Position Summary
The Cybersecurity Expert is responsible for designing, implementing, security controls across enterprise network and system infrastructures. The role requires strong hands-on technical experience, deep understanding of industry security frameworks (ISO 27001, PCI DSS, SOC 2, NIST), and the ability to interface directly with customers, deliver presentations, and prepare high-quality technical proposals.
This position bridges technical excellence and client-facing capabilities, ensuring secure operations, compliance alignment, and exceptional customer experience.
Key Responsibilities
1. Network & System Security Engineering
- Deploy, configure, and maintain cybersecurity solutions across on-prem and cloud environments.
- Implement and manage network security controls including firewalls, IDS/IPS, proxies, VPN, segmentation, and zero-trust architectures.
- Maintain secure system configurations for Windows, Linux, virtualized servers, and cloud workloads.
- Conduct vulnerability assessments, patch management, and security hardening.
- Participate in security incident response, root-cause analysis, and remediation activities.
2. Security Architecture & Technical Design
- Contribute to the design of secure network and system architectures.
- Evaluate and recommend security technologies, tools, and best practices.
- Develop detailed technical designs, architecture diagrams, and solution documentation.
- Support secure integration of IAM, PAM, EDR/XDR, DLP, SIEM, and other security tools.
3. Security Compliance & Standards
- Align security practices with common standards including:
- ISO 27001:2022
- PCI DSS v4.0
- SOC 2 Trust Services Criteria
- NIST CSF / NIST 800-53 / NIST 800-171
- Support compliance readiness assessments, gap analysis, audits, and evidence preparation.
- Develop, update, and maintain security policies, procedures, standards, and guidelines.
4. Risk Management & Governance Support
- Conduct risk assessments for systems, networks, and applications.
- Identify and document threats, vulnerabilities, impacts, and recommended mitigations.
- Work with GRC teams on risk treatment plans and compliance documentation.
5. Penetration Testing & Security Validation (Optional)
- Assist with internal vulnerability testing, configuration reviews, and control effectiveness assessments.
- Validate security control gaps and provide improvement recommendations.
6. Customer Interfacing & Consulting
- Act as a technical cybersecurity advisor during customer meetings, workshops, and presentations.
- Understand customer requirements and translate them into feasible, secure technical solutions.
- Support customers during onboarding, integration, compliance assessments, and security improvements.
- Manage customer escalations with professionalism and clear communication.
- Build strong, trust-based relationships through consistent engagement and expertise.
7. Presentation & Communication Skills
- Deliver high-impact cybersecurity presentations, demos, and training sessions.
- Present architecture diagrams, solution strategies, and security posture updates to both technical and non-technical audiences.
- Prepare clear, concise, and professional security reports, technical proposals, and executive summaries.
Technical Proposal & Pre-Sales Support
- Develop technical proposals, BoQs, solution descriptions, and RFP/RFQ responses.
- Support pre-sales teams in cybersecurity solution scoping, sizing, and design.
- Participate in proof-of-concept (POC) planning and execution.
- Present solution architectures and capabilities to customers during bid evaluations.
Qualifications & Skills
Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, or similar.
Professional Experience
- 45+ years of hands-on cybersecurity experience covering both network and system security.
- Strong exposure to compliance frameworks: ISO 27001, PCI DSS, SOC 2, NIST.
- Experience designing and deploying enterprise security technologies.
Technical Skills
- Strong familiarity with firewalls, IDS/IPS, NAC, VPN, WAF, load balancers, and network monitoring tools.
- Hands-on experience with Windows and Linux security hardening.
- Knowledge of SIEM, EDR/XDR, IAM/PAM, vulnerability management, DLP, PKI.
- Understanding of cloud security best practices (AWS, Azure, GCP).
- Ability to produce professional documentation, diagrams (Visio/Lucidchart), and technical write-ups.
Soft Skills
- Excellent communication, customer-facing, and presentation abilities.
- Strong analytical and problem-solving capabilities.
- Ability to explain complex technical topics in simple business terms.
- High professionalism, teamwork, and adaptability in fast environments.
Key Deliverables
- Secure and optimized network and system security environments.
- Compliance-aligned processes and evidence for audits (ISO, PCI, SOC2, NIST).
- High-quality technical presentations and security documentation.
- Technical proposals, RFP responses, and customer solution designs.
- Customer satisfaction through clear communication and expert support.
- Technical reports, incident summaries, and architecture diagrams.