We are hiring for our leading client in Abu Dhabi and are looking for an experienced Senior Cybersecurity Specialist with 10+ years of hands-on cybersecurity experience.
The ideal candidate will have strong practical expertise across the Microsoft Security ecosystem, Microsoft Sentinel, Wazuh, SIEM/SOC operations, threat detection, Active Directory security, network and web security, security automation, and ISO 27001.
This is a highly hands-on, engineering-oriented role focused on designing, operating, optimizing, and automating enterprise security controls.
Key Responsibilities:
- Lead cybersecurity operations, threat detection, incident response, threat hunting, and security posture improvement initiatives.
- Manage and optimize Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud, Defender for Office 365, and related Microsoft security solutions.
- Administer and enhance Microsoft Sentinel, including analytics rules, KQL queries, workbooks, playbooks, threat hunting, and incident workflows.
- Deploy, manage, tune, and monitor Wazuh for endpoint monitoring, log analysis, compliance, and threat detection.
- Develop detection logic and response processes aligned with the MITRE ATT&CK framework.
- Conduct security investigations, root cause analysis, threat hunting, and post-incident reporting.
- Assess and improve web application security, including OWASP Top 10, WAF configuration, secure configurations, and vulnerability remediation.
- Strengthen Active Directory security, including identity protection, privilege management, hardening, monitoring, and attack-path reduction.
- Review and improve network security controls, including firewalls, IDS/IPS, segmentation, VPN, secure remote access, and network monitoring.
- Develop security automation using PowerShell, Python, KQL, APIs, Logic Apps, n8n, and other workflow/automation platforms.
- Automate alert triage, enrichment, notification, ticketing, containment, and security reporting processes.
- Support ISO 27001 / ISMS activities, including risk assessments, control reviews, internal audits, evidence collection, gap assessments, corrective actions, and continuous improvement.
- Collaborate with IT, infrastructure, cloud, network, and application teams to embed security into enterprise systems and processes.
- Support vulnerability management, security assessments, remediation tracking, documentation, runbooks, and security playbooks.
Required Skills & Experience:
- 10+ years of professional cybersecurity experience.
- Strong hands-on experience with the Microsoft Defender security suite.
- Strong experience with Microsoft Sentinel covering SIEM, SOAR, threat hunting, analytics, and incident response.
- Hands-on experience with Wazuh deployment, configuration, tuning, monitoring, and reporting.
- Strong practical understanding of MITRE ATT&CK and detection engineering.
- Strong knowledge of web application security, OWASP Top 10, WAF, and vulnerability remediation.
- Strong knowledge of Active Directory security, identity attacks, privilege escalation, lateral movement, hardening, and monitoring.
- Strong knowledge of network security, including firewalls, segmentation, VPN, IDS/IPS, secure protocols, and traffic analysis.
- Working knowledge of ISO 27001, ISMS, risk management, security controls, and audit requirements.
- Experience supporting ISO 27001 audits, control implementation, gap assessments, evidence collection, and remediation.
- Practical experience with security automation and scripting using PowerShell, Python, KQL, Logic Apps, n8n, APIs, or similar technologies.
- Strong understanding of enterprise security architecture, security operations, incident investigation, and risk management.
Preferred Skills:
- Experience with n8n and security workflow automation.
- Experience with AI-assisted / AI-driven development approaches for security tools and automation.
- Microsoft Azure security experience.
- Advanced KQL development, detection rules, alert logic, dashboards, and workbooks.
- Experience integrating SIEM/SOAR platforms with ticketing systems, messaging platforms, threat intelligence, and endpoint security solutions.
- Knowledge of security frameworks, baselines, compliance requirements, and control maturity assessments.
- Ability to map technical controls and evidence to ISO 27001 requirements.
- Strong communication, documentation, analytical, and stakeholder management skills.
Preferred Certifications:
- CISSP
- CISM
- ISO 27001 Lead Auditor / Lead Implementer
- CEH
- SANS GIAC certifications
- Microsoft SC-200
- Microsoft AZ-500
- Microsoft SC-100