Cybersecurity Engineer
SiGMA Group · Germasogeia, Cyprus, Cyprus
Philanthropic Fundraising Services · 2-10 employees
About the role
You will own the day-to-day technical security of the organization's Microsoft 365 tenant, Cloudflare edge, and network infrastructure. This involves configuring security controls, monitoring alerts, and driving remediation efforts alongside IT Operations and DevOps teams.
What they look for
Requirements
The role requires 3-5+ years of hands-on experience in cybersecurity or security-focused infrastructure. Candidates must have practical knowledge of Microsoft 365 security, edge protection platforms, network security, and Linux systems.
Full description
Location: Limassol, Cyprus (hybrid, occasional travel to Malta)
Department: Information Technology
Reports To: Head of IT Platforms & Security
Type: Full-time
Role Summary
This is a hands-on security engineering role, not a policy-only position. You will own the day-to-day technical security of Sigma Group’s Microsoft 365 tenant, Cloudflare edge, firewalls and networks — configuring controls yourself, monitoring and investigating alerts in Log360 and Site24x7, and driving findings through to closure with IT Operations and DevOps.
Roughly 70% of the work is technical (configuration, hardening, detection, incident response, testing) and 30% is governance (policy, risk register, audits, awareness). You will work alongside IT Operations and DevOps in a fast-moving, multi-site environment, and report directly to the Head of IT Platforms & Security.
Our Environment
- You should be comfortable working hands-on with most of the following from day one:
- Microsoft 365 / Entra ID — Defender for Office 365, Defender for Endpoint, Intune, Purview DLP, Conditional Access, PIM
- Cloudflare — Zero Trust (Access, WARP, Gateway, Tunnels), WAF, DNS, DDoS and bot protection across a large domain portfolio
- Firewalls & networking — Cisco Meraki and Ubiquiti UniFi across multiple offices and event sites; site-to-site and client VPN
- Linux servers — Ubuntu/Debian workloads on cloud, built and maintained by our DevOps team, which you will partner with on security
- Monitoring & SIEM — Site24x7 for infrastructure, server and website monitoring; ManageEngine Log360 for log aggregation, correlation and alerting
- SaaS & endpoints — Windows and macOS fleet, BYOD, NAS storage, and a broad third-party SaaS estate
Key Responsibilities
- Microsoft 365, Identity & Endpoint Security
- Own and continuously harden the Microsoft 365 security baseline; track and improve Secure Score with a documented rationale for each exception.
- Configure and tune Defender for Office 365 — anti-phishing, anti-spam, Safe Links, Safe Attachments, quarantine policies, transport rules — and defend against BEC, spoofing and impersonation (SPF, DKIM, DMARC enforcement).
- Design and maintain Conditional Access policies, MFA and phishing-resistant authentication, risk-based sign-in policies, and Privileged Identity Management for admin roles.
- Implement and tune Purview DLP across Exchange, SharePoint, OneDrive, Teams and endpoints; handle false positives and user exceptions.
- Manage Defender for Endpoint and Intune compliance/configuration profiles for Windows, macOS and mobile, including BYOD and app protection policies.
- Review and remediate risky app registrations, OAuth consents, guest access and stale privileged accounts.
- Cloudflare & Edge Security
- Administer Cloudflare across the group’s domain portfolio: WAF rules and custom rulesets, rate limiting, bot management, DDoS protection and SSL/TLS configuration.
- Build and maintain Zero Trust access: Cloudflare Access applications and policies, Gateway DNS/HTTP filtering, and Tunnels to replace direct exposure of internal services.
- Investigate WAF blocks and false positives with application owners; write and test exceptions safely rather than switching protection off.
- Maintain DNS hygiene — records, CAA, email authentication, and removal of dangling or unused entries that create takeover risk.
- Firewalls, Network & Infrastructure Security
- Configure and review firewall rules, VLAN segmentation, IDS/IPS and content filtering on Meraki and Ubiquiti.
- Run periodic firewall rule reviews — remove any/any rules, unused objects, and unnecessary inbound exposure; keep an accurate record of what is open and why.
- Secure wireless and guest networks, and manage site-to-site and remote-access VPN configuration.
- Review the Cloud Infrastructure estate for security gaps: security groups, IAM policies and keys, public S3 buckets, logging and encryption at rest.
- Server & Workload Security (with DevOps)
- Our DevOps team builds and operates the Linux server estate. You are not expected to be a Linux systems administrator — but you do need to be comfortable enough on the command line to review a server, read logs and confirm that controls are in place.
- Define the security baseline for Linux servers (CIS-aligned) and review configurations against it — SSH and key-based access, sudo policy, unnecessary services, host firewall, logging and time sync.
- Review patch and vulnerability status across the server estate, raise what needs fixing, and track it to closure with DevOps, who own the patching windows and execution.
- Verify that servers are onboarded to monitoring and logging, and that host-level controls (host firewall, fail2ban, auditd or equivalent) are present and reporting.
- Manage privileged access to servers from a security standpoint: account lifecycle, key rotation, removal of shared credentials, and access via jump host or Cloudflare Tunnel rather than open SSH.
- Review the security of web-facing and containerised workloads together with DevOps — TLS configuration, reverse-proxy hardening, secrets handling and least-privilege service accounts.
- Feed security requirements into deployment pipelines and infrastructure-as-code rather than bolting them on afterwards.
- Vulnerability Management & Testing
- Run quarterly (and ad-hoc) authenticated vulnerability scans across servers, endpoints, network devices and cloud services using tools such as Nessus, Qualys or OpenVAS.
- Triage findings by real exploitability and business impact, assign owners, track remediation to closure, and re-scan to verify.
- Perform targeted internal testing of websites, network devices and internal applications using standard tooling (Nmap, Burp Suite, Metasploit, OWASP methodology) within an agreed scope.
- Coordinate external penetration tests and manage the remediation plan that follows.
- Monitoring, Detection & Incident Response
- Own the security side of ManageEngine Log360: onboard log sources (Microsoft 365, Entra ID, firewalls, Cloudflare, servers, network devices), build and tune correlation rules and alert profiles, and cut down false positives so alerts are trusted and acted on.
- Work with IT Operations and DevOps in Site24x7 to make sure security-relevant assets, services, certificates and websites are monitored, and that thresholds and escalation paths are set correctly.
- Use Log360 and Site24x7 as your daily working view — review dashboards and alerts, investigate anomalies, and turn recurring findings into permanent configuration or rule changes.
- Act as first responder for security incidents: detect, investigate, contain, eradicate and recover, with clear communication to management throughout.
Perform log analysis and basic forensics — sign-in and audit logs, mailbox rules, endpoint timelines, server and web logs, evidence preservation.
- Run post-incident reviews, document root cause, and make sure corrective actions are actually implemented.
- Track threat intelligence relevant to our sector and translate it into concrete configuration changes.
- Governance, Risk & Compliance
- Maintain the security policy set (acceptable use, access control, DLP, remote access, BYOD, vendor security) and keep it aligned with how systems are actually configured.
- Run risk assessments and maintain the corporate risk register with owners, mitigations and review dates, mapped to ISO 27001, NIST CSF and CIS Controls.
- Support internal and external audits and GDPR/data protection obligations, and produce the evidence auditors ask for.
- Run security awareness training and phishing simulations, and follow up with the people and teams that need it.
- Perform security reviews of new SaaS vendors and integrations before they go live.
- Reporting & Continuous Improvement
- Produce a monthly security posture report: incidents, threats, vulnerability trends, patch and compliance status, and progress against the roadmap.
- Maintain a rolling 12-month security roadmap with clear priorities, effort and expected risk reduction.
- Brief management in plain language — what the risk is, what it costs, and what you recommend.
Required Skills & Experience
- 3–5+ years in a hands-on cybersecurity, security engineering or security-focused infrastructure role.
- Demonstrable hands-on administration of Microsoft 365 security: Defender for Office 365, Defender for Endpoint, Entra ID, Conditional Access, Intune.
- Practical experience with Cloudflare or an equivalent edge/Zero Trust platform (WAF, DNS, access proxy, tunnels).
- Solid firewall and network security experience — rule design and review, segmentation, VPN, wireless security (Meraki, Ubiquiti, Fortinet, pfSense or similar).
- Working knowledge of Linux — confident on the command line and able to review server configuration, permissions, services and logs. Deep systems administration is handled by DevOps, so breadth matters more than depth here.
- Experience with a SIEM or centralised log platform — onboarding sources, writing and tuning correlation rules, and investigating alerts. ManageEngine Log360 experience is a strong advantage; Sentinel, Wazuh, Splunk, ELK or similar transfers well.
- Experience with infrastructure and uptime monitoring platforms such as Site24x7, Zabbix, Nagios or Datadog, including alert configuration and escalation.
- Working knowledge of vulnerability scanning tools and the ability to interpret and prioritise results rather than forward raw reports.
- Incident response and log analysis fundamentals across cloud, endpoint and server.
- Good understanding of ISO 27001, NIST CSF and CIS Controls, and how to apply them to real systems.
- Clear written and spoken English, and the ability to explain technical risk to non-technical stakeholders.
Preferred Skills
- Scripting and automation — PowerShell, Microsoft Graph, Python, Bash — to report, remediate and enforce at scale.
- AWS or Azure security experience (IAM, security groups, logging, CSPM tooling).
- Hands-on penetration testing or red-team exposure and familiarity with OWASP Top 10.
- Familiarity with container and CI/CD security concepts (Docker, image scanning, secrets management) — enough to review what DevOps builds.
- Experience securing distributed, multi-office and event-based environments.
- Experience in a regulated or high-visibility sector such as iGaming, fintech or events.
Certifications (preferred, not required)
- CompTIA Security+ or CySA+
- Microsoft Certified: Security Operations Analyst (SC-200) or Identity & Access Administrator (SC-300)
- ISO 27001 Lead Implementer / Lead Auditor
- OSCP, CEH, CISSP or CISM (advantageous)
First 90 Days
- To give you a sense of what the role looks like in practice, in your first three months you would be expected to:
- Complete a full review of the Microsoft 365 security baseline and deliver a prioritised hardening plan.
- Audit Cloudflare configuration and DNS across the domain portfolio and close off exposed or misconfigured services.
- Run a firewall rule and network segmentation review across all sites.
- Agree a CIS-aligned Linux hardening baseline with DevOps and assess the current estate against it.
- Review Log360 coverage and alert rules, close any gaps in log sources, and tune out the noise.
- Deliver the first full vulnerability scan cycle with an owned, tracked remediation plan.