Cybersecurity Engineer

Contractor

Job Description

Job Summary

We are seeking a hands-on Cybersecurity Engineer to design, deploy, and manage our Privileged Access Management, Data Loss Prevention, and Email Security infrastructure built on the Fortinet security suite (FortiPAM, FortiDLP, FortiMail). The successful candidate will be responsible for securing privileged credentials and sessions, preventing sensitive data exfiltration, and protecting the organization’s email ecosystem against phishing, spoofing, and business email compromise. This role requires deep technical expertise in privileged session management, data classification and policy engineering, and mail security gateway architecture, along with the ability to work cross-functionally with network, SOC, and compliance teams to continuously mature the organization’s security posture.

Key Responsibilities

FortiPAM — Privileged Access Management

▪ Deploy, configure, and administer FortiPAM for centralized management of privileged accounts, credentials, and sessions across on-premises, cloud, and hybrid environments.

▪ Onboard privileged and service accounts (Windows, Linux/Unix, network devices, databases, hypervisors) into vaulted credential stores with automated password rotation policies.

▪ Configure and manage secure remote access workflows (RDP, SSH, HTTPS, database consoles) via FortiPAM’s session broker, including session recording, live session monitoring, and just-in-time (JIT) access provisioning.

▪ Implement approval workflows, checkout/check-in policies, and dual-control access for high-risk privileged operations.

▪ Integrate FortiPAM with Active Directory/Entra ID, LDAP, RADIUS, and SAML/SSO providers for identity federation and MFA enforcement on privileged sessions.

▪ Configure granular role-based access control (RBAC) and least-privilege policies aligned with job function and risk tier.

▪ Set up session recording storage and retention policies, and integrate recorded sessions with SIEM/SOC workflows for forensic review.

▪ Conduct periodic access reviews, orphaned and stale privileged account audits, and credential rotation compliance checks.

▪ Troubleshoot connectivity, authentication, and session-broker issues between FortiPAM and target endpoints or devices.

▪ Develop and maintain break-glass / emergency access procedures for FortiPAM outages.

FortiDLP — Data Loss Prevention

▪ Design, implement, and tune FortiDLP policies to detect and prevent unauthorized transfer of sensitive data (PII, PHI, financial data, intellectual property) across endpoints, email, web, and removable media channels.

▪ Build and maintain data classification schemas and fingerprinting/pattern-matching rules (regex, exact data match, document fingerprinting, OCR-based detection for scanned or image content).

▪ Configure endpoint DLP agents for monitoring and blocking of USB, cloud upload (SaaS/CASB integration), print, clipboard, and screen-capture activities.

▪ Integrate FortiDLP with FortiMail and web/proxy gateways to enforce consistent data-protection policy across all egress channels.

▪ Analyze DLP incident alerts, tune detection thresholds to reduce false positives, and produce incident investigation reports for compliance and legal review.

▪ Collaborate with data owners and compliance teams to define sensitivity labels and policy exceptions in line with regulatory requirements, including healthcare data protection standards.

▪ Maintain audit trails and generate DLP compliance reporting for internal audits and regulatory assessments.

▪ Perform periodic policy simulation and testing (tabletop and live data-exfiltration test scenarios) to validate DLP efficacy.

FortiMail — Email Security Gateway

▪ Administer FortiMail in gateway/transparent mode across a multi-tenant Microsoft 365 and hybrid Exchange environment.

▪ Configure and maintain SPF, DKIM, and DMARC records/policies across all managed domains; monitor DMARC aggregate and forensic reports for spoofing and delivery issues.

▪ Design and tune anti-spam, anti-phishing, anti-malware, impersonation analysis, and URL/attachment sandboxing policies.

▪ Configure and manage SMTP relay validation, connection security (TLS enforcement, opportunistic vs. forced TLS), and IP reputation/greylisting policies.

▪ Manage Protected Identities / executive impersonation protection features and business email compromise (BEC) detection rules.

▪ Integrate FortiMail with Microsoft Graph API for journaling, quarantine management, and mailbox-level remediation actions.

▪ Maintain multi-tenant domain onboarding, per-tenant policy segregation, and delegated administration structures.

▪ Conduct User Acceptance Testing (UAT) for FortiMail policy changes and upgrades, including test-execution documentation and vendor coordination.

▪ Monitor mail queues and bounce/NDR patterns, and troubleshoot mail-flow issues across hybrid Exchange/M365 routing.

▪ Perform regular review of quarantine, false positive/negative tuning, and end-user release-request handling.

▪ Maintain disaster recovery and high-availability configuration for FortiMail clusters.

General Responsibilities

▪ Participate in security and network architecture design and continuous improvement initiatives.

▪ Work closely with network, infrastructure, SOC, and compliance teams.

▪ Perform advanced troubleshooting and performance optimization across network and security layers.

▪ Maintain accurate documentation, configurations, and standard operating procedures.

▪ Ensure all solutions align with organizational policies and industry best practices.

Required Skills & Qualifications

▪ Bachelor’s degree in Information Security, Information Technology, or a related field (or equivalent hands-on professional experience).

▪ Minimum 3–5 years of hands-on experience administering enterprise security infrastructure, with demonstrable experience on at least two of: FortiPAM (or equivalent PAM platforms such as CyberArk, BeyondTrust, Delinea), FortiDLP (or equivalent DLP platforms such as Forcepoint, Symantec DLP, Microsoft Purview), FortiMail (or equivalent mail security gateways such as Proofpoint, Mimecast, Microsoft Defender for Office 365).

▪ Solid working knowledge of email authentication protocols: SPF, DKIM, DMARC, and MTA-STS.

▪ Strong understanding of Active Directory, Entra ID, LDAP, RADIUS, and SAML/SSO integration.

▪ Experience with Microsoft 365 hybrid Exchange environments, including mail-flow connectors and transport rules.

▪ Familiarity with privileged session management concepts: credential vaulting, JIT access, session recording, and RBAC design.

▪ Knowledge of data classification methodologies and DLP policy engineering (regex, fingerprinting, exact data match).

▪ Practical experience with network fundamentals (TCP/IP, DNS, routing/switching basics) and firewall/security appliance administration.

▪ Ability to read and interpret logs across SIEM, mail gateway, and endpoint agent consoles for troubleshooting and incident investigation.

▪ Strong scripting/automation aptitude (PowerShell, Python, or Bash) for reporting, log parsing, or policy automation is a plus.

Preferred Qualifications

▪ Fortinet certifications: NSE 4/5/6/7, or specific FortiPAM/FortiMail specialist certifications where available.

▪ Certifications in adjacent domains: CompTIA Security+, CySA+, CISSP, CISM, or CEH.

▪ Experience working toward or maintaining compliance with ISO/IEC 27001 (Information Security Management), ISO/IEC 27701 (Privacy Information Management), or ISO 22301 (Business Continuity).

▪ Familiarity with healthcare-sector regulatory frameworks and data protection requirements (e.g., HIPAA-equivalent standards and UAE healthcare data protection regulations, including DOH/DHA compliance where applicable); prior experience securing healthcare or other regulated environments (finance, telecom) is strongly preferred.

▪ Experience with vulnerability management platforms (Qualys, Nessus) and NAC solutions (Aruba ClearPass) is a plus, given cross-team overlap with SecOps.

▪ Exposure to Microsoft Defender for Endpoint, FortiManager/FortiGate, and broader Fortinet Security Fabric integration.

▪ Prior experience in multi-tenant MSSP or shared-services security environments.

Soft Skills

▪ Strong analytical and problem-solving skills with attention to detail in policy tuning and incident triage.

▪ Excellent verbal and written communication skills, including the ability to produce clear technical documentation and vendor-facing correspondence.

▪ Ability to work collaboratively across cross-functional teams (network, SOC, compliance, application owners).

▪ Comfortable operating under audit/compliance scrutiny and communicating risk to both technical and non-technical stakeholders.

▪ Strong time-management skills to balance business-as-usual operations with project-based deployment work.

▪ A proactive, ownership-driven mindset with willingness to continuously learn evolving Fortinet feature sets and the threat landscape.

▪ Calm, methodical approach during security incidents or PAM/mail outages affecting business operations.

Job Overview

All content copyrighted Tangent International © All rights reserved. Recruitment Website Design - RecWebs