About the Role
We are looking for a Cybersecurity professional to support the organisation’s internal cybersecurity across cloud, on-premise infrastructure, identity, networking, application/API security, cryptography, secrets management, vulnerability management, and DevSecOps. The role will work closely with Infrastructure, Cloud, Network, DevOps, and IT teams to identify security weaknesses, implement security controls, improve security configurations, and support remediation activities.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Support the definition of mitigation strategies and security improvements.
- Security Engineering: Support implementation, configuration, and improvement of cybersecurity controls across on-premise and cloud environments.
- Identity Security: Support Microsoft Entra ID and Active Directory, including MFA, Conditional Access, privileged access, and access reviews.
- Cloud Security: Support security assessments and hardening across Microsoft Azure and GCP, including identity, network security, logging, encryption, and secure configuration.
- Network Security: Support network segmentation, access controls, VPNs, and firewall security, including FortiGate.
- Vulnerability Management: Perform vulnerability scanning, analyse findings, prioritise risks, coordinate remediation, and validate fixes.
- Cryptography & Secrets Management: Support secure management of cryptographic keys, certificates, encryption, secrets, and credentials using platforms such as HashiCorp Vault, Azure Key Vault, and GCP Secret Manager.
- API Security: Support security assessments and controls for APIs, including authentication, authorisation, encryption, access controls, API gateways, and common API vulnerabilities.
- DevSecOps: Integrate security into CI/CD processes, including SAST, dependency scanning, secrets detection, container security, and IaC security.
- Terraform / IaC Security: Review and improve security controls within Terraform and infrastructure-as-code environments.
- Incident Response: Support security investigations, incident response, remediation, and lessons learned.
- Security Policies & Standards: Support development and implementation of cybersecurity policies, technical standards, hardening baselines, and security procedures.
- Security Assessments: Provide cybersecurity input into technology projects, architecture reviews, risk assessments, and audits.
- Automation & Continuous Improvement: Identify opportunities to automate security processes and continuously improve the organisation’s security posture.
Qualifications
- Qualifications & Experience:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience.
- 2-4 years of experience in cybersecurity, security engineering, cloud security, infrastructure security, or related technical roles.
- Practical understanding of cybersecurity, networking, identity and access management, cloud security, infrastructure security, cryptography, secrets management, and API security.
- Hands-on experience with several of the technologies listed below, with the ability and willingness to develop expertise across the broader technology environment.
- Strong analytical, problem-solving, and troubleshooting skills.
- Strong verbal and written English communication skills.
Technical Environment
Experience or exposure to:
- Microsoft Entra ID & Active Directory
- Microsoft Azure & Google Cloud Platform (GCP)
- HashiCorp Vault
- Azure Key Vault, GCP Secret Manager, or equivalent secrets management solutions
- Cryptography, PKI, certificates, encryption, and key management
- API security and API gateways
- Windows and Linux infrastructure
- Networking and network segmentation
- FortiGate or similar enterprise firewall technologies
- Vulnerability scanning and vulnerability management tools
- Terraform and Infrastructure as Code (IaC)
- DevSecOps and CI/CD security practices
- Security monitoring, incident response, and threat remediation
- Python, PowerShell, Bash, or similar scripting languages
Certifications (Desirable)
- CompTIA Security+ and/or CySA+
- Microsoft or Google Cloud Security Certifications
- Fortinet Certifications
- HashiCorp and/or Terraform Certifications
- Certified Cloud Security Professional (CCSP) and/or Certified Information Systems Security Professional (CISSP)
- GIAC Certifications