Responsibilities
- Implement and oversee data loss prevention policies across endpoints, cloud platforms, and network layers to block unauthorized data transfers.
- Refine data loss prevention rules regularly to minimize false alerts and improve detection accuracy.
- Deploy and maintain endpoint protection agents across servers, virtual machines, and containerized environments at scale.
- Run host-level intrusion detection systems and ensure comprehensive log collection with optimized alerting mechanisms.
- Set up and manage antivirus and antimalware scanning schedules and define appropriate exclusions.
- Develop automated incident response procedures for rapid threat mitigation.
- Optimize intrusion detection, intrusion prevention, web application firewall, and rate-limiting configurations.
- Perform regular firewall rule reviews to remove excessive permissions and apply least privilege principles.
- Automate the entire lifecycle of digital certificates, including issuance, deployment, rotation, and revocation.
- Enforce encryption for data in transit and at rest using both cloud-provided and external key management services.
- Operate secrets management platforms with strict access controls, rotation policies, and integration into development pipelines.
- Develop pre-secured infrastructure templates using Infrastructure as Code to ensure new deployments meet baseline security standards.
- Operationalize native cloud security tools including threat detection, secure zones, vulnerability assessment, bastion hosts, web application firewalls, and identity domains.
- Strengthen cloud workloads such as compute instances, storage buckets, and databases while enforcing consistent tagging policies.
- Correct security misconfigurations using automated code fixes rather than manual interventions.
- Use GitHub as the central, version-controlled repository for all security and infrastructure configuration changes.
- Develop and maintain Terraform modules using the Oracle Cloud Infrastructure provider to provision security resources.
- Enforce governance policies for GitHub repositories, including branch protection, code ownership, and merge requirements.
- Build continuous integration and continuous delivery pipelines using GitHub Actions to support code validation, policy checks, and automated security testing.
- Securely manage Terraform state files using remote storage, locking, encryption, and role-based access controls.
- Write automation scripts in Python or Bash for log analysis, bulk configuration updates, compliance reporting, and enhancing security alerts