We are seeking a skilled and proactive Cybersecurity Engineer to join our team and safeguard our systems, networks, and data from cyber threats. In this role, you will be responsible for designing and implementing secure network solutions, monitoring for security breaches, conducting vulnerability assessments, and responding to incidents with a calm, analytical mindset. You’ll make recommendations for our infrastructure, tooling, and security practices, and ensure that emerging threats are swiftly addressed. The ideal candidate has hands-on experience with firewalls, SIEMs, intrusion detection/prevention systems, and a solid understanding of security protocols and regulatory frameworks.
Key Responsibilities:
- Conduct comprehensive security assessments and audits across Quartermaster's technology stack, including web platforms, mobile applications, network infrastructure, and remote sensor systems deployed in maritime environments.
- Design and implement security architecture improvements across backend services, databases, and frontend interfaces to protect against common web vulnerabilities (e.g., OWASP Top 10).
- Evaluate and enhance authentication and authorization mechanisms, including session management, role-based access control, and API-level protections.
- Develop and maintain security protocols for remote systems communicating over satellite or other long-range networks, ensuring data is securely transmitted from the field to cloud infrastructure.
- Implement and manage secure communication solutions for encrypted connectivity between remote systems and centralized infrastructure.
- Perform regular security testing, including penetration tests, vulnerability scans, and code reviews across all system layers.
- Monitor system logs and deploy threat detection measures to identify and respond to potential security incidents.
- Develop and maintain incident response procedures tailored to web, mobile, and IoT/sensor systems.
- Ensure compliance with applicable maritime and data protection regulations, including data encryption at rest and in transit.
- Collaborate with engineering teams to integrate security best practices throughout the development lifecycle.
- Create and maintain documentation including security architecture diagrams, risk assessments, and internal security policies.
- Train internal staff on security awareness and secure development and operational practices.
Qualifications (Preferred):
- Bachelor's or Master’s degree in Cybersecurity, Computer Science, or a related field.
- Industry-recognized security certifications (e.g., CISSP, CEH, OSCP, or equivalent).
- 7+ years of experience in cybersecurity, with emphasis on securing web applications, mobile platforms, and embedded/IoT systems.
- Deep understanding of secure coding practices and architecture design for modern backend and frontend frameworks.
- Experience implementing authentication and authorization systems, secure API design, and database security hardening.
- Familiarity with best practices in securing cloud infrastructure and distributed systems.
- Practical experience deploying and securing encrypted communication channels between remote and centralized systems.
- Strong grasp of the unique security challenges associated with IoT, sensor networks, and remote deployments.
- Proficiency in security monitoring, threat detection, and incident response planning.
- Working knowledge of compliance and regulatory requirements relevant to data protection and operational security in regulated environments.
- Analytical mindset with the ability to identify and mitigate security risks across complex systems.
- Strong written and verbal communication skills, with the ability to convey technical security concepts to a variety of audiences.
Work Environment:
- This is a remote position with collaboration via online tools.
- Flexible working hours with occasional deadlines requiring high availability.
- Opportunity to work on innovative projects with a global impact.
Benefits:
- Competitive salary
- Flexible work hours and the option for remote work.
- Opportunities for professional development and continued education.