Castor Ships S.A.

IT Security Officer

Castor Ships S.A.  •  Kifisiá, GR (Onsite)  •  10 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Castor Ships S.A. is looking for a hands-on IT Security Officer to take technical ownership of the company's security systems and controls. Your core function is to ensure that every security policy is correctly and verifiably configured across every system — firewall, endpoint protection, identity platform, SIEM, and Microsoft 365 / Azure security stack. You will spend your time building, tuning, hardening, and verifying. This is a hands-on technical implementation role: you operate, configure, and verify the security controls defined under the Company's cybersecurity Policy.

Core Responsibilities

Firewall & Network Security

  • Configure, administer, and maintain the company's next-generation firewall (NGFW) platform including rule base management, NAT policies, application control, SSL/TLS inspection, and IPS/IDS signature management
  • Maintain firewall high-availability (HA) configuration and execute firmware upgrade cycles; verify failover behavior after each change
  • Configure and maintain site-to-site IPsec IKEv2 VPN tunnels for vessel and remote office connectivity; configure and manage the remote access VPN solution including client deployment and connection profiles
  • Execute scheduled technical reviews of the firewall rule base — identify and remove redundant, overly permissive, or shadowed rules; implement approved corrections and record changes in the change register
  • Configure and maintain DNS filtering, web content filtering categories, and application-layer controls to enforce acceptable use at the network level

Microsoft Azure & Microsoft 365 Security

  • Configure and maintain Microsoft Entra ID security controls: Conditional Access policies, sign-in risk policies, Identity Protection settings, Privileged Identity Management (PIM) role assignments, and Named Locations in accordance with the Company’s Cybersecurity Policy
  • Deploy, configure, and maintain Microsoft Defender for Endpoint (MDE) across all managed servers and workstations: sensor health verification, attack surface reduction (ASR) rule configuration, and custom detection rule implementation
  • Maintain Microsoft Defender for Office 365 protective policies: anti-phishing rules, safe links, safe attachments, anti-spoofing, and impersonation protection settings in accordance with the Company's Cybersecurity Policy
  • Implement security hardening recommendations from Microsoft Defender for Cloud; configure and verify controls contributing to Secure Score improvement targets
  • Configure and maintain Entra ID MFA policies, SSPR settings, authentication methods, and named exclusions; verify enforcement across all in-scope accounts

Endpoint & Server Security

  • Configure and maintain EPP/EDR platform policies across Windows workstations and servers: protection levels, exclusion management, tamper protection, and automated response actions
  • Configure Windows Defender Antivirus, Attack Surface Reduction rules, and Controlled Folder Access via Intune or Group Policy; verify rule enforcement is active and correctly applied on all managed devices
  • Implement and maintain application control policies, USB device control configurations, and removable media restrictions across the managed endpoint estate in accordance with the Company’s Cybersecurity Policy
  • Apply and enforce CIS Benchmark or Microsoft Security Baseline hardening configurations on Windows Server and Windows 10/11 systems; verify compliance using configuration assessment tools
  • Configure and maintain email security gateway settings: SPF, DKIM, and DMARC enforcement, anti-spam policies, quarantine configuration, and inbound/outbound mail flow rules
  • Manage certificate lifecycle for all in-scope services: request, deploy, renew, and revoke SSL/TLS certificates for published services; maintain the internal CA and certificate inventory

SIEM Platform Configuration & Tuning

  • Build and maintain the SIEM platform (ManageEngine Log360 / Microsoft Sentinel or equivalent): configure log source connectors, define parsing rules.
  • Ensure complete and verified log ingestion from all critical sources: firewalls, domain controllers, Active Directory, Windows servers, endpoints, Microsoft 365, Entra ID, and network infrastructure devices; remediate any gaps in coverage
  • Vulnerability Management & Security Testing
  • Technically remediate confirmed vulnerabilities within defined SLA windows — apply patches, harden configurations, or implement compensating controls; verify remediation by re-scanning
  • Regularly review and assess the company's external attack surface — verify that only approved services are internet-facing, enumerate open ports, and close or restrict any identified exposure

Identity & Access Security

  • Configure and maintain API key and application credential expiry policies within Azure and connected platforms; verify rotation compliance is enforced at the platform level.
  • Technical Remediation Support During Incidents
  • On instruction from the Cybersecurity Officer, execute technical containment actions within security systems: isolate compromised endpoints in Microsoft Defender for Endpoint, block malicious IPs or domains in the firewall and DNS filtering platform, revoke active sessions and tokens in Entra ID
  • Disable or lock compromised user and service accounts in Active Directory and Entra ID; force credential resets and MFA re-registration for affected identities
  • Remove malicious rules, scheduled tasks, registry entries, or persistence mechanisms identified on compromised systems through EDR tooling

Requirements

Qualifications & Experience

  • Bachelor's degree in Information Security, Computer Science, or related technical field
  • Minimum 4 years of hands-on IT security engineering or security operations experience
  • Demonstrated, configuration-level expertise with at least one enterprise NGFW platform — Sophos XGS/SFOS, Fortinet FortiGate, Palo Alto PAN-OS, or equivalent; rule base management and VPN configuration experience required
  • Strong practical knowledge of Microsoft Azure and Microsoft 365 security configuration: Conditional Access, Entra ID Identity Protection, PIM, Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Purview, and Microsoft Sentinel
  • Hands-on SIEM experience: log source onboarding, correlation rule creation, alert tuning, and platform health management (ManageEngine Log360, Microsoft Sentinel, Splunk, or equivalent)
  • Strong working knowledge of network security: TCP/IP, VLANs, firewall rule logic, IPS/IDS, DNS security, TLS inspection, and VPN technologies (IPsec IKEv2, SSL VPN)
  • Experience implementing and verifying CIS Benchmark or Microsoft Security Baseline configurations on Windows Server and Windows 10/11
  • Hands-on experience with email security: SPF, DKIM, DMARC, anti-phishing policies, and mail flow security controls
  • CompTIA Security+, CEH, or CISSP is a strong advantage
  • Fluent in English and Greek language

Benefits

💰 Competitive salary, plus annual discretionary bonus performance related (taxed at just 10% under shipping-sector tax rules)

🏥 Coverage under the company's collective Life, Health & Dental insurance plan

🥗 Daily catered lunch — main dish and side salad provided on us, every day

☕ Healthy breakfast, snacks and beverages always stocked in the breakout area

🎉 Company-sponsored team-bonding events

🎂 A special birthday gift, because your day deserves to be celebrated

📈 Ongoing development opportunities to sharpen your skills and grow your career within Shipping

🚀 An entrepreneurial culture and genuinely interesting people to work with

Castor Ships S.A.

About Castor Ships S.A.

CASTOR SHIPS S.A. is a technical and commercial ship management company established in Greece in 2020 under law 27/75.

The mission of CASTOR SHIPS S.A. is to operate a continuously mixed growing fleet of Oil Tankers, LPGs, Bulk Carriers and Containers in the most effective, efficient and the safest way, serving the needs of our customers, protecting their interests and fulfilling their expectations, showing a commitment to continuous improvement on Safety and ESG matters.

Our vision is to become the leaders in our field through continuous development of business excellence and sustainability aspects, by treating the social concerns of the shipping industry in a responsible manner, embracing innovation and new technologies and promoting ethical business conduct.

Industry
Transportation & Logistics
Company Size
11-50 employees
Headquarters
Kifissia, GR
Year Founded
2020
Social Media