improvement

EA Reg no: R1440978

Company Reg No.: 201131609D

Licence No.: 11C4684