100% Remote: Senior Security Engineer
Senior Security Engineer
100% Remote
3-6+ Months
- Code42 / Mimecast Incydr (insider risk/DLP)
- Thales CCKM (multi-cloud key management)
- KnowBe4 (security awareness admin)
High-Level Scope Overview Interim administration & day to day operations for:
- Code42/Mimecast Incydr
- Thales CipherTrust Cloud Key Manager (CCKM)
- KnowBe4 Resource Requested A. Single SME (preferred if available) Commitment: ~40 hrs/week for 12 weeks Required Skills: Senior engineer/analyst with hands on expertise in Incydr, CCKM (multi cloud BYOK/HYOK), and KnowBe4 admin. B. Split Role Model (less preferred due to scheduling complexity) Incydr / Insider Risk & DLP Engineer: ~20 30 hrs/week Cloud Key Management (CCKM) Engineer: ~20 30 hrs/week KnowBe4 Admin (can be fractional or bundled): ~5 10 hrs/month High Level Activities by Solution 1) Code42/Mimecast Incydr (Insider Risk & DLP)
- Daily alert triage, case creation, investigation, and closure; stakeholder comms.
- Policy/watchlist hygiene and tuning (exfiltration vectors; thresholds; noise reduction).
- Maintain & validate data sources (endpoints, cloud storage/email, browser plug ins).
- Maintain integrations (SIEM/SOAR ticketing & response), enrichment and routing.
- Weekly metrics & trend reporting (notable events, MTTR, false positive reduction)
- Runbook/documentation updates; handoff briefings. 2) Thales CCKM (CipherTrust Cloud Key Manager)
- Key lifecycle operations; creating/importing, enabling, rotating, retiring.
- BYOK/HYOK across cloud service providers.
- Ensure connector health & policy alignment.
- Access control reviews (roles, least privilege), break glass procedures.
- Audit & evidence prep (rotation logs, access reviews, change records).
- Automation hygiene (scripts/Terraform where applicable) for repeatable key ops. 3) KnowBe4 (Security Awareness & Phishing Simulation)
- Operate recurring phishing simulations.
- Update templates & landing pages.
- Manage user lifecycle via SSO/SCIM; Smart Groups and risk scoring hygiene.
- Training assignments, reminders, and escalation rules and track completions.
- Monthly KPI reporting (phish prone %, repeat clickers, tracking training completion).
- Tune Phish Alert Button workflows.