Senior Security Analyst

Alchemy

Dubai

On-site

AED 180,000 - 300,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Alchemy in Dubai seeks a senior security professional to operationalise an ISO 27001-aligned ISMS and lead security operations for a SaaS platform. You will coordinate with DevOps and cloud teams to implement robust controls across AWS, manage vulnerability scans with Tenable/AWS Inspector/Snyk, and ensure endpoint compliance with Jamf and Intune.

You will prepare audit evidence and drive incident response activities.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or a related field or significant alternative relevant technical security industry experience.
  • 5+ years of hands-on experience in technical security roles in a SaaS context, with a focus on ISO 27001, SOC, AWS, and vulnerability management.
  • At least 2 years team lead experience in a 24x7 global SOC
  • Experience with AWS security tools and services in a production SaaS environment.
  • Experience with Tenable and/or similar tools for vulnerability management.
  • Familiarity with Jamf and Intune for endpoint compliance and hardening.
  • Good understanding of network security fundamentals, including cloud networking, segmentation, firewalls, and VPNs.
  • Ability to generate and present clear and actionable security and compliance reports to stakeholders.
  • Experience with DevOps tools, infrastructure-as-code, and CI/CD pipelines.

Responsibilities

  • Support the ongoing operation of the ISMS (ISO 27001-aligned) including evidence collection, control implementation, and audit readiness.
  • Work with DevOps and cloud teams to implement and monitor security controls across AWS infrastructure and services like EC2, IAM, S3, RDS.
  • Manage and operationalise vulnerability management using Tenable, AWS Inspector, and Snyk: schedule scans, triage findings, and track remediation.
  • Administer and ensure compliance of endpoints using Jamf and Microsoft Intune.
  • Monitor alerts and findings from AWS-native tools (GuardDuty, Security Hub) and coordinate incident response activities.
  • Produce and maintain management reports and dashboards detailing vulnerability status, endpoint security compliance, and audit readiness.
  • Support ISMS documentation, including SoA, risk assessments, corrective actions, and control mapping.
  • Participate in internal and external audits by preparing evidence and delivering technical walkthroughs.
  • Support policy implementation, training activities, and DevOps-aligned security processes.
  • Prepare the organisation for SOC 2 certification
  • Specify and implement security and compliance protocols for Alchemy SaaS products
  • Begin to identify tooling and partners to initiate a hybrid external/internal SOC.
  • Contribute to incident response testing and post-incident reviews.
  • Sets a positive example for quality and responsibility
  • Prepares all necessary project documentation and processes to enable ongoing support of Alchemy's software products.

Skills

ISO 27001
SOC
AWS
vulnerability management
team leadership
DevOps
IaC
CI/CD
network security
reporting
stakeholder communication

Education

Bachelor's degree in Information Security or related field

Tools

Tenable
Jamf
Intune
GuardDuty
Security Hub
AWS Inspector
Snyk

Job description

  • Support the ongoing operation of the ISO 27001-aligned Information Security Management System (ISMS), including evidence collection, control implementation, and audit readiness.
  • Work with DevOps and cloud teams to implement and monitor security controls across AWS infrastructure and services (e.g., EC2, IAM, S3, RDS).
  • Manage and operationalise vulnerability management using tools like Tenable, AWS Inspector, and Snyk: schedule scans, triage findings, and track remediation efforts.
  • Administer and ensure compliance of endpoints using Jamf (macOS) and Microsoft Intune (Windows).
  • Monitor alerts and findings from AWS-native tools (e.g., GuardDuty, Security Hub) and assist in coordinating incident response activities.
  • Produce and maintain management reports and dashboards detailing:
    • Vulnerability status and trends
    • Endpoint security compliance
    • Audit readiness and risk treatment status
  • Support maintenance of ISMS documentation, including SoA, risk assessments, corrective actions, and control mapping.
  • Participate in internal and external audits by preparing evidence and delivering technical walkthroughs.
  • Support policy implementation, training activities, and DevOps-aligned security processes.
  • Prepare the organisation for also achieving SOC 2 certification
  • Specify and implement security and compliance protocols for Alchemy SaaS products
  • Begin to identify and work with tooling and partners to initiate the creation of a hybrid external/internal SOC.
  • Contribute to incident response testing and post-incident reviews when applicable.
  • Sets a positive example throughout the organization for quality and responsibility
  • Prepares all necessary project documentation and processes to enable ongoing support of Alchemy's software products

The above list is not exhaustive, and you may be asked to undertake reasonable additional duties/ projects by Management.

SELECTION CRITERIA
Your Behaviors:
  • Detail-oriented and thorough, especially in documenting controls , reporting and audit evidence.
  • Collaborative and approachable- able to work cross-functionally with engineering, DevOps, and IT.
  • Proactive and self-driven, with a strong sense of ownership over technical security operations.
  • Clear communicator- able to explain security concepts to both technical and non-technical stakeholders.
  • Analytical mindset- adept at identifying patterns, prioritising risks, and suggesting practical mitigation strategies.
  • Organised and efficient, with the ability to manage multiple workstreams and deadlines in a compliance-focused environment.
  • Confident - You embrace having open and candid discussions with individuals at all levels both internally and with the Client
  • Decisive - you have a keen sense of prioritization and make intelligent decisions independently
  • Motivated - You are a self-starter with the ability to work independently under light supervision
  • Reliable - You're the person stakeholders and peers always want to work with
  • Compassionate - You understand that people are at the core of success
  • Data driven - Information is your friend; you love to use facts and evidence to help ensure success for the team and our customers
Qualifications, Knowledge, Skills and Experience
ESSENTIAL:
  • Bachelor's degree in Information Security, Computer Science, or a related field or significant alternative relevant technical security industry experience.
  • 5+ years of hands-on experience in technical security roles in a SaaS coontext, with a focus on ISO 27001, SOC, AWS, and vulnerability management.
  • At least 2 years team lead experience in a 24x7 global SOC
  • Experience with AWS security tools and services in a production SaaS environment.
  • Experience with Tenable and/or similar tools for vulnerability management.
  • Familiarity with Jamf and Intune for endpoint compliance and hardening.
  • Good understanding of network security fundamentals, including cloud networking, segmentation, firewalls, and VPNs.
  • Ability to generate and present clear and actionable security and compliance reports to stakeholders.
  • Experience with DevOps tools, infrastructure-as-code, and CI/CD pipelines.
DESIRABLE:
  • AWS Certified Security - Specialty or equivalent AWS certification.
  • Awareness of GDPR, NIST and related standards.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst: AWS, ISO 27001 & SOC Lead
Senior Security Analyst: AWS, ISO 27001 & SOC Lead

Alchemy • Dubai

On-site
AED 180,000 - 300,000
Senior Information security Analyst
Senior Information security Analyst

K20s - Kinetic Technologies Private Limited • Dubai

On-site
AED 360,000 - 560,000
Security Architect
Security Architect

iConnect IT Business Solutions DMCC • Dubai

On-site
AED 300,000 - 600,000
SecOps Engineer
SecOps Engineer

Evollabs • Dubai

On-site
AED 180,000 - 360,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

AGAPI • Dubai

On-site
AED 240,000 - 420,000
Executive Manager - Squad Cyber Technical Lead
Executive Manager - Squad Cyber Technical Lead

Dicetek LLC • Abu Dhabi

On-site
AED 420,000 - 640,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Client of ITHR 360° CONSULTING FZE • Dubai

On-site
AED 240,000 - 360,000
Senior Specialist – InfoSec Ops Management
Senior Specialist – InfoSec Ops Management

Tanqeeb • Abu Dhabi

On-site
AED 250,000 - 420,000
Information Security Specialist
Information Security Specialist

Salt • Sharjah

On-site
AED 240,000 - 360,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • United Arab Emirates

On-site
AED 350,000 - 550,000