Important Note: -Given the urgency of this position, the recruitment process has been accelerated. Interviews are progressing actively, with all candidate assessments expected to be completed over the next two weeks.
Salary
- AED 18000 - 20,000 per month
Duration
- 1 year (can be extendable)
Required Notice Period
-Immediate or max 1 month
Education -
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
Mandate: -
Experience -
7+ years
Location / Coverage -
Abu Dhabi | 8x5 with support for critical incidents and planned changes when required
Primary focus -
Database activity monitoring; API security monitoring; privileged access management
Secondary focus -
Enterprise DLP and information protection; deception; endpoint protection and XDR; network detection and prevention.
Education and Preferred Credentials
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline.
- Relevant professional certification in information security, audit or security operations is preferred.
- Capability-based certifications in database security, API security or privileged access are advantageous.
- IT service management certification is advantageous.
Required Experience and Skills
- 7+ years of information security, security engineering or security operations experience.
- Deep hands‑on experience in at least one primary domain: database activity monitoring, API security monitoring or privileged access management; practical exposure to at least one additional domain is preferred.
- Experience configuring and tuning monitoring policies, thresholds, exclusions and alert workflows.
- Understanding of database access patterns, privileged activity, API discovery, authentication risks and common API attacks.
- Experience with SIEM event forwarding, ITSM workflows and incident handling.
- Ability to troubleshoot agents, collectors, gateways, connectors, event pipelines and access‑control issues.
- Working knowledge of DLP/information protection, endpoint/XDR, deception and network security for backup coverage.
- Strong documentation, evidence management and stakeholder communication skills.
Key Responsibilities
- Administer and maintain database activity monitoring, API security monitoring and privileged access management capabilities.
- Maintain inventories of monitored databases, APIs, privileged accounts, integrated systems and supporting components.
- Validate agent, gateway, collector, filtering‑node, connector and event‑ingestion health.
- Configure and tune policies for privileged database activity, sensitive‑data access, anomalous queries, API attacks and unauthorized behaviour.
- Review alerts, validate risk and coordinate investigation and remediation with relevant teams.
- Reconcile discovered APIs and monitored databases against approved inventories and owners.
- Maintain administrative‑access controls, access reviews, exceptions and evidence of privileged activity.
- Integrate telemetry with SIEM, ITSM and incident workflows; validate event completeness and escalation paths.
- Plan approved changes with testing, rollback, validation and complete evidence.
- Maintain SOPs, runbooks, architecture diagrams, integration matrices and recovery procedures.
- Produce reporting covering service health, monitoring coverage, alert quality, risks and remediation.
- Support audits, compliance assessments and closure of platform findings.
- Provide first‑level backup coverage for DLP/information protection, endpoint/XDR, deception and IDS/IPS.
Success Measures
- Database, API and privileged‑account inventories are current and reconciled.
- Platform‑health and ingestion failures are detected and resolved promptly.
- Policies and alerts provide actionable coverage with controlled false positives.
- Changes, incidents, exceptions and access reviews are audit‑ready.
- Backup readiness is maintained through access, runbooks and knowledge transfer.