ABOUT RMZ GROUP
RMZ Group is one of the world's largest privately-controlled alternative
asset owners, with a core focus on real estate, digital infrastructure,
renewable energy, and AI-driven transformation. With a bold 2031 Execution
Mandate and an IPO trajectory, RMZ is actively shaping tomorrow's economy
through sustainable, purpose-driven investment and innovation. Our IT team
underpins this ambition — securing, scaling, and evolving enterprise
technology across a complex, multi-location portfolio.
ROLE SUMMARY
We are seeking a skilled and versatile IT Security & Infrastructure
Engineer to join RMZ's enterprise IT team. This is a broad, high-impact
role spanning network security, endpoint protection, data loss prevention,
cloud security, messaging gateway management, IT service management, and
Windows server infrastructure. The ideal candidate will bring deep
technical expertise across multiple security and infrastructure domains,
with the ability to operate both independently and as part of a
collaborative team.
KEY RESPONSIBILITIES
1.
Fortinet Firewall Management (FortiGate)
•
Design, deploy, configure, and maintain enterprise Fortinet FortiGate
firewall infrastructure across all RMZ locations.
•
Administer and enforce firewall rule sets, ACLs, NAT policies, and
security zones aligned with RMZ's network security framework.
•
Conduct regular firewall policy audits, rule optimisation, and cleanup
exercises to minimise attack surface.
•
Monitor firewall logs and SIEM alerts; investigate and respond to
anomalies, intrusion attempts, and policy violations in real time.
•
Manage VPN infrastructure (site-to-site and remote access), ensuring
secure connectivity across all RMZ locations and cloud environments.
•
Configure and manage IPSec site-to-site VPN tunnels and SSL VPN
remote-access portals on FortiGate firewalls, including phase 1/phase 2
parameters, authentication, and split-tunnel policies.
•
Design and implement firewall high availability and redundancy —
configuring FortiGate HA clusters (active-passive / active-active),
failover, and session synchronisation to ensure continuous uptime.
•
Generate and maintain firewall reports — traffic and bandwidth analysis,
threat and intrusion reports, application usage, VPN tunnel status, and
compliance reporting using FortiAnalyzer / FortiGate reporting tools.
•
Produce scheduled and on-demand security reports for IT leadership,
audits, and ISO 27001:2025 / DPDP compliance reviews.
•
Perform firmware upgrades, patch management, and vulnerability remediation
in line with change management procedures.
•
Collaborate with network architects on zero-trust-aligned, segmented
network topologies.
•
Maintain comprehensive documentation of firewall configurations, topology
diagrams, and change logs.
2.
Broadcom Endpoint Protection (SEP)
•
Administer Broadcom Symantec Endpoint Protection (SEP) Manager or Carbon
Black Cloud/EDR across all endpoints — desktops, laptops, servers, and VDI
environments.
•
Define, deploy, and continuously tune endpoint protection policies
including antivirus, anti-malware, HIPS, application control, and device
control.
•
Oversee agent deployment, version lifecycle management, and endpoint
health monitoring across RMZ's full estate.
•
Investigate and remediate endpoint security incidents including malware
infections, ransomware events, and anomalous process behaviour.
•
Manage exclusion/exception lists, whitelisting policies, and threat
quarantine workflows.
•
Integrate endpoint telemetry with SIEM/SOC platforms for centralised
threat detection and correlated alerting.
•
Produce regular endpoint compliance and risk posture reports for IT
leadership review.
3.
Broadcom Cloud Messaging Gateway (Email Security)
•
Administer and manage the Broadcom Cloud Messaging Gateway (formerly
Symantec/MessageLabs) for inbound and outbound email security across all
RMZ domains.
•
Configure and fine-tune anti-spam, anti-phishing, anti-malware, and
advanced threat protection (sandboxing) policies.
•
Manage email routing, MX record hygiene, SPF/DKIM/DMARC configuration, and
relay controls.
•
Monitor email traffic flows, quarantine queues, and threat intelligence
dashboards; investigate and release false positives promptly.
•
Enforce email encryption policies for sensitive communications in
alignment with data protection requirements.
•
Respond to email-borne threats including phishing campaigns, BEC attempts,
and malicious attachment incidents.
•
Coordinate with Microsoft 365 / Exchange Online administration for
seamless mail flow and connector configuration.
•
Generate regular reports on email threat statistics, gateway performance,
and policy effectiveness.
4.
Broadcom Cloud DLP
•
Deploy and manage Broadcom Symantec DLP across endpoint, network, and
cloud channels to protect RMZ's sensitive and regulated data.
•
Define and maintain DLP policies, content inspection rules, and data
classifiers aligned to RMZ's data governance framework, ISO 27001:2025
standards, and DPDP compliance requirements.
•
Monitor DLP incident queues; investigate, triage, and escalate data
exfiltration events and policy violations.
•
Manage DLP agent deployment, health checks, and version updates across the
endpoint estate.
•
Collaborate with legal, compliance, and HR teams to define sensitive data
categories and appropriate handling procedures.
•
Produce DLP incident reports and trend analysis for CISO and senior IT
leadership.
•
Fine-tune policies to reduce false positives while maintaining effective
data protection coverage.
5.
Zscaler Web Proxy (ZIA / ZPA)
•
Administer and manage the Zscaler Internet Access (ZIA) and/or Zscaler
Private Access (ZPA) platform across RMZ's user population and office
locations.
•
Configure SSL inspection, URL filtering, cloud application control,
bandwidth management, and advanced threat protection policies.
•
Manage PAC files, GRE/IPSec tunnel configurations, and Zscaler Client
Connector deployment and updates.
•
Monitor Zscaler dashboards and logs for anomalous web traffic, shadow IT
usage, and policy violations.
•
Enforce acceptable use policies and cloud access security broker (CASB)
controls for sanctioned and unsanctioned SaaS applications.
•
Integrate Zscaler with Azure AD / Entra ID for identity-based policy
enforcement and SCIM-based user provisioning.
•
Collaborate with network teams to optimise traffic steering, branch
connectivity, and SD-WAN integration.
•
Stay current with Zscaler platform updates and evaluate new capabilities
aligned to RMZ's zero-trust strategy.
6.
ZOHO ManageEngine ServiceDesk Plus (ITSM)
•
Administer and configure ManageEngine ServiceDesk Plus for IT service
management across RMZ, including incident, problem, change, and asset
management modules.
•
Design and maintain service catalogue entries, SLA definitions, escalation
matrices, and automated workflows.
•
Configure multi-queue email identity routing, auto-ticket creation rules,
and notification templates.
•
Manage role-based access controls, technician groups, and approval
hierarchies within the tool.
•
Generate and distribute ITSM performance reports including ticket volumes,
SLA compliance, and resolution metrics for IT leadership.
•
Integrate ServiceDesk Plus with Active Directory / Entra ID for user
synchronisation and SSO.
•
Drive continuous improvement of ITSM processes, working with service desk
teams to reduce MTTR and improve end-user satisfaction.
•
Evaluate and implement upgrades, patches, and new ManageEngine modules as
RMZ's IT maturity evolves.
7.
Creation of Windows Servers & VM Servers
•
Build, provision, and configure Windows Server environments (2016 / 2019 /
2022) from the ground up on Hyper-V virtualisation infrastructure,
including OS installation, roles, and features.
•
Create, deploy, and manage virtual machines (VM servers) primarily on
Microsoft Hyper-V — including host configuration, virtual switches,
templates, checkpoints, resource allocation, and guest OS provisioning.
•
Administer Active Directory (AD DS), Group Policy Objects (GPO), DNS,
DHCP, and PKI/Certificate Services.
•
Manage Microsoft Entra ID (Azure AD) integration, Entra Connect
synchronisation, and hybrid identity configuration.
•
Perform regular patching via Windows Server Update Services (WSUS) or
Microsoft Endpoint Configuration Manager (MECM/SCCM).
•
Monitor server health, capacity, and performance using appropriate
monitoring tools; respond proactively to alerts and performance
degradation.
•
Administer file server infrastructure, DFS namespaces, and storage
management in line with data governance policies.
•
Manage server backup and recovery processes, ensuring RPO/RTO targets are
met for critical systems.
•
Support IT security hardening of Windows Server environments in alignment
with CIS Benchmarks and RMZ security standards.
8.
Backup & Recovery — Veritas Backup Exec and NetBackup
•
Administer and manage the Veritas backup environment (NetBackup and/or
Backup Exec) across physical, virtual, and cloud workloads.
•
Design, schedule, and maintain backup policies, retention schedules, and
storage lifecycle policies aligned to RMZ’s data protection and business
continuity requirements.
•
Manage backup media servers, storage units, deduplication pools (MSDP),
and tape/cloud storage targets.
•
Monitor daily backup jobs; investigate and remediate failures, ensuring
backup success rates meet defined SLAs.
•
Perform regular restore testing and disaster recovery drills to validate
recoverability and meet RPO/RTO objectives for critical systems.
•
Manage backup of business-critical workloads including Windows Servers,
Active Directory, Microsoft 365 / Exchange, SQL databases, and Hyper-V
(and VMware) virtual environments.
•
Optimise backup windows, capacity planning, and storage utilisation across
the backup estate.
•
Maintain documentation of backup architecture, schedules, and recovery
runbooks; produce regular backup compliance and health reports for IT
leadership.
•
Support backup-related security hardening, including ransomware-resilient
and immutable backup strategies.
9.
Fortinet SIEM Services (FortiSIEM)
•
Administer, configure, and maintain the Fortinet FortiSIEM platform for
centralised security information and event management across RMZ’s
infrastructure.
•
Onboard and integrate log sources across the environment — firewalls,
endpoints, servers, Zscaler, email gateway, DLP, network devices, and
cloud platforms.
•
Develop and tune correlation rules, alerting policies, and analytics to
detect threats, anomalies, and policy violations with minimal false
positives.
•
Monitor real-time dashboards and alerts; triage, investigate, and escalate
security incidents in line with RMZ’s incident response procedures.
•
Build and maintain custom reports, compliance dashboards, and executive
summaries for ISO 27001:2025 and DPDP audit requirements.
•
Manage FortiSIEM collectors, supervisors, and CMDB; ensure platform
health, log ingestion integrity, and event parsing accuracy.
•
Conduct threat hunting and forensic analysis using correlated event data
across multiple security layers.
•
Maintain log retention and archival policies aligned to regulatory and
organisational requirements.
•
Continuously enhance detection coverage by mapping use cases to frameworks
such as MITRE ATT&CK.
10.
Microsoft 365 (O365) Administration
•
Administer the Microsoft 365 tenant and admin centre, managing licensing,
service health, and overall platform governance.
•
Exchange Online — manage mailboxes, distribution and shared mailboxes,
mail flow and transport rules, connectors, anti-spam/anti-malware
policies, and hybrid Exchange configuration where applicable.
•
Microsoft Entra ID (Azure AD) — manage users, groups, roles, conditional
access policies, multi-factor authentication (MFA), SSO, and Entra Connect
synchronisation with on-premises Active Directory.
•
OneDrive for Business — configure storage policies, sharing and external
access controls, sync settings, retention, and data protection in line
with DLP and DPDP requirements.
•
Microsoft Teams — administer teams, channels, meeting and messaging
policies, guest access, app governance, and Teams telephony/voice
configuration where required.
•
Implement and manage security and compliance controls across M365 —
conditional access, data retention, and integration with Broadcom Cloud
DLP and email security.
•
Monitor M365 usage, adoption, and security posture via Microsoft 365
Defender and reporting dashboards.
•
Provide escalated support for M365 services and collaborate with the
service desk on end-user issues.
REQUIRED QUALIFICATIONS & SKILLS
Technical Skills
•
5+ years of hands-on experience across enterprise network security,
endpoint protection, and IT infrastructure.
•
Firewall administration — Fortinet FortiGate, Palo Alto Networks, Cisco
ASA/FTD, or Check Point (minimum 3 years).
•
Broadcom Symantec Endpoint Protection (SEP) Manager/EDR administration.
(minimum 3 years).
•
Broadcom Cloud Messaging Gateway (or Symantec MessageLabs / Email
Security. cloud) configuration and management. (minimum 3 years).
•
Broadcom Symantec DLP — policy authoring, incident management, and
multi-vector deployment.
•
Zscaler ZIA and/or ZPA — tunnel configuration, SSL inspection, CASB, and
Client Connector management.
•
ZOHO ManageEngine ServiceDesk Plus — ITSM configuration, workflow
automation, and SLA management.
•
Windows Server (2016/2019/2022), Active Directory, Group Policy, Entra ID,
and hybrid identity management.
•
Strong hands-on experience with Microsoft Hyper-V — host setup, VM
creation and lifecycle management, virtual networking, and clustering
(required).
•
Veritas NetBackup and/or Backup Exec — backup policy design, restore
operations, and disaster recovery management.
•
Solid understanding of TCP/IP, VLANs, routing (BGP/OSPF), DNS, DHCP, and
PKI fundamentals.
•
Hands-on experience administering Fortinet FortiSIEM — log source
onboarding, correlation rule development, and incident triage.
•
Familiarity with broader SIEM platforms (Microsoft Sentinel, Splunk, or
equivalent) is advantageous.
•
Added advantage: experience with VMware vSphere / ESXi virtualisation.
•
Added advantage: basic networking skills with a working knowledge of LAN /
VLAN concepts, switching, and structured cabling.
•
Microsoft 365 administration — Exchange Online, Entra ID (Azure AD),
OneDrive for Business, and Microsoft Teams.
Certifications (Preferred)
•
Fortinet NSE 4/7 or Palo Alto PCNSE
•
Fortinet FortiSIEM Specialist / NSE 5 (FortiSIEM) Certification
•
Broadcom Symantec Endpoint / DLP / Email Security Specialist Certification
•
Zscaler ZCCA-IA or ZCCP-IA / ZPA equivalent
•
Microsoft Certified: Windows Server Hybrid Administrator (AZ-800/801) or
MCSA
•
Veritas Certified Specialist (VCS) — NetBackup or Backup Exec
•
CompTIA Security+, CEH, or equivalent
•
CISSP or CISM (advantageous)
•
ITIL Foundation v4 (advantageous for ServiceDesk responsibilities)
•
Microsoft 365 Certified: Administrator Expert (MS-102) or equivalent
Education
•
Bachelor’s degree in computer science, Information Technology,
Cybersecurity, or a related field.
•
Equivalent professional experience with relevant certifications will be
considered.
BEHAVIOURAL COMPETENCIES
•
Strong analytical and troubleshooting skills across complex, multi-vendor
security and infrastructure environments.
•
High ownership mindset — proactively identifies risks and drives issues
through to resolution.
•
Clear communicator — able to translate technical detail into actionable
insight for business and IT leadership.
•
Disciplined approach to documentation, change management, and operational
governance.
•
Collaborative team player who partners effectively with network, cloud,
service desk, and compliance functions.
•
Committed to continuous learning; stays current with evolving threat
landscape and security technologies.
WHY JOIN RMZ
•
Play a pivotal role in securing RMZ's transformation from traditional real
estate to a global digital infrastructure and AI leader.
•
Contribute directly to ISO 27001:2025 compliance, DPDP implementation, and
IPO readiness programmes.
•
Work with a broad, enterprise-grade security stack across a
multi-location, multi-asset portfolio in India and globally.
•
Competitive remuneration, structured development pathways, and exposure to
strategic technology investment decisions.
•
A culture anchored in RMZ's values: Empowerment, Imagination, Agility, and
Well-Being.
Apply through whichever channel suits you best.