Job Description
Job Purpose
We are seeking a hands‑on Cybersecurity Specialist with strong experience in penetration testing, security monitoring, vulnerability management, and cybersecurity governance. The ideal candidate should have a strong security background while also being comfortable working with enterprise infrastructure, SIEM platforms, cloud environments, servers, Active Directory, and web applications.
Key Responsibilities
- Conduct penetration testing and security assessments of web applications, APIs, networks, servers, Active Directory environments, and other enterprise systems.
- Identify vulnerabilities, assess their risk and exploitability, and provide practical remediation recommendations.
- Perform manual penetration testing, including assessments against OWASP Top 10 and OWASP API Security Top 10 risks.
- Monitor and investigate security events and alerts through SIEM and security monitoring platforms.
- Support security incident investigation, response, containment, remediation, and post-incident improvement activities.
- Develop and tune SIEM alerts, detection rules, dashboards, and monitoring use cases.
- Support vulnerability management and coordinate remediation activities with infrastructure and development teams.
- Review the security of Microsoft Azure and AWS environments.
- Review Microsoft Azure and AWS environments and support the implementation of appropriate identity, network, logging, workload, and configuration security controls.
- Review and strengthen Microsoft Active Directory and Entra ID security, including privileged access, service accounts, authentication controls, Group Policy, and identity-related risks.
- Support the implementation and operation of protective technologies such as endpoint security, web application firewalls, SIEM, vulnerability management, and identity security controls.
- Participate in security reviews of new applications, systems, infrastructure, and technology projects.
- Support cybersecurity governance, risk assessments, policies, standards, compliance activities, and security audits.
- Work closely with infrastructure, software development, networking, and other IT teams to improve the organization's overall security posture.
Qualifications
Required / Preferred Experience
- Hands-on cybersecurity experience involving the implementation, administration, or improvement of technical security controls in enterprise environments.
- Professional hands-on experience in penetration testing and vulnerability assessment.
- Strong understanding of web application, API, network, operating system, and enterprise security.
- Experience with penetration testing tools such as Burp Suite, Nmap, Metasploit, or equivalent tools.
- Experience working with SIEM and security monitoring platforms. Wazuh, Microsoft Sentinel, Splunk, or similar platforms.
- Experience investigating cybersecurity alerts and security incidents.
- Experience working with Microsoft Azure and/or AWS, including an understanding of cloud identity, network, workload, and logging security.
- Strong understanding of Windows, Linux, TCP/IP, networking, authentication, and enterprise infrastructure.
- Good understanding of cybersecurity governance, risk management, policies, standards, and compliance requirements.
- Good knowledge of Microsoft Active Directory and identity security concepts, including authentication, privileged accounts, Group Policy, Kerberos, NTLM, LDAP, and service accounts.
- Previous cybersecurity experience within a UAE government, semi-government, higher education, or regulated organization is highly desirable.
Strong Advantages
- Web development experience, particularly an understanding of how modern web applications, APIs, databases, authentication, sessions, and backend services operate.
- Familiarity with development technologies such as Python, PHP, JavaScript, .NET, Java, Flask, Django, Node.js, or similar frameworks.
- Server administration experience across Windows and/or Linux environments, including web servers, services, permissions, hardening, logging, and troubleshooting.
- Strong knowledge of Microsoft Active Directory, including users and groups, Group Policy, Kerberos, NTLM, LDAP, privileged accounts, service accounts, and common Active Directory security risks.
- Active Directory penetration testing or security assessment experience.
- Experience with Microsoft Entra ID, Conditional Access, Privileged Identity Management, Defender, Sentinel, and Intune.
- Cloud security assessment and cloud configuration review experience.
- Strong web application and API penetration testing experience.
- Scripting or automation experience using PowerShell, Python, Bash, or similar technologies.
Qualifications & Certifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related field.
- OSCP/OSWE/OSEP is strongly preferred.
- Hack The Box certifications such as CPTS/CWES/CBBH/CDSA/CWEE/CAPE/COAE are considered a strong advantage.
- Additional certifications in cloud security, Microsoft security, incident response, penetration testing, infrastructure security, or cybersecurity governance are beneficial.
Key Competencies
- Strong technical and analytical problem-solving skills.
- Ability to think from both an attacker and defender perspective.
- Strong understanding of how applications, servers, networks, identities, and security controls interact.
- Ability to investigate technical issues independently.
- Clear technical documentation and reporting skills.
- Ability to communicate cybersecurity risks to both technical and non-technical stakeholders.
- Strong professional ethics, confidentiality, and attention to detail.
Job Category
Information Security
Advertiser
Hamdan Bin Mohammed Smart University
Required Nationality
UAE Only
Monthly Salary
Unspecified
Schedule-Time
Full time
Job Posting
08/09/2026
Unposting Date
08/12/2026