Employment Type: Full-time
Location: Township, Lahore – Onsite
Working Hours: 6:00 PM – 3:00 AM PKT (aligned with US Central Time)
Function: Information Technology

The System & Network Security Engineer will be responsible for implementing, maintaining, and reviewing security controls across enterprise systems, endpoints, networks, and infrastructure platforms. This role focuses on endpoint security, firewall management, vulnerability assessments, patch compliance, credential security, infrastructure hardening, and email/web security. The engineer will collaborate closely with Infrastructure & Engineering, SOC, and NOC teams while maintaining clear boundaries of responsibility.

Key Responsibilities
- Administer and maintain security controls across systems, endpoints, networks, and infrastructure platforms.
- Manage Endpoint Detection and Response (EDR) and antimalware platforms, including policy enforcement, coverage monitoring, exclusions, agent health, and security configurations.
- Conduct vulnerability scanning, validate findings, and track remediation efforts through to closure.
- Monitor patch compliance across servers, endpoints, and relevant infrastructure components.
- Maintain security-hardening standards for Windows/Linux systems, endpoints, network devices, and firewalls.
- Identify security control gaps and coordinate remediation activities with Systems, Network, and Infrastructure teams.
- Validate remediation efforts and escalate any overdue critical or high-risk vulnerabilities.
- Review infrastructure changes for security requirements and configuration risks.
- Maintain technical security documentation, configuration standards, exception records, and audit evidence.

Vulnerability, Patch, and Security Assurance
- Perform scheduled vulnerability assessments, prioritizing findings based on severity, exploitability, exposure, and business impact.
- Track vulnerabilities against remediation timelines, then rescan and validate closure.
- Monitor patch compliance status and identify systems with missing or overdue security updates.
- Conduct periodic security configuration and hardening reviews.
- Support compliance with ISO 27001, HIPAA, and internal or external audit requirements within the assigned technical scope.

Endpoint, Network, and Access Security
- Maintain EDR and antimalware coverage across supported endpoints and servers, investigating any coverage or policy gaps.
- Review firewall rules, VPN security, and network segmentation to identify obsolete, excessive, or unnecessary access.
- Coordinate approved security changes with Systems and Network Engineering teams.
- Administer password vault and Privileged Access Management (PAM) controls, reviewing privileged or administrative access.
- Support credential rotation, emergency access, and break-glass controls.
- Apply least privilege and segregation of duties principles to privileged-access controls.

Email and Web Security
- Maintain and review anti-phishing, attachment protection, URL protection, web filtering, and DNS security controls where implemented.
- Investigate configuration gaps, coordinate corrective actions, and maintain approved security exceptions.

Role Interfaces and Boundaries
- Infrastructure & Engineering manages infrastructure architecture, systems and network operations, patch deployment, and implementation of approved changes.
- SOC handles SIEM, security monitoring, detection, and incident response.
- NOC is responsible for availability, performance monitoring, and operational alerting.
- The System & Network Security Engineer implements, reviews, and validates assigned infrastructure security controls and coordinates remediation with the responsible technical teams.

Required Qualifications and Experience
- Bachelor’s degree in Information Technology, Computer Science, Information Security, Engineering, or a related field; equivalent relevant experience may be considered.
- 4-5 years of experience in system, network, or infrastructure security.
- Hands-on experience with EDR, endpoint protection, enterprise firewalls, and vulnerability management tools.
- Proficiency with Windows Server, Active Directory, Windows endpoints, network security, and working knowledge of Linux security.
- Experience in vulnerability assessment, patch compliance, security hardening, and remediation tracking.
- Knowledge of firewall policies, VPN security, network segmentation, and privileged access management.
- Familiarity with password vault/PAM technologies and email/web security controls.
- Strong troubleshooting, documentation, and analytical skills.
- Understanding of least privilege, segregation of duties, and security-control evidence requirements.

Preferred Qualifications
- Experience working in healthcare, financial services, or other regulated environments.
- Familiarity with ISO 27001 and HIPAA security standards.
- Relevant certifications such as Security+, CySA+, Fortinet, Microsoft Security, Cisco Security, or equivalent are highly desirable.

Work Location: Onsite in Township, Lahore.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Bachelors
Career Level:
Mid-Level
Experience:
3 Years - 5 Years
Apply Before:
Oct 14, 2026
Posting Date:
Oct 08, 2026

Physicians Revenue Group, Inc.

· 11-50 employees - Lahore

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!