Required Qualifications & Experience
• Minimum 3 years of hands-on experience in a SOC/NOC or security operations monitoring role.
• Direct exposure to Microsoft 365 security and compliance tooling.
• Microsoft certification required: SC-200 (Microsoft Certified: Security Operations Analyst Associate) and/or SC-400 (Microsoft Information Protection Administrator), or equivalent demonstrable expertise.
• Working knowledge of Microsoft Purview DLP policy structure, Microsoft Defender for Endpoint, Defender for Cloud Apps, and Defender for Office 365.
• Solid understanding of DLP concepts, insider-risk indicators, alert triage, and escalation methodology. • Strong documentation and reporting skills in English; Arabic is an advantage.
Nice to Have
• Additional Microsoft security certifications (e.g., SC-300, AZ-500).
• Experience with KQL / advanced hunting, SIEM platforms, or insider-risk programmes.