Job Summary
We are seeking a mid-level Security Engineer to develop, implement, and maintain robust security infrastructure protecting our corporate systems and data, with primary focus on Microsoft security ecosystems. You will architect and manage our Microsoft 365 environment, deploy advanced threat protection through Microsoft Defender, and secure our Azure cloud infrastructure. This role bridges infrastructure security and cloud security, requiring hands-on technical expertise and the ability to coordinate across engineering and security teams.
Key Accountabilities
Microsoft 365 & Defender Security Microsoft 365 & Defender Security
• Design and maintain Microsoft 365 security posture, including Exchange Online, Teams, and SharePoint protection
• Deploy, configure, and optimize Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Cloud
• Manage advanced threat protection policies, phishing prevention, and email filtering rules
• Conduct threat hunts and investigate security alerts from Defender ecosystem tools
• Implement conditional access policies and identity-driven security controls
Azure Cloud Security Azure Cloud Security
• Secure Azure infrastructure through network segmentation, NSGs, and Azure Firewall configuration
• Implement Azure-native security services (Azure Security Center, Key Vault, App Configuration)
• Conduct Azure resource audits and enforce compliance through Azure Policy
• Manage privileged access and identity governance in Azure AD/Entra ID
Infrastructure & Threat Management Infrastructure & Threat Management
• Deploy and configure firewalls, intrusion prevention systems, and web application firewalls
• Conduct vulnerability scans and coordinate patch management across infrastructure and cloud workloads
• Lead initial triage of security alerts and participate in active incident response operations
• Integrate security controls into CI/CD pipelines (container scanning, secret management, dependency checks)
Security Operations & Compliance Security Operations & Compliance
• Participate in security architecture reviews and recommend improvements
• Document security configurations and maintain runbooks for operational efficiency
• Support compliance audits and regulatory assessments (ISO 27001, SOC 2, industry-specific)
Knowledge, Skills and Aptitude
- Educational Qualifications and Certifications:
- University degree in CS/IT/IS/IMS or equivalent.
- Microsoft Azure Security Engineer Associate (AZ-500) — Required
- CompTIA CySA+, GIAC (GSEC/GCIA), or equivalent mid-level credential
- Knowledge:
- Strong knowledge of Microsoft security products: Defender suite, Entra ID, Azure security services
- Network security fundamentals: TCP/IP, firewalls, VPNs, intrusion detection
- Technical Skills:
- Scripting/automation: Python, PowerShell, Bash for security tooling and log analysis
- Language Skills:
- Fluency in both English and Arabic
- Experience:
- 2–3 years dedicated experience in cybersecurity, cloud security, or infrastructure engineering
- Demonstrated experience with Microsoft 365 administration and security (at least 1 year)
- Hands-on experience with Azure infrastructure and security services
- Experience with at least one SIEM tool
Key Interactions
- Key Internal Contacts: DSD Product Managers, Leadership.Operational Product Owners
- Purpose of Interaction: Align security strategy with business objectives and digital transformation initiatives.Ensure continuous alignment between security requirements and business operations
- Key External Contacts: Vendors & Suppliers.Government
- Purpose of Interaction: Evaluate, manage, and support security solutions, licensing, and vendor relationships.Ensure compliance with cybersecurity regulations and data protection laws
- Direct Reports: Security Specialist, Security Associates, System Administrators