Apply Edge Start your job search

Information Security Engineer

GBM · Dubai, Dubai, United Arab Emirates

Apply & track with Apply Edge
Job Title: Information Security EngineerJob Area: DITJob Location: GBM Dubai HQJob Summary:The Information Security Engineer supports the organization's cybersecurity program through security monitoring, identity and access governance, Microsoft security technologies, data protection controls, vulnerability management, and compliance activities. The role assists in identifying security risks, reviewing technical security controls, maintaining security documentation, and supporting remediation, monitoring, and compliance activities under the direction of Information Security Management.Job Responsibilities:Monitor, investigate, and document cybersecurity alerts, events, and incidents using Microsoft Defender and other approved security tools.Administer and review Microsoft security technologies, including Microsoft Defender, Microsoft Entra ID.Review Conditional Access policies, Multi-Factor Authentication (MFA), administrative roles, Privileged Identity Management (PIM), and access-control configurations.Conduct periodic user access reviews across Microsoft 365, cloud services, SaaS applications, and business systems.Identify excessive, inappropriate, dormant, or unnecessary access privileges and report findings to Information Security management.Handle Microsoft Purview capabilities, including Data Loss Prevention (DLP), sensitivity labels, information protection, and data classification activities.Review endpoint security controls and Microsoft Defender configurations and document security observations and recommendations.Perform technical security reviews of applications, cloud services, and technology solutions and document identified risks and recommended controls.Review vulnerability assessment results, validate findings, support risk prioritization activities, and document remediation recommendations.Support governance, risk, compliance, audit, and ISO/IEC 27001 activities.Track cybersecurity findings, remediation activities, closure evidence, and supporting documentation.Escalate security incidents, vulnerabilities, compliance observations, and security concerns.Support security awareness initiatives and technical security projects.Qualifications & Education Requirements:Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline.Three to five years of experience in cybersecurity, information security, or a related security role.Experience in security monitoring, incident investigation, vulnerability management, access governance, audit activities, or compliance reviews.Hands-on experience with Microsoft Defender, Microsoft Entra ID, Microsoft Purview, Conditional Access, PIM, PAM, Identity Governance, and DLP.Good understanding of cybersecurity principles, endpoint protection, cloud security, and Microsoft security technologies.Ability to identify cybersecurity risks and review security controls from a technical perspective.Strong analytical, investigative, documentation, reporting, and problem-solving skills.Soft Skills:Analytical and problem-solving mindset.Strong attention to detail.Effective investigation and troubleshooting skills.Good written and verbal communication skills.Ability to manage multiple priorities and work independently.Ability to work collaboratively across teams.Core Competencies:Microsoft 365 SecurityMicrosoft Defender Suite (MDE, MDO, MDC, MDVM)Microsoft Entra IDIdentity GovernanceConditional AccessLeast PrivilegePrivileged Identity Management (PIM)Privileged Access Management (PAM)Access ReviewsDLP ( Microsoft Purview).Security Monitoring & Incident InvestigationCybersecurity Risk AssessmentISO 27001