Nexon
Professional Services Engineer
January 2026 to present
- Manage hybrid-cloud environments spanning on-premises and cloud-hosted production servers; plan hybrid AD-to-cloud identity synchronisation, defining attribute scope and sync rules.
- Diagnose multi-layered connectivity failures across VPN, firewall and secure web gateway platforms through systematic log analysis, reconfiguring cloud Zero Trust access policies to restore secure client application access.
- Design and enforce compliance-driven security configurations, including data retention and litigation hold, aligned with regulatory audit and data-governance obligations.
- Diagnose and resolve endpoint web-protection blocks by analysing Windows Defender Exploit Guard logs and Cloud Discovery policy conflicts, implementing sanctioning exceptions in Defender for Cloud Apps.
- Track Endpoint Detection and Response alerts, perform risk assessments, and execute patching routines for server CVE vectors.
- Investigate and respond to security incidents involving compromised credentials, diagnosing broken secure-channel configurations and remediating legacy authentication vulnerabilities.
- End-to-end database provisioning and decommissioning across client environments, including configuration, access setup, and lifecycle compliance.
- Harden production access through authorised jumpboxes and manage RMM-escalated endpoint compliance alerts.
- Develop and maintain automation scripts to support identity lifecycle management, system health monitoring, and administrative efficiency across cloud services.
- Resolve enterprise email delivery failures across hybrid mail environments by analysing DNS SPF and DMARC records, mail routing paths and third-party gateway configurations.
- Configure NPS and RADIUS, VPN profiles, routing, ACLs and VLANs to client segmentation and compliance requirements; resolve multi-platform network faults via LogicMonitor, Meraki and Fortinet.
- Implement federated authentication (SAML 2.0 SSO), managing metadata configurations and token validation keys.