openqareer

Database Activity Monitoring (Guardium DAM) Engineer

Metazyber Technologies · Doha

# Database Activity Monitoring (Guardium DAM) Engineer **Metazyber Technologies** · Doha · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Job Summary: The Guardium DAM Engineer is responsible for the deployment, configuration, administration, and ongoing tuning of the organization’s IBM Security Guardium Database Activity Monitoring platform. This role serves as the primary technical owner of the Guardium environment within the Security Operations (SecOps) team, ensuring continuous, tamper-evident visibility into database activity, sensitive data access, and compliance posture across on-premise and cloud database estates. The Guardium DAM Engineer works closely with database administrators, SOC analysts, and audit/compliance teams to onboard database instances, build and tune monitoring policies, investigate anomalous activity, and produce the reporting required for regulatory and internal audit obligations. Tasks & Responsibilities : Functional Responsibilities : Platform Administration & Operations - Install, configure, and maintain the Guardium environment, including Collectors, Aggregators, and the Central Manager, across on-premise and cloud-hosted database estates. - Deploy, upgrade, and troubleshoot S-TAP agents on database servers, including STAP failover (K-TAP/Z-TAP where applicable) and agent health monitoring. - Manage Guardium licensing, appliance sizing, and storage/archival configuration in line with data retention requirements. - Perform routine health checks, patching, and version upgrades across the Guardium appliance stack to maintain system stability and security. - Configure high availability and failover between Collectors and Aggregators, and validate backup/restore procedures for Guardium configuration and audit data. - Monitor platform performance metrics such as buffer usage, queue depth, and appliance resource utilization, and implement tuning measures proactively. Data Source Onboarding & Policy Configuration: - Onboard new database instances (Oracle, Microsoft SQL Server, MySQL, PostgreSQL, DB2, MongoDB, and cloud-managed databases such as AWS RDS/Aurora and Azure SQL) into Guardium monitoring. - Build and maintain Guardium groups, policies, and rules to monitor privileged user activity, sensitive data access, and schema/DDL changes. - Run and tune sensitive data discovery and classification scans to keep data-at-risk inventories current. - Validate data collection completeness and accuracy — monitoring for gaps, dropped traffic, and misconfigured inspection engines. - Coordinate with DBAs to ensure Guardium policies reflect actual database change control and access management processes. Monitoring, Alerting & Compliance Reporting - Build and maintain compliance workflows and reports (e.g., PCI-DSS, SOX, GDPR, local regulatory requirements) using Guardium’s audit and reporting capabilities. - Configure real-time alerts and policy violations for privileged access misuse, data exfiltration patterns, and out-of-policy database activity. - Maintain sign-off workflows for compliance reports and ensure audit evidence is retained per organizational policy. - Develop and maintain dashboards and reports for SOC analysts, DBAs, auditors, and executive stakeholders. Threat Detection & Incident Response - Investigate anomalous database activity and outlier detection alerts, and escalate confirmed incidents per SOC incident response procedures. - Integrate Guardium alerts and audit data with the organization’s SIEM (Splunk) and SOAR platforms to support correlation and automated response. - Support forensic investigations by producing detailed database activity audit trails on request. - Collaborate with the threat intelligence and SOC teams to align Guardium detection logic with known attack patterns targeting database tiers. Access Control & Security Management - Administer Role-Based Access Control (RBAC) within Guardium, ensuring DBAs, auditors, and SOC staff have appropriate data and capability access. - Manage Guardium authentication integrations, including LDAP/AD and multi- factor authentication (MFA) where applicable. - Enforce segregation of duties between database administration and database activity monitoring, consistent with audit requirements. - Conduct periodic access reviews and ensure Guardium configurations align with organizational security policies. Collaboration with DBAs, SOC & Compliance Teams - Partner with DBA teams to understand new database deployments and ensure timely onboarding into Guardium. - Provide training and knowledge transfer sessions on Guardium reporting and policy workflows to SOC analysts and auditors. - Coordinate with infrastructure and cloud teams to ensure database traffic is correctly routed for Guardium inspection. - Act as the primary escalation point for Guardium platform issues impacting compliance reporting or SOC operations. Academic & Professional Qualifications : - Bachelor’s degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent. - IBM Certified Deployment Professional – Security Guardium (required). - IBM Certified Administrator – Security Guardium (preferred). - Database platform certification (Oracle, Microsoft SQL Server, or equivalent) is an advantage. - Preferred security certifications: CompTIA Security+, CySA+, CEH, or CISSP. Experience : - 3–5 years of hands-on experience administering IBM Guardium or an equivalent Database Activity Monitoring / database security platform. - Prior experience in database administration, SIEM engineering, or Security Operations is highly valued. Technical Skills (Must Have) - Guardium Platform Mastery: Advanced proficiency administering Guardium Collectors, Aggregators, and the Central Manager, including S-TAP deployment and troubleshooting. - Policy & Group Management: Hands-on experience building and tuning Guardium groups, policies, and rules for privileged access monitoring and sensitive data protection. - Database Expertise: Working knowledge of major database platforms (Oracle, SQL Server, MySQL, PostgreSQL, DB2, MongoDB) and their native audit/logging mechanisms. - SQL Proficiency: Ability to read and interpret SQL statements to assess policy violations and investigate suspicious database activity. - Compliance Reporting: Experience building and maintaining compliance workflows (PCI-DSS, SOX, GDPR, or equivalent) within Guardium. - Scripting: Proficiency in Python and/or Bash for automation, custom reporting, and API integrations with Guardium’s REST API. - SIEM Integration: Experience integrating Guardium alerts and audit logs with Splunk or an equivalent SIEM for correlation and alerting. - Cloud Database Platforms: Exposure to monitoring cloud-managed databases such as AWS RDS/Aurora, Azure SQL, or GCP Cloud SQL is an advantage. - Networking & Security Fundamentals: Solid understanding of TCP/IP, network segmentation, and encryption in transit as they relate to database traffic inspection. - Frameworks: Working knowledge of data protection regulations and control frameworks relevant to the organization’s industry. Soft Skills - Strong analytical and structured problem-solving capability with attention to detail. - Excellent communication skills — able to present technical and compliance findings clearly to both technical and non-technical audiences, including auditors. - Ability to prioritize and manage multiple tasks simultaneously in a fast-paced SecOps environment. - Collaborative mindset with a documentation-driven approach to platform changes and runbook development. 5. Communications and Working Relationships : Internal: - Database Administration (DBA) Team - Service Operations - Service Design - Information Governance Security - SOC - Security Infrastructure Engineer External: - Clients - Vendors - Partners - External Auditors Health, Security, Safety and Environment Ensure compliance with all relevant health, security, safety and environmental management policies, procedures and controls within own area, monitoring, reviewing, and evaluating on a continuous basis, to guarantee employee safety, legislative compliance, delivery of high-quality service and a responsible environmental attitude Application Question(s): - Do you have prior experience in database administration, SIEM engineering, or Security Operations ? - Do you have working knowledge of major database platforms (Oracle, SQL Server, MySQL, PostgreSQL, DB2, MongoDB) and their native audit/logging mechanisms? - Do you have experience integrating Guardium alerts and audit logs with Splunk or an equivalent SIEM for correlation and alerting? - What is you salary expectation and notice period to join? Experience: - administering IBM Guardium or an equivalent DAM: 3 years (Preferred) Work Location: In person

Наблюдалась 2026-10-07, впервые 2026-10-05, источник — Indeed.

Открыть у работодателя