Job Title
Information Security Engineer | Dicetek UAE (Government Project) | Dubai, UAE
Recruiting Company
Dicetek UAE
Job Location
Dubai, UAE
Job Type
Full-Time
Number of Positions
Multiple Openings
Client
Government Project
Notice Period Requirement
30 Days or Less
Hiring Priority
Urgent Requirement
Email Subject Format
Information Security Engineer - [Your Location] - [Notice Period]
Position Summary
A leading government project in Dubai is seeking experienced Information Security Engineers to strengthen its cybersecurity posture across enterprise infrastructure, cloud, container platforms, DevSecOps pipelines, and emerging AI-driven environments. This role requires a highly skilled security professional capable of conducting complex security assessments, identifying risks, enforcing compliance standards, and supporting secure digital transformation initiatives across mission-critical systems.
Detailed Job Description
As an Information Security Engineer, you will be responsible for assessing, securing, and strengthening enterprise technology environments spanning on-premises infrastructure, cloud platforms, containers, databases, middleware, and modern DevSecOps ecosystems. Working closely with technology teams, project stakeholders, vendors, and security leadership, you will conduct comprehensive security reviews, vulnerability assessments, compliance evaluations, and risk management activities. The role demands strong expertise in cloud security, container security, identity and access management, CI/CD security, and regulatory compliance frameworks. You will play a key role in ensuring secure architecture design, enforcing security best practices, and supporting governance requirements across complex enterprise and government environments. This position offers exposure to cutting-edge technologies, including AI security, cloud-native platforms, Microsoft security ecosystems, and enterprise-scale cybersecurity programs.
Key Responsibilities
- Conduct infrastructure security assessments across servers, networks, databases, middleware, virtualization platforms, and cloud environments.
- Perform security reviews and hardening assessments for Oracle, SQL Server, PostgreSQL, MySQL, MongoDB, IIS, Tomcat, and JBoss environments.
- Evaluate compliance against CIS Benchmarks, NIST, ISO 27001, and industry security standards.
- Assess and strengthen Identity & Access Management (IAM) controls, Active Directory, LDAP, RBAC, PAM, and privileged access environments.
- Perform container security assessments across Docker, Kubernetes, OpenShift, Podman, and CRI-O platforms.
- Review container images, runtime security controls, network segmentation, RBAC policies, and certificate-based security implementations.
- Conduct CI/CD security assessments covering Jenkins, GitLab CI/CD, GitHub Actions, and DevSecOps pipelines.
- Validate implementation of SAST, DAST, SCA, secrets management, dependency security, and SBOM controls.
- Assess security architectures and configurations across Azure, AWS, GCP, and OCI cloud environments.
- Evaluate cloud-native security controls, CSPM implementations, IAM policies, data protection mechanisms, and workload security.
- Support Microsoft 365, Azure Security, Microsoft Purview, DLP, compliance, and encryption security initiatives.
- Participate in AI/ML security assessments, secure AI architecture reviews, API security evaluations, and AI governance programs.
- Perform risk assessments, vulnerability analysis, remediation planning, and security reporting.
- Collaborate with infrastructure, application, cloud, and project teams to implement security recommendations.
- Support regulatory, compliance, audit, and governance requirements across the organization.
- Manage security-related projects, stakeholder communications, vendor engagements, and change management activities.
Required Qualifications & Skills
- Proven experience conducting enterprise Infrastructure Security Assessments.
- Strong hands-on experience securing databases including Oracle, SQL Server, PostgreSQL, MySQL, and MongoDB.
- Experience assessing middleware and web application platforms including IIS, Tomcat, and JBoss.
- Deep understanding of CIS Benchmarks, NIST Cybersecurity Framework, ISO 27001, and security configuration reviews.
- Hands-on expertise with Identity & Access Management technologies including Active Directory, LDAP, RBAC, and PAM.
- Strong experience in Container Security across Kubernetes, OpenShift, Docker, Podman, and CRI-O environments.
- Practical knowledge of container security tools such as Trivy, Anchore, Clair, Falco, Aqua Security, Prisma Cloud, and Sysdig.
- Experience conducting CI/CD and DevSecOps security assessments.
- Strong understanding of SAST, DAST, SCA, secrets management, and software supply chain security.
- Hands-on experience assessing Azure, AWS, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI).
- Experience with Microsoft 365 Security, Microsoft Azure Security, Microsoft Purview, DLP, encryption, and compliance controls.
- Knowledge of AI/ML security concepts, secure AI architecture, API security, and AI governance frameworks.
- Understanding of GDPR, UAE PDPL, CBUAE regulations, PCI DSS, ISR, and ISO/IEC 27001 compliance requirements.
- Strong project management, stakeholder engagement, risk management, and vendor management skills.
- Ability to prepare assessment reports, security recommendations, and executive-level documentation.
Nice-to-Have Skills
- CISSP certification.
- CCSK (Certificate of Cloud Security Knowledge).
- Microsoft SC-401 certification.
- Microsoft SC-900 certification.
- Experience with Wiz and Cloud Security Posture Management (CSPM) platforms.
- Exposure to government, highly regulated, or critical infrastructure environments.
- Knowledge of Zero Trust security architectures and cloud-native security frameworks.
- Experience with enterprise-scale security transformation programs.
Recruitment Pro Tip
For senior security assessment roles, recruiters and hiring managers pay close attention to the breadth of platforms you have secured and the measurable impact of your assessments. Highlight specific infrastructure, cloud, container, DevSecOps, and compliance projects where you identified critical vulnerabilities, implemented security controls, achieved regulatory compliance, or reduced organizational risk. Candidates who can demonstrate hands-on assessment expertise across multiple technology domains and provide quantifiable security outcomes are significantly more likely to be shortlisted.