Skip to content

Open nowPosted 75 days ago

IT Security Officer

Workable (global search)108,016 open roles

Where
Kifisia, Attica, Greece
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Security OfficerWorkable (global search) · Kifisia, Attica, Greece
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 75 days ago

Workable (global search) median: 7 days open

The posting

Role Summary

Castor Ships S.A. is looking for a hands-on IT Security Officer to take technical ownership of the company's security systems and controls. Your core function is to ensure that every security policy is correctly and verifiably configured across every system — firewall, endpoint protection, identity platform, SIEM, and Microsoft 365 / Azure security stack. You will spend your time building, tuning, hardening, and verifying. This is a hands-on technical implementation role: you operate, configure, and verify the security controls defined under the Company's cybersecurity Policy.

Core Responsibilities

Firewall & Network Security

  • Configure, administer, and maintain the company's next-generation firewall (NGFW) platform including rule base management, NAT policies, application control, SSL/TLS inspection, and IPS/IDS signature management
  • Maintain firewall high-availability (HA) configuration and execute firmware upgrade cycles; verify failover behavior after each change
  • Configure and maintain site-to-site IPsec IKEv2 VPN tunnels for vessel and remote office connectivity; configure and manage the remote access VPN solution including client deployment and connection profiles
  • Execute scheduled technical reviews of the firewall rule base — identify and remove redundant, overly permissive, or shadowed rules; implement approved corrections and record changes in the change register
  • Configure and maintain DNS filtering, web content filtering categories, and application-layer controls to enforce acceptable use at the network level

Microsoft Azure & Microsoft 365 Security

  • Configure and maintain Microsoft Entra ID security controls: Conditional Access policies, sign-in risk policies, Identity Protection settings, Privileged Identity Management (PIM) role assignments, and Named Locations in accordance with the Company’s Cybersecurity Policy
  • Deploy, configure, and maintain Microsoft Defender for Endpoint (MDE) across all managed servers and workstations: sensor health verification, attack surface reduction (ASR) rule configuration, and custom detection rule implementation
  • Maintain Microsoft Defender for Office 365 protective policies: anti-phishing rules, safe links, safe attachments, anti-spoofing, and impersonation protection settings in accordance with the Company's Cybersecurity Policy
  • Implement security hardening recommendations from Microsoft Defender for Cloud; configure and verify controls contributing to Secure Score improvement targets
  • Configure and maintain Entra ID MFA policies, SSPR settings, authentication methods, and named exclusions; verify enforcement across all in-scope accounts

Endpoint & Server Security

  • Configure and maintain EPP/EDR platform policies across Windows workstations and servers: protection levels, exclusion management, tamper protection, and automated response actions
  • Configure Windows Defender Antivirus, Attack Surface Reduction rules, and Controlled Folder Access via Intune or Group Policy; verify rule enforcement is active and correctly applied on all managed devices
  • Implement and maintain application control policies, USB device control configurations, and removable media restrictions across the managed endpoint estate in accordance with the Company’s Cybersecurity Policy
  • Apply and enforce CIS Benchmark or Microsoft Security Baseline hardening configurations on Windows Server and Windows 10/11 systems; verify compliance using configuration assessment tools
  • Configure and maintain email security gateway settings: SPF, DKIM, and DMARC enforcement, anti-spam policies, quarantine configuration, and inbound/outbound mail flow rules
  • Manage certificate lifecycle for all in-scope services: request, deploy, renew, and revoke SSL/TLS certificates for published services; maintain the internal CA and certificate inventory

SIEM Platform Configuration & Tuning

  • Build and maintain the SIEM platform (ManageEngine Log360 / Microsoft Sentinel or equivalent): configure log source connectors, define parsing rules.
  • Ensure complete and verified log ingestion from all critical sources: firewalls, domain controllers, Active Directory, Windows servers, endpoints, Microsoft 365, Entra ID, and network infrastructure devices; remediate any gaps in coverage
  • Vulnerability Management & Security Testing
  • Technically remediate confirmed vulnerabilities within defined SLA windows — apply patches, harden configurations, or implement compensating controls; verify remediation by re-scanning
  • Regularly review and assess the company's external attack surface — verify that only approved services are internet-facing, enumerate open ports, and close or restrict any identified exposure

Identity & Access Security

  • Configure and maintain API key and application credential expiry policies within Azure and connected platforms; verify rotation compliance is enforced at the platform level.
  • Technical Remediation Support During Incidents
  • On instruction from the Cybersecurity Officer, execute technical containment actions within security systems: isolate compromised endpoints in Microsoft Defender for Endpoint, block malicious IPs or domains in the firewall and DNS filtering platform, revoke active sessions and tokens in Entra ID
  • Disable or lock compromised user and service accounts in Active Directory and Entra ID; force credential resets and MFA re-registration for affected identities
  • Remove malicious rules, scheduled tasks, registry entries, or persistence mechanisms identified on compromised systems through EDR tooling

Requirements

Qualifications & Experience

  • Bachelor's degree in Information Security, Computer Science, or related technical field
  • Minimum 4 years of hands-on IT security engineering or security operations experience
  • Demonstrated, configuration-level expertise with at least one enterprise NGFW platform — Sophos XGS/SFOS, Fortinet FortiGate, Palo Alto PAN-OS, or equivalent; rule base management and VPN configuration experience required
  • Strong practical knowledge of Microsoft Azure and Microsoft 365 security configuration: Conditional Access, Entra ID Identity Protection, PIM, Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Purview, and Microsoft Sentinel
  • Hands-on SIEM experience: log source onboarding, correlation rule creation, alert tuning, and platform health management (ManageEngine Log360, Microsoft Sentinel, Splunk, or equivalent)
  • Strong working knowledge of network security: TCP/IP, VLANs, firewall rule logic, IPS/IDS, DNS security, TLS inspection, and VPN technologies (IPsec IKEv2, SSL VPN)
  • Experience implementing and verifying CIS Benchmark or Microsoft Security Baseline configurations on Windows Server and Windows 10/11
  • Hands-on experience with email security: SPF, DKIM, DMARC, anti-phishing policies, and mail flow security controls
  • CompTIA Security+, CEH, or CISSP is a strong advantage
  • Fluent in English and Greek language

Benefits

💰 Competitive salary, plus annual discretionary bonus performance related (taxed at just 10% under shipping-sector tax rules)

🏥 Coverage under the company's collective Life, Health & Dental insurance plan

🥗 Daily catered lunch — main dish and side salad provided on us, every day

☕ Healthy breakfast, snacks and beverages always stocked in the breakout area

🎉 Company-sponsored team-bonding events

🎂 A special birthday gift, because your day deserves to be celebrated

📈 Ongoing development opportunities to sharpen your skills and grow your career within Shipping

🚀 An entrepreneurial culture and genuinely interesting people to work with

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.