Cyber Security Engineer
- Hiring from
- Hungary
- Work type
- Remote
- Posted
Is this job info correct?
538,309 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Role: Cybersecurity Lead Engineer
Location: Remote
Type: Permanent/ Full-Time
Job Responsibilities
Micro-Segmentation & Zero Trust Security
- Design, implement, and maintain enterprise micro-segmentation strategies across data center, virtualized, cloud, and hybrid infrastructure environments.
- Develop and enforce granular workload-level security policies based on application dependencies, communication patterns, and business requirements.
- Implement Zero Trust principles, including least-privilege access, continuous validation, and restrictive workload communication policies.
- Identify and mitigate unauthorized east-west traffic, lateral movement risks, and potential attack paths.
- Analyze application communication flows and dependencies to develop effective segmentation policies with minimal operational disruption.
- Establish policy lifecycle management processes, including discovery, design, testing, deployment, validation, and ongoing optimization.
Illumio & VMware vDefend Engineering
- Lead the deployment, configuration, administration, and optimization of Illumio micro-segmentation solutions.
- Design and implement workload segmentation policies using Illumio capabilities, including application dependency mapping, policy modeling, and enforcement.
- Implement and manage VMware vDefend security capabilities, including distributed firewalling and network micro-segmentation, where applicable.
- Integrate micro-segmentation solutions with existing network security, virtualization, cloud, and security operations platforms.
- Troubleshoot policy conflicts, connectivity issues, enforcement failures, and platform integration challenges.
- Maintain platform health, configuration standards, operational documentation, and security policy consistency.
Network & Infrastructure Security Architecture
- Design secure infrastructure architectures covering data center networks, virtualized workloads, cloud environments, and hybrid infrastructure.
- Analyze network traffic flows, application dependencies, ports, protocols, and service-to-service communication requirements.
- Collaborate with network and infrastructure teams to implement effective security controls without compromising application availability.
- Assess infrastructure security risks and recommend mitigation strategies aligned with enterprise security policies.
- Support secure architecture reviews, technical design assessments, and infrastructure modernization initiatives.
- Ensure micro-segmentation designs align with enterprise security architecture, regulatory requirements, and internal governance standards.
Security Automation & Scripting
- Develop automation scripts and tools using Python, Shell, or similar technologies to streamline security provisioning, policy deployment, validation, and reporting.
- Automate repetitive security operations, configuration management, compliance checks, and infrastructure lifecycle activities.
- Integrate security workflows with APIs, infrastructure automation tools, and enterprise operational platforms.
- Implement automated policy validation, configuration auditing, and security posture reporting.
- Support automated patching, configuration updates, and security control verification in collaboration with infrastructure operations teams.
- Establish repeatable, version-controlled, and auditable security deployment processes.
Security Monitoring, Troubleshooting & Incident Response
- Monitor micro-segmentation policy effectiveness and investigate suspicious or unauthorized workload communication.
- Troubleshoot connectivity disruptions, policy violations, enforcement issues, and application communication failures.
- Collaborate with Security Operations Center (SOC), incident response, and threat hunting teams to investigate security incidents.
- Support containment activities by implementing targeted segmentation policies to isolate compromised workloads when authorized.
- Perform root cause analysis and develop corrective actions for recurring security and infrastructure issues.
- Maintain operational runbooks, troubleshooting procedures, and incident response documentation.
Security Governance, Risk & Compliance
- Establish and maintain micro-segmentation standards, security architecture guidelines, and operational procedures.
- Participate in security risk assessments, architecture governance, and technical compliance reviews.
- Maintain evidence of security controls, policy changes, approvals, and enforcement status for audit purposes.
- Ensure security policies align with applicable regulatory requirements and organizational risk management frameworks.
- Track security posture improvements, policy coverage, exceptions, and remediation activities.
- Review and continuously improve security controls based on emerging threats, infrastructure changes, and business requirements.
Enterprise Infrastructure Lifecycle Management
- Manage security requirements throughout the infrastructure lifecycle, including onboarding, configuration, patching, upgrades, migration, and decommissioning.
- Coordinate micro-segmentation changes during application deployments, data center migrations, cloud adoption, and infrastructure transformation projects.
- Assess the security impact of infrastructure changes and ensure appropriate policy updates and validation.
- Collaborate with application owners and infrastructure teams to minimize downtime and prevent unintended service disruptions.
- Maintain accurate inventory, application dependency information, segmentation coverage, and security configuration records.
Technical Leadership & Stakeholder Management
- Provide technical leadership and mentoring to cybersecurity, infrastructure, and security engineering teams.
- Define technical standards, implementation roadmaps, and best practices for micro-segmentation and Zero Trust adoption.
- Lead technical workshops, solution design reviews, and security implementation planning.
- Coordinate with network engineering, virtualization, cloud, application, and SOC teams to resolve complex cross-functional issues.
- Communicate security risks, implementation progress, operational challenges, and remediation plans to technical and business stakeholders.
Required Skills & Qualifications
- Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related discipline, or equivalent practical experience.
- Significant hands-on experience in enterprise cybersecurity, infrastructure security, network security, or security engineering.
- Strong practical experience with Illumio micro-segmentation and/or VMware vDefend.
- Deep understanding of micro-segmentation concepts, workload isolation, application dependency mapping, and security policy enforcement.
- Strong knowledge of Zero Trust architecture, least-privilege access, defense-in-depth, and lateral movement prevention.
- Solid understanding of networking fundamentals, including TCP/IP, routing, switching, VLANs, firewalls, ports, protocols, and east-west traffic flows.
- Experience securing virtualized environments and enterprise data center infrastructure.
- Proficiency in Python, Shell scripting, or similar automation technologies.
- Experience with REST APIs, configuration automation, and security operations workflows.
- Ability to troubleshoot complex connectivity, segmentation, and infrastructure security issues.
- Understanding of security governance, change management, risk assessment, and compliance processes.
- Strong technical leadership, analytical, documentation, and stakeholder management skills.
Preferred Qualifications
- Experience deploying micro-segmentation at enterprise scale across complex application environments.
- Experience with VMware vSphere, NSX, software-defined networking, and distributed firewall technologies.
- Familiarity with cloud security controls and workload protection across AWS, Microsoft Azure, or GCP.
- Experience integrating security platforms with SIEM, SOAR, vulnerability management, or configuration management systems.
- Knowledge of Infrastructure as Code (IaC), Terraform, Ansible, and Git-based configuration management.
- Familiarity with MITRE ATT&CK, attack path analysis, and threat-informed security architecture.
- Experience supporting security audits, regulatory compliance, and enterprise risk management.
- Relevant cybersecurity, networking, virtualization, or vendor-specific certifications.