12 Sep
|
Sourcebae
|
Kurla
Job location: Kurla
What you'll own
- CyberArk (PAM) — safe/policy design, privileged account lifecycle, credential rotation monitoring, access recertification
- Zscaler (SSE) — policy tuning, app onboarding, exception handling
- Cloudflare (WAF/CDN, and Zero Trust/Access if applicable) — rule tuning, DNS, edge security posture
Key responsibilities
- Take over day-2 administration of CyberArk from the implementation partner; ensure clean runbooks/SOPs exist and are maintained
- Run privileged access onboarding/offboarding and periodic access recertification, feeding evidence to the GRC Analyst for audit cycles
- Own Zscaler and Cloudflare policy baselines; manage exceptions without degrading security posture
- Partner with engineering teams as headcount scales to keep IAM and network controls usable, not just secure
- Support technical deep-dives requested by auditors or pen testers on identity/network architecture
- Identify opportunities to automate policy-drift detection and routine PAM/SSE administration, in line with the team's AI-driven, lean operating model
- Escalate control-design questions or audit findings on these tools to the Security Lead
What we're looking for
- 6+ years in security engineering, with hands-on ownership of at least one PAM platform (CyberArk strongly preferred) in production
- Working experience with a cloud SSE/ZTNA platform (Zscaler, Cloudflare Access, or similar) and a CDN/WAF
- Comfortable being the sole owner of high-scrutiny controls in an audited setting (SOC 2, ISO 27001, or similar)
- Strong scripting/automation ability (Python, Terraform, or similar) to keep a lean team's operational load sustainable
- Clear written communication — you'll produce evidence and explanations auditors and pen testers can follow
How we'll know you're succeeding
- CyberArk, Zscaler, and Cloudflare pass audit control tests with minimal findings
- Privileged access recertification completed on schedule every cycle
- No unplanned production impact from policy changes across owned tools
- Routine administration increasingly automated rather than manual quarter over quarter
📌 Security Engineer (Kurla)
🏢 Sourcebae
📍 Kurla