Cybersecurity / IT Security Engineer
nSearch Global · Dubai, Dubai, United Arab Emirates
Apply & track with Apply EdgeResponsibilities:Provide security consultancy and technical advisory across Identity & Access Management (IAM), Cloud Security, Data Security and Application Security throughout the system and application lifecycle.Assess security risks, vulnerabilities and control gaps across applications, cloud platforms, infrastructure, identities and data environments, and recommend appropriate remediation and mitigation measures.Design, implement, review and maintain security controls including access management, authentication, privileged access, security configurations, encryption, data protection and application security controls.Support IAM initiatives including user access management, role-based access control (RBAC), privileged access management (PAM), identity governance, access reviews and authentication controls.Perform cloud security reviews and configuration assessments across AWS and/or Microsoft Azure, including identity, network, workload, storage, logging and security posture management.Assess and implement appropriate data security and data protection controls, including data classification, encryption, access controls, secure data handling and prevention of unauthorised data exposure.Conduct application security assessments covering secure design, vulnerability assessment, configuration review, penetration testing and common application vulnerabilitiesSupport the implementation of security requirements within DevSecOps and CI/CD environments, including security testing, vulnerability scanning and integration of security controls into development processes.Lead or participate in threat and risk assessments, vulnerability assessments, security reviews and penetration testing activities, including validation of findings, severity assessment, root-cause analysis and remediation recommendations.Perform security operational activities including security configuration, patching, upgrades, monitoring and maintenance of enterprise security platforms and infrastructure.Analyse security findings and vulnerability trends, identify recurring risks and recommend improvements to strengthen the organisation's overall security posture.Develop scripts, automation and workflow improvements, where applicable, to improve security operations, assessments, reporting and integration between security platforms.Work closely with application teams, infrastructure teams, cloud teams, system owners and other stakeholders to remediate identified security risks and ensure security requirements are appropriately implemented.Requirements:Degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related, security certifications such as CISSP, CISA, GSEC, OSCP, CCSP or equivalent would be advantageous.Good knowledge and practical experience in one or more areas of IAM, Cloud Security, Data Security and Application Security.Experience with IAM concepts and technologies including authentication, authorisation, RBAC, PAM, identity governance and access management.Experience with cloud security technologies, tools and security configuration within AWS and/or Microsoft Azure environments.Knowledge of data security principles including encryption, access control, data classification, data loss prevention and secure data handling.Familiarity with application and web security vulnerabilities, including OWASP Top 10, vulnerability categorisation, severity assessment, root-cause analysis and remediation.Experience with vulnerability assessment, penetration testing, security configuration review and security risk assessment in enterprise environments.Familiarity with DevSecOps methodologies, CI/CD security practices and security toolsets.Good understanding of information security standards and frameworks including ISO 27001 and NIST Cybersecurity Framework.Experience working in Agile environments and with collaboration/documentation tools such as Jira and Confluence would be advantageous.