Other

Senior Cyber Security Engineer

Sucafina

Beirut, Beirut Governorate, Lebanon
Full-time, Mid-Senior Level
Remote: No

Company Description

The Company:

Sucafina is the leading sustainable Farm to Roaster coffee company, with a family tradition in commodities that stretches back to 1905. Today, with more than 1,400 employees in 34 countries, we help stakeholders worldwide to find the perfect coffee solutions. We embed technology, innovation, and sustainability throughout the supply chain, creating shared value for all by Investing in Farmers, Caring for People, and Protecting Our Planet. For more information, visit www.sucafina.com.

What are we looking for:

We are looking for entrepreneurs, techies, passionate, eager to learn, humble, with a positive attitude and a high level of integrity People. Flexible and willing to take challenges, work and live in coffee-producing countries, People who want to build expertise and a career in the coffee business and are ready to go the extra mile.

What we offer:

We offer within our pleasant family environment, great opportunities to learn and grow, we offer challenges and exposure to multicultural environments, on-merit base compensation, and free coffee around the clock!

Job Description

Role Overview:

Senior technical owner of the company’s cybersecurity controls, with particular responsibility for application security and for security audit and compliance.

Key Responsibilities:

  • Application security: embed security into the SDLC, threat modelling, secure code review and remediation follow-up.
  • Penetration testing: scope and manage internal and third-party application and infrastructure tests, and drive findings to closure.
  • Security audit: lead internal and external audits, customer assessments and certification cycles; prepare evidence and close findings.
  • Compliance and frameworks: maintain controls, policies and standards against ISO 27001, NIST CSF / CIS Controls and applicable regulation.
  • Risk management: identify, assess and report information security risks and track treatment plans.
  • Vulnerability management: run the scanning and patching cycle with risk-based prioritization and SLAs.
  • SIEM and monitoring: maintain log coverage, correlation rules and alert tuning; ensure critical systems are monitored.
  • EDR / endpoint security: administer and tune the EDR/XDR platform, maintain coverage and perform threat hunting.
  • Network and perimeter security: manage Fortinet FortiGate firewall policies, IPS and web filtering, SSL inspection, VPN and rule recertification.
  • Identity and access management: govern authentication, MFA, SSO, privileged access and periodic access reviews.
  • Cloud security: define and verify hardening baselines and configuration for Azure.
  • Data protection: set standards for encryption, key management, data classification and DLP.
  • Incident response: act as senior responder; maintain and exercise playbooks and lead post-incident reviews.
  • Third-party security: assess vendors and SaaS providers and set contractual security requirements.
  • Awareness and reporting: deliver security training and phishing simulations; report metrics to management.

Job Qualifications

Qualifications and Experience:

      • Degree in Computer Science, Information Security or Engineering, or equivalent experience.
      • 6–8+ years in cybersecurity, including a senior or lead role.
      • Hands-on application security experience: secure SDLC, threat modelling, SAST/DAST/SCA, secure code review, OWASP Top 10 / ASVS.
      • Proven experience leading security audits and compliance work (ISO 27001, NIST CSF, CIS or SOC 2).
      • Solid command of cybersecurity essentials: risk, IAM, network, cloud, endpoint, cryptography, vulnerability management and incident response.
      • Hands-on SIEM experience (e.g. Forti SIEM)  log onboarding, use cases, alert tuning.
      • Hands-on EDR/XDR experience (e.g. Defender for Endpoint, CrowdStrike).
      • Hands-on Fortinet FortiGate firewall administration (policies, IPS, VPN, FortiManager / FortiAnalyzer).
      • Experience with at least one major cloud platform and modern CI/CD toolchains.
      • Ability to read code in at least one mainstream language and engage credibly with developers.
      • Preferred certifications: CISSP, CISM, CISA, CSSLP, ISO 27001 Lead Auditor, Fortinet NSE 4+, OSCP or SC-200.