Loading open roles
Loading open roles
Loading role

UpMan Placements Private Limited · posted 2 months ago
ABOUT RMZ GROUP
RMZ Group is one of the world's largest privately-controlled alternative asset owners, with a core focus on real estate, digital infrastructure, renewable energy, and AI-driven transformation. With a bold 2031 Execution Mandate and an IPO trajectory, RMZ is actively shaping tomorrow's economy through sustainable, purpose-driven investment and innovation. Our IT team underpins this ambition — securing, scaling, and evolving enterprise technology across a complex, multi-location portfolio.
ROLE SUMMARY
We are seeking a skilled and versatile IT Security & Infrastructure Engineer to join RMZ's enterprise IT team. This is a broad, high-impact role spanning network security, endpoint protection, data loss prevention, cloud security, messaging gateway management, IT service management, and Windows server infrastructure. The ideal candidate will bring deep technical expertise across multiple security and infrastructure domains, with the ability to operate both independently and as part of a collaborative team.
KEY RESPONSIBILITIES
1. Fortinet Firewall Management (FortiGate)
• Design, deploy, configure, and maintain enterprise Fortinet FortiGate firewall infrastructure across all RMZ locations.
• Administer and enforce firewall rule sets, ACLs, NAT policies, and security zones aligned with RMZ's network security framework.
• Conduct regular firewall policy audits, rule optimisation, and cleanup exercises to minimise attack surface.
• Monitor firewall logs and SIEM alerts; investigate and respond to anomalies, intrusion attempts, and policy violations in real time.
• Manage VPN infrastructure (site-to-site and remote access), ensuring secure connectivity across all RMZ locations and cloud environments.
• Configure and manage IPSec site-to-site VPN tunnels and SSL VPN remote-access portals on FortiGate firewalls, including phase 1/phase 2 parameters, authentication, and split-tunnel policies.
• Design and implement firewall high availability and redundancy — configuring FortiGate HA clusters (active-passive / active-active), failover, and session synchronisation to ensure continuous uptime.
• Generate and maintain firewall reports — traffic and bandwidth analysis, threat and intrusion reports, application usage, VPN tunnel status, and compliance reporting using FortiAnalyzer / FortiGate reporting tools.
• Produce scheduled and on-demand security reports for IT leadership, audits, and ISO 27001:2025 / DPDP compliance reviews.
• Perform firmware upgrades, patch management, and vulnerability remediation in line with change management procedures.
• Collaborate with network architects on zero-trust-aligned, segmented network topologies.
• Maintain comprehensive documentation of firewall configurations, topology diagrams, and change logs.
2. Broadcom Endpoint Protection (SEP)
• Administer Broadcom Symantec Endpoint Protection (SEP) Manager or Carbon Black Cloud/EDR across all endpoints — desktops, laptops, servers, and VDI environments.
• Define, deploy, and continuously tune endpoint protection policies including antivirus, anti-malware, HIPS, application control, and device control.
• Oversee agent deployment, version lifecycle management, and endpoint health monitoring across RMZ's full estate.
• Investigate and remediate endpoint security incidents including malware infections, ransomware events, and anomalous process behaviour.
• Manage exclusion/exception lists, whitelisting policies, and threat quarantine workflows.
• Integrate endpoint telemetry with SIEM/SOC platforms for centralised threat detection and correlated alerting.
• Produce regular endpoint compliance and risk posture reports for IT leadership review.
3. Broadcom Cloud Messaging Gateway (Email Security)
• Administer and manage the Broadcom Cloud Messaging Gateway (formerly Symantec/MessageLabs) for inbound and outbound email security across all RMZ domains.
• Configure and fine-tune anti-spam, anti-phishing, anti-malware, and advanced threat protection (sandboxing) policies.
• Manage email routing, MX record hygiene, SPF/DKIM/DMARC configuration, and relay controls.
• Monitor email traffic flows, quarantine queues, and threat intelligence dashboards; investigate and release false positives promptly.
• Enforce email encryption policies for sensitive communications in alignment with data protection requirements.
• Respond to email-borne threats including phishing campaigns, BEC attempts, and malicious attachment incidents.
• Coordinate with Microsoft 365 / Exchange Online administration for seamless mail flow and connector configuration.
• Generate regular reports on email threat statistics, gateway performance, and policy effectiveness.
4. Broadcom Cloud DLP
• Deploy and manage Broadcom Symantec DLP across endpoint, network, and cloud channels to protect RMZ's sensitive and regulated data.
• Define and maintain DLP policies, content inspection rules, and data classifiers aligned to RMZ's data governance framework, ISO 27001:2025 standards, and DPDP compliance requirements.
• Monitor DLP incident queues; investigate, triage, and escalate data exfiltration events and policy violations.
• Manage DLP agent deployment, health checks, and version updates across the endpoint estate.
• Collaborate with legal, compliance, and HR teams to define sensitive data categories and appropriate handling procedures.
• Produce DLP incident reports and trend analysis for CISO and senior IT leadership.
• Fine-tune policies to reduce false positives while maintaining effective data protection coverage.
5. Zscaler Web Proxy (ZIA / ZPA)
• Administer and manage the Zscaler Internet Access (ZIA) and/or Zscaler Private Access (ZPA) platform across RMZ's user population and office locations.
• Configure SSL inspection, URL filtering, cloud application control, bandwidth management, and advanced threat protection policies.
• Manage PAC files, GRE/IPSec tunnel configurations, and Zscaler Client Connector deployment and updates.
• Monitor Zscaler dashboards and logs for anomalous web traffic, shadow IT usage, and policy violations.
• Enforce acceptable use policies and cloud access security broker (CASB) controls for sanctioned and unsanctioned SaaS applications.
• Integrate Zscaler with Azure AD / Entra ID for identity-based policy enforcement and SCIM-based user provisioning.
• Collaborate with network teams to optimise traffic steering, branch connectivity, and SD-WAN integration.
• Stay current with Zscaler platform updates and evaluate new capabilities aligned to RMZ's zero-trust strategy.
6. ZOHO ManageEngine ServiceDesk Plus (ITSM)
• Administer and configure ManageEngine ServiceDesk Plus for IT service management across RMZ, including incident, problem, change, and asset management modules.
• Design and maintain service catalogue entries, SLA definitions, escalation matrices, and automated workflows.
• Configure multi-queue email identity routing, auto-ticket creation rules, and notification templates.
• Manage role-based access controls, technician groups, and approval hierarchies within the tool.
• Generate and distribute ITSM performance reports including ticket volumes, SLA compliance, and resolution metrics for IT leadership.
• Integrate ServiceDesk Plus with Active Directory / Entra ID for user synchronisation and SSO.
• Drive continuous improvement of ITSM processes, working with service desk teams to reduce MTTR and improve end-user satisfaction.
• Evaluate and implement upgrades, patches, and new ManageEngine modules as RMZ's IT maturity evolves.
7. Creation of Windows Servers & VM Servers
• Build, provision, and configure Windows Server environments (2016 / 2019 / 2022) from the ground up on Hyper-V virtualisation infrastructure, including OS installation, roles, and features.
• Create, deploy, and manage virtual machines (VM servers) primarily on Microsoft Hyper-V — including host configuration, virtual switches, templates, checkpoints, resource allocation, and guest OS provisioning.
• Administer Active Directory (AD DS), Group Policy Objects (GPO), DNS, DHCP, and PKI/Certificate Services.
• Manage Microsoft Entra ID (Azure AD) integration, Entra Connect synchronisation, and hybrid identity configuration.
• Perform regular patching via Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager (MECM/SCCM).
• Monitor server health, capacity, and performance using appropriate monitoring tools; respond proactively to alerts and performance degradation.
• Administer file server infrastructure, DFS namespaces, and storage management in line with data governance policies.
• Manage server backup and recovery processes, ensuring RPO/RTO targets are met for critical systems.
• Support IT security hardening of Windows Server environments in alignment with CIS Benchmarks and RMZ security standards.
8. Backup & Recovery — Veritas Backup Exec and NetBackup
• Administer and manage the Veritas backup environment (NetBackup and/or Backup Exec) across physical, virtual, and cloud workloads.
• Design, schedule, and maintain backup policies, retention schedules, and storage lifecycle policies aligned to RMZ’s data protection and business continuity requirements.
• Manage backup media servers, storage units, deduplication pools (MSDP), and tape/cloud storage targets.
• Monitor daily backup jobs; investigate and remediate failures, ensuring backup success rates meet defined SLAs.
• Perform regular restore testing and disaster recovery drills to validate recoverability and meet RPO/RTO objectives for critical systems.
• Manage backup of business-critical workloads including Windows Servers, Active Directory, Microsoft 365 / Exchange, SQL databases, and Hyper-V (and VMware) virtual environments.
• Optimise backup windows, capacity planning, and storage utilisation across the backup estate.
• Maintain documentation of backup architecture, schedules, and recovery runbooks; produce regular backup compliance and health reports for IT leadership.
• Support backup-related security hardening, including ransomware-resilient and immutable backup strategies.
9. Fortinet SIEM Services (FortiSIEM)
• Administer, configure, and maintain the Fortinet FortiSIEM platform for centralised security information and event management across RMZ’s infrastructure.
• Onboard and integrate log sources across the environment — firewalls, endpoints, servers, Zscaler, email gateway, DLP, network devices, and cloud platforms.
• Develop and tune correlation rules, alerting policies, and analytics to detect threats, anomalies, and policy violations with minimal false positives.
• Monitor real-time dashboards and alerts; triage, investigate, and escalate security incidents in line with RMZ’s incident response procedures.
• Build and maintain custom reports, compliance dashboards, and executive summaries for ISO 27001:2025 and DPDP audit requirements.
• Manage FortiSIEM collectors, supervisors, and CMDB; ensure platform health, log ingestion integrity, and event parsing accuracy.
• Conduct threat hunting and forensic analysis using correlated event data across multiple security layers.
• Maintain log retention and archival policies aligned to regulatory and organisational requirements.
• Continuously enhance detection coverage by mapping use cases to frameworks such as MITRE ATT&CK.
10. Microsoft 365 (O365) Administration
• Administer the Microsoft 365 tenant and admin centre, managing licensing, service health, and overall platform governance.
• Exchange Online — manage mailboxes, distribution and shared mailboxes, mail flow and transport rules, connectors, anti-spam/anti-malware policies, and hybrid Exchange configuration where applicable.
• Microsoft Entra ID (Azure AD) — manage users, groups, roles, conditional access policies, multi-factor authentication (MFA), SSO, and Entra Connect synchronisation with on-premises Active Directory.
• OneDrive for Business — configure storage policies, sharing and external access controls, sync settings, retention, and data protection in line with DLP and DPDP requirements.
• Microsoft Teams — administer teams, channels, meeting and messaging policies, guest access, app governance, and Teams telephony/voice configuration where required.
• Implement and manage security and compliance controls across M365 — conditional access, data retention, and integration with Broadcom Cloud DLP and email security.
• Monitor M365 usage, adoption, and security posture via Microsoft 365 Defender and reporting dashboards.
• Provide escalated support for M365 services and collaborate with the service desk on end-user issues.
REQUIRED QUALIFICATIONS & SKILLS
Technical Skills
• 5+ years of hands-on experience across enterprise network security, endpoint protection, and IT infrastructure.
• Firewall administration — Fortinet FortiGate, Palo Alto Networks, Cisco ASA/FTD, or Check Point (minimum 3 years).
• Broadcom Symantec Endpoint Protection (SEP) Manager/EDR administration. (minimum 3 years).
• Broadcom Cloud Messaging Gateway (or Symantec MessageLabs / Email Security. cloud) configuration and management. (minimum 3 years).
• Broadcom Symantec DLP — policy authoring, incident management, and multi-vector deployment.
• Zscaler ZIA and/or ZPA — tunnel configuration, SSL inspection, CASB, and Client Connector management.
• ZOHO ManageEngine ServiceDesk Plus — ITSM configuration, workflow automation, and SLA management.
• Windows Server (2016/2019/2022), Active Directory, Group Policy, Entra ID, and hybrid identity management.
• Strong hands-on experience with Microsoft Hyper-V — host setup, VM creation and lifecycle management, virtual networking, and clustering (required).
• Veritas NetBackup and/or Backup Exec — backup policy design, restore operations, and disaster recovery management.
• Solid understanding of TCP/IP, VLANs, routing (BGP/OSPF), DNS, DHCP, and PKI fundamentals.
• Hands-on experience administering Fortinet FortiSIEM — log source onboarding, correlation rule development, and incident triage.
• Familiarity with broader SIEM platforms (Microsoft Sentinel, Splunk, or equivalent) is advantageous.
• Added advantage: experience with VMware vSphere / ESXi virtualisation.
• Added advantage: basic networking skills with a working knowledge of LAN / VLAN concepts, switching, and structured cabling.
• Microsoft 365 administration — Exchange Online, Entra ID (Azure AD), OneDrive for Business, and Microsoft Teams.
Certifications (Preferred)
• Fortinet NSE 4/7 or Palo Alto PCNSE
• Fortinet FortiSIEM Specialist / NSE 5 (FortiSIEM) Certification
• Broadcom Symantec Endpoint / DLP / Email Security Specialist Certification
• Zscaler ZCCA-IA or ZCCP-IA / ZPA equivalent
• Microsoft Certified: Windows Server Hybrid Administrator (AZ-800/801) or MCSA
• Veritas Certified Specialist (VCS) — NetBackup or Backup Exec
• CompTIA Security+, CEH, or equivalent
• CISSP or CISM (advantageous)
• ITIL Foundation v4 (advantageous for ServiceDesk responsibilities)
• Microsoft 365 Certified: Administrator Expert (MS-102) or equivalent
Education
• Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
• Equivalent professional experience with relevant certifications will be considered.
BEHAVIOURAL COMPETENCIES
• Strong analytical and troubleshooting skills across complex, multi-vendor security and infrastructure environments.
• High ownership mindset — proactively identifies risks and drives issues through to resolution.
• Clear communicator — able to translate technical detail into actionable insight for business and IT leadership.
• Disciplined approach to documentation, change management, and operational governance.
• Collaborative team player who partners effectively with network, cloud, service desk, and compliance functions.
• Committed to continuous learning; stays current with evolving threat landscape and security technologies.
WHY JOIN RMZ
• Play a pivotal role in securing RMZ's transformation from traditional real estate to a global digital infrastructure and AI leader.
• Contribute directly to ISO 27001:2025 compliance, DPDP implementation, and IPO readiness programmes.
• Work with a broad, enterprise-grade security stack across a multi-location, multi-asset portfolio in India and globally.
• Competitive remuneration, structured development pathways, and exposure to strategic technology investment decisions.
• A culture anchored in RMZ's values: Empowerment, Imagination, Agility, and Well-Being.