Title: Cloud & Network Engineer
Company Name: NECX. Inc
Vacancy: 1
Age: At least 25 years
Job Location: Dhaka (DOHS Baridhara)
Salary: Tk. 55000 - 60000 (Monthly)
Experience:
Cisco Certified Network Associate (CCNA) (optional)
Azure Network Engineer Associate (AZ-700) (optional)
CompTIA Security+ (optional)
About NECX
NECX protects people when they are at their most vulnerable. We build the technology that victim services agencies, government bodies, and advocates rely on to coordinate care, manage cases, and deliver support to survivors of crime across multiple countries and jurisdictions.
Our platform sits at the intersection of criminal justice, healthcare, and social services. The data we handle is governed by CJIS, HIPAA, HMIS, and GDPR. A single misconfiguration could expose the identity of a domestic violence survivor or compromise a criminal investigation. That is the weight of this role, and that is why we are selective about who fills it.
We are growing. New jurisdictions, new compliance requirements, new integrations. The security function needs an owner, not a consultant, not a part-timer. Someone who wakes up thinking about attack surfaces and goes to bed reviewing access logs. If that sounds like you, keep reading.
Why this role matters
Most security roles are about protecting revenue. This one is about protecting people. Survivors. Witnesses. Families in crisis. The data you secure is not shopping carts and ad clicks. It is case files, medical records, and location histories of people whose safety depends on your work.
You will not be buried in a 200-person IT department waiting for tickets. You will sit with the engineering team, influence architecture decisions, and see your recommendations go live in days, not quarters.
NECX is expanding internationally. New compliance requirements, new threat models, new infrastructure decisions. If you want a role where the problems keep getting harder and more interesting, this is it.
What you will own
Take full ownership of NECX's Azure cloud security architecture. Virtual networks, NSGs, Azure Firewall, Key Vault, Entra ID. This is your domain.
Architect and enforce zero trust policies, network segmentation, and least privilege access across development, staging, and production. No shortcuts, no exceptions.
Deploy and operate Azure Security Center, Microsoft Defender for Cloud, and Microsoft Sentinel as our threat detection and incident response backbone.
Run vulnerability assessments, coordinate penetration tests, and lead security audits. Find the gaps before someone else does.
Build compliance frameworks that actually hold up under audit for CJIS, HIPAA, HMIS, GDPR, and whatever new standard the next jurisdiction demands.
Write security policies, incident response playbooks, and disaster recovery plans that your colleagues will follow. Clear language, real procedures, zero fluff.
Embed security into the development lifecycle. Container scanning, secret management, dependency audits, CI/CD pipeline hardening. Shift left and stay there.
Own VPN, WAF, DDoS protection, and TLS certificate management. Keep the perimeter tight and the traffic clean.
Secure Azure Blob Storage, enforce encryption at rest and in transit, and maintain backup strategies that work when everything else fails.
When an incident happens, you lead. Investigate, contain, remediate, document, and make sure it does not happen again.
Track emerging threats, new CVEs, and evolving compliance landscapes. Filter the noise and brief the team on what actually requires action.
Balance robust security with cloud economics (FinOps). Lead Azure cost optimization initiatives, right-size compute resources, enforce budget alerts, and manage reserved instances without compromising our security posture.
Manage and harden Virtual Private Servers (VPS). Oversee the secure provisioning, lifecycle management, strict access control, and patch cadence for standalone Linux and Windows servers.
Drive Cloud Security Posture Management (CSPM). Continuously monitor the Azure environment to detect and auto-remediate misconfigurations before they can be exploited.
What we expect you to bring
3 to 4 years of proven, hands-on cloud security experience with deep Azure expertise. We will ask you to prove it.
Operational fluency with Azure Virtual Networks, NSGs, Azure Firewall, Key Vault, Entra ID (Azure AD), Security Center, Defender for Cloud, and Sentinel.
Proven experience in Azure cost optimization, including hands-on work with Azure Cost Management, Azure Advisor, rightsizing workloads, and navigating Reserved Instances.
Strong VPS management and server administration skills, including secure OS baselining, SSH key management, and automated patching pipelines.
Strong network security fundamentals: TCP/IP, DNS, VPN, firewalls, IDS/IPS, proxies, load balancers. You should be able to troubleshoot at packet level if needed.
Direct experience building or maintaining compliance programs for at least two of: CJIS, HIPAA, HMIS, GDPR. We do not need someone learning these on the job.
Working knowledge of security frameworks such as NIST CSF, ISO 27001, or CIS Controls.
Hands-on experience with infrastructure-as-code (Terraform, ARM templates, or Bicep) for automated security provisioning.
Scripting proficiency in PowerShell, Bash, or Python for security automation and custom tooling.
Understanding of container security (Docker, Kubernetes) and how to harden CI/CD pipelines end to end.
Even better if you have
Azure security certifications: AZ-500 (Security Engineer Associate) or SC-100 (Cybersecurity Architect Expert). These move you to the front of the line.
SOC 2 Type II audit experience or FedRAMP familiarity.
Background in securing Node.js/Express backends and PostgreSQL databases. That is our stack.
FinOps certification or a proven track record of reducing cloud infrastructure burn rates while scaling.
Experience writing SIEM detection rules and building automated incident response workflows.
Prior work in victim services, law enforcement technology, or government-adjacent platforms. You will understand the stakes faster.
Knowledge of data residency and sovereignty requirements across US, EU, and South Asian jurisdictions, and other continents.