Lead Security Engineer – Cloud, SaaS & DevSecOps
IFZA Dubai · Dubai, United Arab Emirates
Apply & track with Apply EdgeRole:In this role you will own the security posture of SaaS platforms (including Zoho), Azure cloud infrastructure, and software delivery pipelines.This role sits at the intersection of cloud security architecture, application security, secure software delivery, and enterprise SaaS governance - making it a unique opportunity for engineers who thrive across multiple security domains.You will be responsible for embedding security into every layer of our technology stack: from Azure workloads and CI/CD pipelines to Zoho application configurations and third-party SaaS integrations. You will work closely with DevOps, IT, and Engineering teams to ensure security is shared, continuous practice rather than a checkpoint.Key Responsibilities:Cloud Security (Azure)Design, implement, and maintain security controls across Azure environments - Virtual Networks, Network Security Groups (NSGs), Private Endpoints, and Azure FirewallOwn outbound/inbound network security posture, including Azure Firewall policy design, FQDN allow-listing, and egress controlMonitor cloud infrastructure for misconfigurations, threats, and compliance violations using Microsoft Defender for CloudConduct cloud risk assessments and maintain cloud security architecture documentationImplement DDoS protection and WAF policies (Azure Front Door / Application Gateway)Application SecurityPerform application security reviews across web applications and APIs - authentication/authorization flaws, business logic issues, injection, SSRF, and OWASP Top 10 categoriesConduct threat modeling and secure design review for new features and architecture changesDefine and enforce secure coding standards and developer security guidelinesReview API and microservice designs for authentication, input validation, and data exposure risksSecure Software Delivery (DevSecOps)Integrate security scanning into CI/CD pipelines (SAST, DAST, SCA, secrets detection)Implement and manage container security controls for Azure Container Apps (image scanning, registry security, runtime configuration)Automate security testing and compliance checks across deployment workflowsManage vulnerability remediation workflows in collaboration with development teamsConduct security risk assessments across software delivery pipelines, code repositories, and deployment environments to identify, prioritize, and remediate risks before they reach productionZoho & SaaS Platform SecurityOwn security configuration and governance of Zoho One (CRM, Desk, People, Books, Cliq, One)Manage Zoho user access controls, role-based permissions, and data sharing policiesMonitor Zoho audit logs and investigate suspicious activity or data access anomaliesConfigure Zoho security policies including MFA enforcement, IP restrictions, and session controlsAssess third-party Zoho integrations, extensions, and webhook endpoints for security and data privacy risksMaintain SaaS security inventory and conduct periodic access reviews across all platformsEvaluate and onboard new SaaS tools through a security review processSecurity Operations & GovernanceOperate and tune SIEM platform for cloud and SaaS log ingestion, alerting, and incident responseLead security incident response for cloud, pipeline, and SaaS-related eventsDevelop and maintain security policies, runbooks, and compliance documentationConduct regular vulnerability assessments and penetration testing coordinationSkills & Experience required:8+ years of hands-on experience in cloud security, application security, or information securityProven experience securing production environments on Azure (VNets, NSGs, Private Endpoints, Azure Firewall, Entra ID)Hands-on experience performing application security assessments (manual + tool-assisted)Hands-on experience integrating security tools into CI/CD pipelinesExperience administering and securing Zoho or equivalent enterprise SaaS platformsDemonstrated experience with SIEM platforms, log analysis, and incident responseKey Technical SkillsCloud platform: Azure security services (Defender for Cloud, Azure Firewall, Front Door/Application Gateway, Key Vault)Application security: OWASP Top 10, Burp Suite, API security testing, secure code reviewDevSecOps tooling: GitHub Actions, Jenkins, or GitLab CI; SonarQube, Snyk, Trivy, CheckovContainer security: Docker image scanning; experience securing serverless/managed container platforms (e.g., Azure Container Apps)SIEM & monitoring: Microsoft Sentinel or equivalentScripting & automation: Python, Bash, PowerShell, or TerraformSecurity frameworks: OWASP, NIST, CIS Benchmarks, Zero TrustZoho administration: security configuration across Zoho One suiteIdentity & access: SSO, SAML, OAuth, MFA, PAM toolsPreferred qualifications:Certifications: AZ-500, CCSP, or equivalentExperience with Zoho Creator, Zoho Analytics, or custom Zoho integrations securityFamiliarity with Kubernetes/AKS security (if organization later adopts it)Exposure to compliance frameworks: ISO 27001, SOC 2 Type II, GDPR, HIPAA, PCI-DSSBackground in red team / penetration testing or bug bounty participationExperience with infrastructure-as-code security scanning (Terraform)