IT Manager - Workspace Security and Compliance
Inception42 · Abu Dhabi Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجIT Manager - Workspace Security and ComplianceDepartment: Information TechnologyReporting To: IT Senior ManagerLocation: Abu Dhabi - UAEJob SummaryThe IT Manager - Workspace Security and Compliance leads the team securing the digital workplace. The role owns Microsoft Intune, Microsoft Defender, Zscaler, Microsoft Purview, endpoint patching, security posture, compliance reporting, incident escalation, and vendor management, ensuring endpoints and Microsoft 365 services remain secure and auditable.Key ResponsibilitiesWorkspace Security Leadership & GovernanceLead the team, defining its operating model, roadmap, standards, priorities, performance objectives, and professional development.Translate business, cybersecurity, privacy, audit, and regulatory requirements into controls, baselines, policies, exceptions, and improvement plans.Endpoint Security, Intune & Microsoft Defender for EndpointGovern Intune enrollment, compliance, configuration, application protection, encryption, device control, local administrator, and Microsoft Defender Firewall policies across supported endpoint platforms.Own Defender for Endpoint onboarding, EDR, antivirus, attack surface reduction, web protection, vulnerability management, automated remediation, patch posture, threat intelligence, exceptions, and response.Microsoft Defender XDR & Microsoft 365 ProtectionGovern Defender XDR, Defender for Office 365, and Defender for Cloud Apps across Exchange Online, SharePoint, OneDrive, Teams, and sanctioned SaaS services, including phishing, malware, Safe Links, Safe Attachments, impersonation, quarantine, app governance, and investigation.Partner with NetSecOps, Cybersecurity and the SOC on signal correlation, containment, recovery, root-cause analysis, and permanent remediation for major workspace incidents.Zscaler Secure Access & Workspace ProtectionLead implementation and administration of Zscaler ZIA, ZPA, Client Connector, device posture, secure web access, threat protection, cloud application controls, SSL inspection, and exceptions.Own Client Connector deployment through Intune, monitoring, troubleshooting, and vendor escalation; coordinate traffic steering, PAC files, private application connectivity, and resilience with the Network and Security Architect.Microsoft Purview Information Protection & DLPGovern Purview Information Protection, including classification, sensitivity labels, encryption, label publishing, automatic labeling, and secure information handling.Implement and tune DLP across endpoints, Exchange, SharePoint, OneDrive, and Teams; manage alerts, incidents, overrides, exceptions, evidence, and false positives.Security Posture, Patching & ReportingGovern operating-system, Microsoft application, and approved third-party patching; track Secure Score, Defender exposure, compliance, drift, vulnerabilities, audit findings, and remediation SLAs.Build automated dashboards for compliance, patching, vulnerabilities, incidents, email security, Zscaler, Purview DLP, exceptions, and service levels using Power BI, KQL, Microsoft Graph, PowerShell, APIs, or equivalent tools.Security Operations, Service Management & VendorsEstablish monitoring, runbooks, change controls, incident and problem management, documentation, escalation paths, knowledge transfer, and service improvement.Serve as senior escalation point and manage Microsoft, Zscaler, partners, and managed services, covering support cases, licensing, SLAs, renewals, reviews, and corrective plans.Qualifications & ExperienceBachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related field.10+ years of experience in endpoint management, Microsoft 365 security, information protection, security operations, or technology compliance, including leadership responsibility.Deep hands-on expertise with Intune, Defender for Endpoint, Defender XDR, Defender for Office 365, security baselines, and enterprise device compliance.Strong experience administering Zscaler ZIA/ZPA and Client Connector, including device posture, user policies, secure access, threat protection, and troubleshooting.Strong experience with Purview Information Protection and DLP across endpoints and Microsoft 365, including policy design, tuning, incidents, exceptions, and audit evidence.Experience governing endpoint hardening, EDR, host firewall, encryption, vulnerability remediation, patching, monitoring, incident response, and compliance testing.Experience with Power BI, KQL, Microsoft Graph, PowerShell, Log Analytics, SIEM, APIs, ITIL operations, vendors, licensing, contracts, and SLA escalation.Professional CertificationsPreferred certifications include:Microsoft 365 Certified: Endpoint Administrator AssociateMicrosoft Certified: Security Operations Analyst AssociateMicrosoft Certified: Information Security Administrator AssociateMicrosoft Certified: Cybersecurity Architect Expert; Microsoft 365 Certified: Administrator ExpertZscaler Digital Transformation Administrator (ZDTA) or Zscaler Digital Transformation Engineer (ZDTE)CISSP, CISM, CCSP, ISO/IEC 27001 Lead Implementer or Lead Auditor, ITIL 4, or equivalentSkills & CompetenciesStrategic leadership, team development, accountability, and balance across security, compliance, operations, and user experience.Strong architecture judgement and technical depth across endpoint security, Microsoft 365 protection, secure access, data protection, monitoring, and compliance.Ability to convert risk, audit, privacy, regulatory, and business requirements into pragmatic policies, measurable controls, and sustainable processes.Calm incident leadership, structured problem solving, root-cause analysis, prioritization, and risk-based judgement.Executive communication and data-storytelling skills, clearly presenting posture, control gaps, incidents, options, and investment priorities.Strong stakeholder influence, collaboration, vendor negotiation, commercial awareness, documentation discipline, attention to detail, and continuous improvement.Key Performance Indicators (KPIs)Endpoint enrollment, Defender onboarding, encryption, firewall, security-baseline, and device-compliance coverage.Patch compliance, critical-vulnerability remediation within SLAs, zero-day response, and reduction of repeatedly non-compliant endpoints.Improvement in Secure Score and Defender exposure posture, including closure of control gaps, drift, audit findings, and exceptions.Defender incident containment and recovery, root-cause closure, recurrence reduction, and protection effectiveness across endpoint and Microsoft 365 services.Zscaler availability, Client Connector health, policy compliance, incident resolution, vendor SLAs, Purview label and DLP coverage, false-positive reduction, dashboard accuracy, and audit evidence quality.