Cyber Security Specialist

جامعة حمدان بن محمد الذكية

Dubai

On-site

AED 180,000 - 240,000

Full time

30 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hamdan bin Mohammed Smart University is seeking a hands-on Cybersecurity Specialist with strong experience in penetration testing, security monitoring, vulnerability management, and governance. You will work across enterprise infrastructure, cloud environments, Active Directory, and web applications to strengthen security controls.

You will conduct tests, monitor events, tune SIEM alerts, review Azure and AWS security, and collaborate with IT teams to drive risk-based remediation and compliance.

Qualifications

  • Hands-on cybersecurity experience implementing security controls in enterprise environments.
  • Penetration testing and vulnerability assessment experience.
  • Strong knowledge of web apps, APIs, networks, OS and enterprise security.
  • Experience with Burp Suite, Nmap, Metasploit or equivalent tools.
  • Experience with SIEM and security monitoring platforms (Wazuh, Microsoft Sentinel, Splunk).
  • Experience with Microsoft Azure and AWS cloud security.
  • Knowledge of Windows, Linux, TCP/IP networking and authentication.
  • Understanding of governance, risk management, policies, standards and compliance.
  • Active Directory/Entra ID security knowledge including privileged accounts and GPO.
  • UAE government/regulatory experience desirable.

Responsibilities

  • Conduct penetration testing and security assessments of web apps, APIs, networks, servers, and AD environments.
  • Identify vulnerabilities, assess risk, and provide remediation recommendations.
  • Perform manual testing including OWASP Top 10 and OWASP API Security Top 10.
  • Monitor security events and alerts through SIEM platforms.
  • Support security incident investigation, containment, remediation and post-incident improvements.
  • Develop and tune SIEM alerts, detection rules, dashboards and monitoring use cases.
  • Support vulnerability management and remediation with infra and development teams.
  • Review security of Azure and AWS environments and implement identity, logging and network controls.
  • Strengthen Active Directory/Entra ID security and privileged access controls.
  • Collaborate with IT teams to improve overall security posture and governance.

Skills

Penetration testing
Vulnerability assessment
Security monitoring
Security governance
Azure security
AWS security
Active Directory security
Windows/Linux security
Incident investigation
Automation scripting
Web/API security

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering
OSCP/OSWE/OSEP
Hack The Box CPTS/CWES/CBBH/CDSA/CWEE/CAPE/COAE
Cloud security certifications

Tools

Burp Suite
Nmap
Metasploit
Wazuh
Microsoft Sentinel
Splunk

Job description

Job Purpose

We are seeking a hands-on Cybersecurity Specialist with strong experience in penetration testing, security monitoring, vulnerability management, and cybersecurity governance. The ideal candidate should have a strong security background while also being comfortable working with enterprise infrastructure, SIEM platforms, cloud environments, servers, Active Directory, and web applications.

Key Responsibilities
  • Conduct penetration testing and security assessments of web applications, APIs, networks, servers, Active Directory environments, and other enterprise systems.
  • Identify vulnerabilities, assess their risk and exploitability, and provide practical remediation recommendations.
  • Perform manual penetration testing, including assessments against OWASP Top 10 and OWASP API Security Top 10 risks.
  • Monitor and investigate security events and alerts through SIEM and security monitoring platforms.
  • Support security incident investigation, response, containment, remediation, and post-incident improvement activities.
  • Develop and tune SIEM alerts, detection rules, dashboards, and monitoring use cases.
  • Support vulnerability management and coordinate remediation activities with infrastructure and development teams.
  • Review the security of Microsoft Azure and AWS environments.
  • Review Microsoft Azure and AWS environments and support the implementation of appropriate identity, network, logging, workload, and configuration security controls.
  • Review and strengthen Microsoft Active Directory and Entra ID security, including privileged access, service accounts, authentication controls, Group Policy, and identity-related risks.
  • Support the implementation and operation of protective technologies such as endpoint security, web application firewalls, SIEM, vulnerability management, and identity security controls.
  • Participate in security reviews of new applications, systems, infrastructure, and technology projects.
  • Support cybersecurity governance, risk assessments, policies, standards, compliance activities, and security audits.
  • Work closely with infrastructure, software development, networking, and other IT teams to improve the organization's overall security posture.
Required / Preferred Experience
  • Hands-on cybersecurity experience involving the implementation, administration, or improvement of technical security controls in enterprise environments.
  • Professional hands-on experience in penetration testing and vulnerability assessment.
  • Strong understanding of web application, API, network, operating system, and enterprise security.
  • Experience with penetration testing tools such as Burp Suite, Nmap, Metasploit, or equivalent tools.
  • Experience working with SIEM and security monitoring platforms. Wazuh, Microsoft Sentinel, Splunk, or similar platforms.
  • Experience investigating cybersecurity alerts and security incidents.
  • Experience working with Microsoft Azure and/or AWS, including an understanding of cloud identity, network, workload, and logging security.
  • Strong understanding of Windows, Linux, TCP/IP, networking, authentication, and enterprise infrastructure.
  • Good understanding of cybersecurity governance, risk management, policies, standards, and compliance requirements.
  • Good knowledge of Microsoft Active Directory and identity security concepts, including authentication, privileged accounts, Group Policy, Kerberos, NTLM, LDAP, and service accounts.
  • Previous cybersecurity experience within a UAE government, semi-government, higher education, or regulated organization is highly desirable.
Strong Advantages
  • Web development experience, particularly an understanding of how modern web applications, APIs, databases, authentication, sessions, and backend services operate.
  • Familiarity with development technologies such as Python, PHP, JavaScript, .NET, Java, Flask, Django, Node.js, or similar frameworks.
  • Server administration experience across Windows and/or Linux environments, including web servers, services, permissions, hardening, logging, and troubleshooting.
  • Strong knowledge of Microsoft Active Directory, including users and groups, Group Policy, Kerberos, NTLM, LDAP, privileged accounts, service accounts, and common Active Directory security risks.
  • Active Directory penetration testing or security assessment experience.
  • Experience with Microsoft Entra ID, Conditional Access, Privileged Identity Management, Defender, Sentinel, and Intune.
  • Cloud security assessment and cloud configuration review experience.
  • Strong web application and API penetration testing experience.
  • Scripting or automation experience using PowerShell, Python, Bash, or similar technologies.
Qualifications & Certifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related field.
  • OSCP/OSWE/OSEP is strongly preferred.
  • Hack The Box certifications such as CPTS/CWES/CBBH/CDSA/CWEE/CAPE/COAE are considered a strong advantage.
  • Additional certifications in cloud security, Microsoft security, incident response, penetration testing, infrastructure security, or cybersecurity governance are beneficial.
Key Competencies
  • Strong technical and analytical problem-solving skills.
  • Ability to think from both an attacker and defender perspective.
  • Strong understanding of how applications, servers, networks, identities, and security controls interact.
  • Ability to investigate technical issues independently.
  • Clear technical documentation and reporting skills.
  • Ability to communicate cybersecurity risks to both technical and non-technical stakeholders.
  • Strong professional ethics, confidentiality, and attention to detail.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000
Cybersecurity Specialist
Cybersecurity Specialist

techcarrot • Abu Dhabi

On-site
AED 268,000 - 402,000
Specialist - Offensive Security
Specialist - Offensive Security

PureCS • Dubai

On-site
AED 180,000 - 300,000
Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Cloud Security Engineer
Cloud Security Engineer

Theme Blog Studio • Dubai

On-site
AED 250,000 - 450,000
Specialist Cybersecurity Analyst Emirati Talent
Specialist Cybersecurity Analyst Emirati Talent

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior Security Engineer
Senior Security Engineer

Confidential • Sharjah

On-site
AED 350,000 - 550,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Dubai

On-site
AED 180,000 - 250,000
Cloud Security Engineer
Cloud Security Engineer

DAG • Dubai

On-site
AED 300,000 - 540,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Abu Dhabi

On-site
AED 293,000 - 441,000