- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
We are seeking a proactive Cyber Security Platform Engineer to advance the deployment of a novel security solution within the client's ecosystem. Collaboration with architects and product specialists will be essential to technically execute the product rollout, coordinate agent installations, manage firewall configurations, and implement security controls including SSO and MFA. The role demands effective stakeholder engagement to transition the product into routine operation. Prior experience with the runZero tool is preferred; candidates acquainted with similar platforms will also be considered.
Platform Engineering and Configuration
- Architect and execute the runZero platform's operational framework encompassing environment setup, access permissions, roles, boundaries, site configurations, asset organization, tagging, and naming conventions.
- Configure discovery processes spanning corporate networks, data centers, cloud infrastructure, remote connections, IoT devices, and operational technology domains.
- Design and apply active scanning, passive discovery, and integration methodologies tailored to different network segments and risk levels.
- Develop secure scanning protocols, including approval processes, maintenance windows, and exception handling for sensitive environments.
- Set up asset categorization systems to track classification, ownership, business impact, criticality, and lifecycle stages.
- Define procedures for managing transient, ephemeral, duplicated, decommissioned, and unmanaged assets.
- Create reusable configuration templates and standardized patterns for consistent deployment across sites.
- Maintain distinct environments for production configuration, testing, and experimental modifications.
Integrations and Data Management
- Integrate runZero with various enterprise systems such as CMDB, ServiceNow, Tenable, EDR, NAC, DNS/DHCP, cloud services, identity management, SIEM, SOAR, and other infrastructure tools.
- Implement secure API-based data ingestion and output mechanisms using least-privilege service identities.
- Automate asset data reconciliation, deduplication, enrichment, ownership linking, and quality control checks.
- Ensure downstream systems receive relevant, consistent data, avoiding overload from unnecessary alerts or asset noise.
- Define integration specifications including data contracts, field mappings, ownership, error management, retry logic, and support guidelines.
- Create mechanisms to detect integration failures, expired credentials, synchronization issues, and unexpected changes in data volume.
Automation and Workflow Engineering
- Automate processes such as platform onboarding, configuration validation, scan scheduling, asset tagging, report generation, and routine maintenance.
- Enable automated routing of identified vulnerabilities to appropriate security, infrastructure, network, cloud, or application teams.
- Develop event-driven workflows to address newly discovered assets, security exposures, control deficiencies, unauthorized devices, and significant changes.
- Design idempotent automations that avoid duplicate records, tickets, or configuration inconsistencies.
- Utilize APIs, webhooks, scripting, and workflow orchestration tools to minimize manual tasks and enhance responsiveness.
- Implement approval mechanisms for actions that could have major or disruptive impacts.
- Create automated procedures for handling asset lifecycle events like retirement, renaming, relocation, rebuilding, or short-term usage.
Site Reliability Engineering and Operations
- Manage runZero configurations and processes as code wherever feasible.
- Establish version control, conduct peer reviews, apply automated testing, and set release and rollback standards for platform changes.
- Define service-level objectives and indicators for discovery effectiveness, data timeliness, integration stability, scan completion rates, alert delivery, and remediation process dependability.
- Develop monitoring dashboards and alerts to identify platform issues proactively before impacting users.
- Create operational documentation for common failure scenarios such as component malfunctions, scan errors, integration faults, data integrity concerns, and access disruptions.
- Design backup, recovery, disaster recovery, and business continuity plans suited to the platform service level.
- Perform capacity planning, performance reviews, and scalability assessments as platform coverage grows across client environments.
- Securely manage credentials utilizing approved enterprise secret management tools, avoiding embedding secrets in code or configuration files.
- Implement role-based and privileged access control together with administrative segregation and auditable change logs.
- Support security and architecture reviews, privacy assessments, risk evaluations, and controls verification exercises.
- Ensure that data governance for logging, retention, residency, and third-party access complies with relevant organizational security policies and regulatory standards.
Industry
Software Development