
Engineer, Security
- Pasay City, Metro Manila
- Permanent
- Full-time
- Key contributor to the protection of shoreside IT and shipboard IT and OT systems and processes to appropriately reduce existing and emerging risks to RCL assets
- Technical excellence - Administer systems to deliver high availability & security
- Troubleshooting skills - Identify and fix root causes of failure, with primary focus on firewall, EDR, and proxy issues
- Change Management - Ensure that outages & change requests are correctly documented, prioritized, and closed
- Ability to specialize - Become an expert in 1-3 of our tools so you can solve difficult problems
- Ability to learn - Provide basic support across a variety of security systems
- Participate in 24/7 on-call rotations to resolve critical issues
- Leverage information security activities and technologies to raise cyber situational awareness and protection
- Assist with maritime cybersecurity technology intended to protect shipboard systems and information is configured and operating per established standards.
- Maintain technical standards, architectural/engineering diagrams, and procedures for shoreside, shipboard and newbuild IT and technology
- Review and understand complex cyber guidelines (NIST) and regulations such as BIMCO Cybersecurity Guidelines for Ships, U.S. Coast Guard security requirements, and International Maritime Organization (IMO)
- Contribute with a high degree of self-sufficiency and resourcefulness on individual and departmental performance objectives
- High degree of motivation to maintain technical skills and cybersecurity knowledge relevant by seeking self-development opportunities such as industry certifications, investing time to learn new skills, and networking with peers in the security industry
- Actively engage in liaison activities with industry associations, peer institutions, regulatory and contractual agencies/organizations and IS information sharing communities
- Bachelor's degree or equivalent industry experience.
- 4-6 years of experience within Information Security
- 2+ years of experience in information security operations role
- Demonstrated ability to perform independent analysis of complex problems
- Deep technical knowledge in multiple enterprise security tool categories, especially firewalls, VPN, web security proxies, and endpoint security tools.
- Prior experience with CMDB, Proxy, firewalls, or EDR systems are strongly preferred.
- Broad IT knowledge, including hardware, virtualization, networking, architecture, common protocols, files systems and operating systems.
- An ability to communicate complex technical issues to English-speakers from many cultures
- Must have competent verbal and written communication abilities; interpersonal collaborative skills; and the ability to communicate IS and risk-related concepts to technical and non-technical audiences
- Ability to learn methodologies, tools, best practices and processes within specific areas of responsibility
- Decision-making, reporting, communication, and skills
- Understanding of Apple, Linux and Windows Operating systems.
- Understanding of TCP/IP networks and the OSI stack.
- Technical understanding across IT systems (applications, networks etc) and information security products (i.e firewalls, IPS, SIEM, proxy) and application security/vulnerability testing tools/techniques
- Understanding of cybersecurity controls related to a number of cybersecurity frameworks/guidelines such as NIST Cybersecurity Framework and BIMCO/CLIA/ICS/INTERCARGO Cybersecurity Guidelines
- Industry certifications are a plus
- Demonstrates organizational skills and time management
- Ability to manage multiple tasks / projects while ensuring deadlines are met
- Displays sound judgment with a high level of integrity, ethics and ability to calmly, diplomatically and effectively deal with stressful situations
- Able to formulate, communicate exceptions/findings and technical solutions
- Demonstrate a degree of creativity with adept analytical and problem solving skills
- General understanding or experience with some Marine or Industrial Engineering OT systems (ICS, Engine Control, HVAC, Water Treatment, Power Generation & Management) and Navigation Systems (ECDIS, GPS, Dynamic Positioning Systems, Voyage Management Systems) is a plus
- Ability to identify remediation activities based on risk to the overall enterprise
- An understanding of anomaly detection methodologies and tools
- Understanding of cryptographic controls and the application is a plus