Company logo hidden

F5/CloudFlare/LB/GTM- Network_Security_Engineer

Unlock employer Doha, Qatar Direct to Company Under an hour ago · 04 Oct 2026

Financial

  • Estimate: $40k - $75k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

About the Role
The L2 Cloud Security Engineer will support day-to-day security operations across our multi-cloud estate (Azure, OCI, and GCP). This is a hands-on, ticket-driven engineering role: you will action identity and access requests, triage and resolve security alerts, implement standard and pre-approved changes, and perform routine operational tasks across Microsoft Entra ID, Microsoft Defender, Intune, Logic Apps automation, and certificate/key management (GCP PKI, Azure Key Vault). You will work within the operations team, picking up tickets from the queue, following runbooks and standard operating procedures, troubleshooting and resolving issues within agreed SLAs, and escalating complex or high-severity matters to the L3 Technical Lead with clear, well-documented findings.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Responsibilities

Identity and Access Management (Entra ID / Azure)

  • Privileged Identity Management (PIM): Process standard role-assignment and access-elevation requests, validate approvals before actioning, and support scheduled access reviews by collecting evidence and following up on outstanding reviewers.
  • App Registrations: Create app registrations and service principals per approved requests, rotate expiring secrets and certificates, and apply API permissions as specified in the request.
  • Managed Identities: Provision system-assigned and user-assigned managed identities and assign the requested RBAC roles for application and platform teams.
  • Conditional Access and MFA: Troubleshoot sign-in and MFA issues using sign-in logs, apply pre-approved Conditional Access changes, and manage user and group exclusions per change requests.
  • SSO / Federation: Support onboarding of applications to SSO using established templates and troubleshoot common federation and SAML/OIDC issues, escalating non-standard integrations.

Security Automation

  • Logic Apps Automation: Monitor existing Logic Apps security automations (IOC blocking, agent health checks, DNS change alerting), investigate failed runs, perform first-line fixes, and make minor updates under guidance.

Cloud Security Operations

  • Alert Triage and Incident Response: Triage security alerts and incidents from the queue, perform initial investigation and containment per playbooks, and escalate confirmed or high-severity incidents to L3 with documented evidence.
  • Azure Policy: Identify and remediate non-compliant resources flagged by Azure Policy, and apply policy assignments and exemptions per approved change requests.
  • Defender for Cloud: Review secure score and security recommendations daily, raise and track remediation tasks with resource owners, and report progress against agreed targets.
  • Defender for Servers and Containers: Monitor threat alerts on server and container workloads (including AKS), perform initial investigation, and process just-in-time (JIT) VM access requests.
  • Endpoint Security and Device Management: Perform routine administration of Microsoft Defender for Endpoint and Intune, including device onboarding, compliance troubleshooting, and application and certificate profile deployment.

PKI and Certificate Management

  • Certificate Lifecycle: Process certificate issuance, renewal, and revocation requests against internal CAs (including private CAs hosted in GCP) in line with existing PKI policy and standards.
  • Key Management: Manage keys and secrets in Azure Key Vault, including scheduled rotation and access-policy or RBAC updates per approved requests.
  • Inventory and Monitoring: Maintain certificate and key inventory records, monitor upcoming expiries, and raise renewal tickets well ahead of expiry dates.

Operations and Documentation

  • ITSM and Change Management: Work tickets within SLA, keep ticket notes accurate and complete, and raise standard change requests with implementation and rollback steps.
  • Runbooks and Knowledge Base: Follow and help maintain runbooks and SOPs, and document resolutions so recurring issues can be handled consistently.
  • Shift and On-call Support: Participate in shift handovers and an on-call rotation as required, ensuring open items are clearly communicated.

Qualifications

  • Education: Bachelor's / college degree in Computer Science, Information Technology, or a related field.
  • Experience: 4-6 years of IT experience, including at least 2-3 years of hands-on cloud security or cloud operations work at L2 level. Practical experience administering Microsoft Entra ID (RBAC, PIM, App Registrations, Conditional Access) and operating Microsoft Defender products is required. Experience working tickets within an incident and change management process (ITSM) is required. Exposure to GCP or OCI is a plus.
  • Certifications: Relevant professional certifications are desirable. These may include, but are not limited to:
    • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
    • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
    • Microsoft Certified: Security Operations Analyst Associate (SC-200)
    • Microsoft Certified: Azure Administrator Associate (AZ-104)
    • Microsoft Certified: Endpoint Administrator Associate (MD-102)
    • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
    • Google Cloud Certified: Associate Cloud Engineer
    • Vendor-agnostic certifications (CompTIA Security+, CCSK, etc.)
  • Technical Skills: Hands-on experience with Microsoft Entra ID, Azure RBAC, Azure Policy, Microsoft Defender for Cloud, Defender for Servers and Endpoint, Microsoft Intune, and Azure Key Vault. Familiarity with Logic Apps, Defender for Containers / AKS, and GCP Certificate Authority Service. Basic scripting ability (PowerShell, Azure CLI, or KQL) for investigation and routine tasks.
  • Knowledge: Solid understanding of identity and access concepts, PKI fundamentals (certificate lifecycle, key management, trust chains), and common cloud security threats. Ability to follow runbooks accurately, prioritise a ticket queue, and know when and how to escalate.
  • Soft Skills: Clear written and verbal communication, strong attention to detail in ticket documentation, and the ability to work effectively in a team and under time pressure.
Apply Direct

Jobs you might like   View all jobs

About IT Services and IT Consulting Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct