Senior Network Security Engineer

Atidiv
Posted on
Atidiv logo

Experience
6 - 9 yrs
Salary (CTC)
₹6L - ₹9L
Job Location
Pune, India
Vacancy
1
Designation
Senior Network Security Engineer
Job Type
Not specified

Job Description

Role & responsibilities

1. Data Loss Prevention (DLP)

  • Own the end-to-end DLP strategy across all channels endpoint, email, web, cloud storage, and removable media
  • Manage Sophos DLP policies in blocking mode define content rules, sensitive data patterns (PII, PCI, PHI, IP), and policy exceptions
  • Administer Google Workspace DLP rules: Gmail, Drive, Meet, and Chat detect and block exfiltration of classified data
  • Configure and maintain USB and removable media blocking policies via Sophos Endpoint Protection
  • Establish DLP incident workflows: alert triage, investigation, user notification, and management reporting
  • Tune DLP policies to minimise false positives while maintaining blocking effectiveness document tuning rationale
  • Conduct quarterly DLP policy reviews aligned with data classification updates and audit findings
  • Produce monthly DLP incident summary reports for the DPO and IT Lead

2. Firewall & Switch Security

  • Own Sophos XGS Firewall configuration lifecycle security zones, NAT rules, VPN tunnels (IPSec/SSL), HA failover, and firmware updates
  • Administer managed network switches: VLAN configuration, port security, 802.1X authentication, storm control, and spanning tree hardening
  • Implement and enforce network segmentation: DMZ, inter-VLAN routing controls, Guest VLAN isolation, and zero-trust perimeter principles
  • Manage IDS/IPS rules within Sophos NGFW — tune signatures, review alerts, and document suppression decisions
  • Conduct periodic firewall rule audits — identify stale, overly permissive, or shadow rules and produce a cleanup remediation log
  • Enforce switch port security: disable unused ports, restrict MAC address counts, and apply BPDU guard on access ports
  • Manage dual internet links (Airtel + Teleglobal) — failover logic, bandwidth policy, and traffic prioritisation
  • Evaluate and implement Network Access Control (NAC) to control which devices can join the corporate network — currently an identified gap
  • Maintain documented network topology diagrams, change logs, and baseline configuration backups for all firewall and switch devices

3. Data Security & Data Management

  • Own the information classification scheme — define and maintain data tiers (Public, Internal, Confidential, Restricted) aligned to ISO 27001
  • Ensure all data stores (Google Drive, email, AWS S3, Freshservice, endpoint local storage) are classified, labelled, and handled per policy
  • Enforce data retention and disposal policies — define retention periods per data type (PII, financial, operational) and verify secure disposal of media and devices
  • Manage encryption posture: ensure data at rest and in transit is encrypted; review Google Workspace TLS/SMIME settings, AWS S3 bucket encryption, and endpoint storage encryption
  • Govern backup security — enforce authentication, encryption, and integrity verification for all backup media (email and Drive backups currently in scope)
  • Assess and remediate data exposure risks: public-facing servers, shared drives with over-permissioned access, and API data flows
  • Maintain a data flow map documenting where PII, PCI, and PHI is collected, stored, processed, and transmitted — refresh annually and on material changes
  • Support the DPO in responding to data subject requests, breach investigations, and regulatory notifications under GDPR and CCPA

4. Data Protection & Privacy Compliance

  • Act as the technical arm of the Data Protection function — translate DPO requirements into enforceable technical controls
  • Maintain and improve compliance with GDPR, CCPA, and ISO 27001 data protection obligations — document control mappings and evidence
  • Conduct Data Protection Impact Assessments (DPIAs) for new systems, integrations, or data processing activities
  • Oversee access control hygiene: enforce least-privilege across Google Workspace, AWS IAM, and Sophos Central — conduct quarterly access reviews
  • Manage identity lifecycle for data access: provisioning, periodic recertification, and timely revocation on offboarding
  • Enforce MFA across all data-access surfaces: Google Workspace, AWS console, VPN, remote admin tools — document exceptions
  • Manage third-party data processor agreements (DPAs) from a technical controls perspective — verify vendor security posture annually
  • Support cyber insurance questionnaire submissions — provide accurate technical responses for data protection sections
  • Monitor and respond to data protection-related security alerts — coordinate with the DPO on breach determination and notification timelines

5. Security Best Practices & Standards

  • Define, document, and enforce Atidiv's security baseline standards — covering endpoints, network devices, cloud accounts, SaaS apps, and user accounts
  • Own the patch management lifecycle: define patching cadence (critical: 72 hours, high: 7 days, medium: 30 days), track SLA compliance, and report on remediation status — currently an identified gap
  • Implement CIS Benchmark hardening for endpoints (Windows/macOS), Sophos, AWS, and Google Workspace — document deviations with risk acceptance
  • Enforce password and authentication standards: minimum complexity, no shared credentials, MFA everywhere, and periodic credential rotation for privileged accounts
  • Govern software installation controls: enforce admin-only installation via Sophos and Google Workspace policies; maintain approved software list
  • Conduct quarterly internal vulnerability scans; coordinate annual VAPT with third-party vendor — scope to include firewall, endpoints, web-facing systems, and AWS workloads
  • Lead phishing simulation campaigns (GoPhish, quarterly) — design scenarios, run campaigns, analyse click rates, and drive targeted remediation training
  • Maintain the Information Security Policy suite — review annually and update following audit findings, incidents, or regulatory changes
  • Perform security risk assessments for new tools, SaaS onboarding, third-party integrations, and infrastructure changes before go-live
  • Develop and maintain the Incident Response Plan — including ransomware playbook, escalation paths, and post-incident review process

6. Centralised Asset Security Management

  • Own the security dimension of the CMDB in Freshservice — ensure all IT assets (laptops, servers, network devices, cloud instances, SaaS apps) are inventoried with ownership, classification, patch status, and security configuration state
  • Implement and manage Sophos Central as the unified security console: endpoint protection, EDR, DLP, firewall, and MDM — enforce consistent policy across all managed devices
  • Define and track security health metrics per asset: patch compliance %, EDR coverage %, DLP policy coverage, MFA adoption — produce weekly dashboard for IT Lead
  • Enforce Google MDM for all corporate mobile devices and BYOD enrolled devices — ensure remote wipe, screen lock, and compliance policies are active
  • Manage device lifecycle from a security standpoint: imaging standards, baseline configuration at provisioning, security sign-off before decommission, and secure data wipe before hardware return or disposal
  • Identify and track unmanaged or shadow IT assets — establish a rogue device detection process using Sophos network scanning and firewall DHCP logs
  • Maintain asset age and risk register — flag assets approaching end-of-support (OS, firmware) and escalate for upgrade or compensating control
  • Evaluate and pilot a centralised IAM/UEM platform to consolidate device security management, patch deployment, and identity governance — aligns to the org's Zero Trust roadmap
  • Produce quarterly asset security posture reports — coverage gaps, non-compliant devices, decommission backlog, and risk exposure summary

Preferred candidate profile

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience)
  • 7–9 years of hands-on experience in network security, information security, or a combined infrastructure + security role
  • Minimum 4 years of firewall administration experience — Sophos, Fortinet, Palo Alto, or Cisco ASA
  • Demonstrated hands-on experience with DLP tools in a production environment (Sophos, Symantec, Forcepoint, or equivalent)
  • Proven experience with data classification, data protection frameworks, and privacy compliance (GDPR / CCPA)
  • Experience managing network switches in a corporate environment — VLAN design, port security, 802.1X
  • Demonstrated experience with centralised endpoint/asset security management platforms (Sophos Central, Intune, Jamf, or equivalent)
  • Experience in audit preparation and supporting at least two compliance cycles — ISO 27001 / SOC / VAPT
  • Experience working in a managed services or multi-client IT environment is a strong plus
  • Familiarity with ITSM and CMDB platforms (Freshservice, ServiceNow, or similar) for asset and change management

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.