We are seeking a hands-on L2/L3 Cloud Security Engineer to handle day-to-day security operations, incidents, and changes across our multi-cloud estate (Azure, OCI, and GCP). This is an execution-focused engineering role: you will process identity and access requests, respond to and resolve security incidents and alerts, implement approved changes, and carry out routine operational tasks across Microsoft Entra ID, Microsoft Defender, Intune, Logic Apps automation, and certificate/key management (GCP PKI, Azure Key Vault). You will work as part of the operations team, picking up tickets and requests from the queue, troubleshooting issues, executing changes per approved change requests.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
Identity and Access Management (Entra ID / Azure)
- Privileged Identity Management (PIM): Process role-assignment and access-elevation requests, action time-bound privileged access approvals, and carry out scheduled access reviews across PIM-enabled groups.
- App Registrations: Create and manage app registrations and service principals — including credential/secret rotation, API permission scoping, and consent actions — per approved requests.
- Managed Identities: Provision system-assigned and user-assigned managed identities as requested by application and platform teams.
- Conditional Access and MFA: Implement and update Conditional Access policies and MFA settings per approved change requests; troubleshoot authentication and access issues raised by users or monitoring.
- SSO / Federation: Configure and troubleshoot single sign-on and federation for platform applications.
Security Automation
- Logic Apps Automation: Build, maintain, and troubleshoot Logic Apps security automations (IOC blocking, agent health checks, DNS change alerting), and respond to automation failures.
Cloud Security Operations
- Azure Policy: Apply and update Azure Policy assignments per approved baselines; identify and remediate non-compliant resources flagged by policy.
- Defender for Cloud: Monitor secure score and security recommendations daily; action remediation tasks and track resolution of flagged issues.
- Defender for Servers and Containers: Monitor and respond to threat alerts on server and container workloads, including AKS; investigate suspicious activity, process just-in-time (JIT) access requests, and apply secure configuration changes.
- Endpoint Security and Device Management: Perform day-to-day administration of Microsoft Defender for endpoints and Intune, including device onboarding, application and certificate deployment, and troubleshooting of device compliance issues.
PKI and Certificate Management
- Certificate Operations: Perform day-to-day operation of internal Certificate Authorities (CAs), including private CAs hosted in GCP.
- Certificate Lifecycle: Process certificate issuance, renewal, and revocation requests in line with existing PKI policy and standards.
- Key Management: Manage keys and secrets in Azure Key Vault, including rotation and access-policy updates per approved requests.
- Inventory and Monitoring: Maintain certificate and key inventory records and monitor for upcoming expiries or flagged misconfigurations.
Qualifications
- Education: Bachelor's / college degree in Computer Science, Information Technology, or a related field.
- Experience: 8-10 years of hands-on experience in cloud security operations (L2/L3), with demonstrable experience administering Microsoft Entra ID (RBAC, PIM, App Registrations, Managed Identities, Conditional Access), operating Microsoft Defender across cloud, server, container, and endpoint workloads, and handling PKI / certificate operations. Experience working within an incident and change management process (ITSM) is required. Multi-cloud experience across Azure, OCI, and/or GCP is a plus.
- Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Google Cloud Certified: Professional Cloud Security Engineer
- Vendor-agnostic security certifications (CISSP, CCSP, CSA CCSK, GIAC, etc.)
- Technical Skills: Strong hands-on experience with Microsoft Entra ID (App Registrations, Managed Identities, RBAC, PIM, Conditional Access, SSO/Federation), Azure Policy, Microsoft Defender for Cloud, Defender for Servers, Defender for Containers (including AKS security posture), Microsoft Intune, Logic Apps for security automation, Azure Key Vault, and GCP-based PKI / private Certificate Authorities. Working knowledge of Oracle Cloud Infrastructure (OCI) security controls.
- Knowledge: Working knowledge of identity and privileged access concepts, PKI fundamentals (certificate lifecycle, key management, trust chains), cloud workload protection, and ticket-driven incident/change processes. Ability to follow runbooks and standard operating procedures accurately under time pressure.