DevOps Engineer
Cyber Security Engineer
Limassol
Apply on the employer's siteRole description
Location:
Limassol, Cyprus (hybrid, occasional travel to Malta)
Department:
Information Technology
Reports To:
Head of IT Platforms & Security
Type:
Full-time
Role Summary
This is a hands-on Security Engineer role responsible for the day-to-day technical security of Sigma Group’s Microsoft 365 environment, Cloudflare edge security, firewalls, networks, monitoring, and incident response.
The role is approximately 70% technical security engineering (configuration, hardening, detection, vulnerability management, incident response, testing) and 30% governance (policies, risk management, audits, awareness).
You will work closely with IT Operations and DevOps in a fast-moving, multi-site environment, ensuring security controls are implemented, monitored, and continuously improved.
Our Environment
You should be comfortable working with:
- Microsoft 365 / Entra ID:
Defender for Office 365, Defender for Endpoint, Intune, Purview DLP, Conditional Access, PIM - Cloudflare:
Zero Trust, Access, WARP, Gateway, Tunnels, WAF, DNS, DDoS and bot protection - Networking:
Cisco Meraki and Ubiquiti firewalls, VLANs, VPNs, wireless security - Linux servers:
Ubuntu/Debian environments, security baselines, logs and access controls - Monitoring & SIEM:
ManageEngine Log360, Site24x7, log aggregation, alerting and investigation - Endpoints & SaaS:
Windows/macOS fleet, BYOD, NAS and third-party SaaS platforms
Key Responsibilities
Microsoft 365, Identity & Endpoint Security
- Own and continuously improve Microsoft 365 security posture and Secure Score.
- Configure and maintain Defender for Office 365 protections, including anti-phishing, anti-spam, Safe Links, Safe Attachments and email authentication controls (SPF, DKIM, DMARC).
- Manage Conditional Access, MFA, privileged access controls and identity security policies.
- Implement and maintain Purview DLP across Microsoft 365 services.
- Manage Defender for Endpoint and Intune security policies across Windows, macOS and mobile devices.
- Review risky applications, OAuth permissions, guest access and privileged accounts.
Cloudflare & Edge Security
- Administer Cloudflare security controls including WAF, custom rules, rate limiting, bot management, DDoS protection and SSL/TLS.
- Maintain Zero Trust access policies, Gateway filtering and secure tunnels.
- Investigate WAF alerts and security events, balancing protection with business requirements.
- Maintain DNS security and prevent misconfigurations.
Network & Infrastructure Security
- Configure and review firewall rules, segmentation, IDS/IPS and VPN access.
- Perform regular security reviews and remove unnecessary exposure.
- Secure office and event networks, wireless access and remote connections.
- Review cloud security configurations including IAM, security groups, logging and encryption.
Server & Workload Security
- Define and review Linux security baselines together with DevOps.
- Review server configurations, access controls, logging and patch status.
- Support vulnerability remediation and ensure security controls are properly implemented.
- Review web-facing and containerised workloads, including TLS, secrets management and least-privilege access.
Vulnerability Management & Testing
- Run vulnerability scans across servers, endpoints, networks and cloud services.
- Prioritise findings based on risk and business impact, track remediation and validate fixes.
- Perform targeted security testing using tools such as Nmap, Burp Suite, Metasploit and OWASP methodologies.
- Coordinate external penetration testing and remediation activities.
Monitoring & Incident Response
- Manage and improve Log360 SIEM coverage, including onboarding log sources and tuning alerts.
- Use Site24x7 and Log360 to monitor security events and investigate anomalies.
- Act as a first responder for security incidents: detection, investigation, containment and recovery.
- Perform log analysis, preserve evidence and conduct post-incident reviews.
- Translate threat intelligence into practical security improvements.
Governance, Risk & Compliance
- Maintain security policies and ensure they reflect real system configurations.
- Support risk assessments, security audits and GDPR-related requirements.
- Maintain alignment with ISO 27001, NIST CSF and CIS Controls.
- Support security awareness training and phishing simulations.
- Review security requirements for new SaaS vendors and integrations.
Reporting & Improvement
- Prepare monthly security posture reports covering incidents, vulnerabilities, compliance and risks.
- Maintain a security roadmap with priorities and expected risk reduction.
- Communicate security risks and recommendations clearly to management.
Required Skills & Experience
- 3–5+ years of experience in cybersecurity, security engineering or security-focused infrastructure roles.
- Hands-on experience securing Microsoft 365 environments.
- Practical experience with Cloudflare or similar Zero Trust/edge security platforms.
- Strong firewall and network security knowledge (Meraki, Ubiquiti, Fortinet, pfSense or similar).
- Working knowledge of Linux security, configuration and troubleshooting.
- Experience with SIEM platforms and security alert investigation.
- Experience with vulnerability scanning and remediation processes.
- Understanding of ISO 27001, NIST CSF and CIS Controls.
- Ability to communicate technical risks clearly to non-technical stakeholders.
- Strong written and spoken English.
Preferred Skills
- Scripting and automation skills (PowerShell, Microsoft Graph, Python, Bash).
- AWS/Azure security experience.
- Penetration testing or red-team exposure.
- OWASP Top 10 knowledge.
- Container and CI/CD security understanding.
- Experience securing distributed, multi-office environments.
- Experience in regulated industries such as iGaming, fintech or events.
Certifications (Preferred)
- CompTIA Security+ / CySA+
- Microsoft SC-200 or SC-300
- ISO 27001 Lead Implementer / Auditor
- OSCP, CEH, CISSP or CISM
First 90 Days
During the first three months, you will be expected to:
- Review Microsoft 365 security posture and deliver a hardening plan.
- Audit Cloudflare configuration and DNS security.
- Complete firewall and network security reviews.
- Establish a Linux security baseline with DevOps.
- Improve Log360 coverage and alert quality.
- Deliver the first vulnerability assessment cycle with tracked remediation.
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.