Analyst Cyber Security

Gulf Air

Bahrain

On-site

BHD 13,000 - 27,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gulf Air is strengthening its cyber security team to implement and enhance controls across cloud, applications, and DevOps pipelines. You will monitor risks, enforce secure coding practices, and collaborate with cross-functional teams to improve resilience while securing operations.

The role involves threat modeling, secret management, and securing APIs/microservices, with a focus on secure DevOps and incident response in a hybrid cloud environment.

Qualifications

  • Experience designing and maintaining automated security checks in CI/CD pipelines (SAST/DAST/SCA).
  • Collaborates with developers to enforce secure coding standards and conduct code reviews.
  • Monitors cloud security alerts across AWS/Azure/Oracle and uses Defender/GuardDuty CSPM findings.
  • Reviews Terraform IaC for misconfigurations and enforces security by design.
  • Enforces container security with image scanning, runtime protection, and pod policies.
  • Implements secrets management across environments.
  • Performs SIEM/XDR/IDS/IPS monitoring and incident response.
  • Leads threat modeling sessions with teams to mitigate risks.
  • Acts as security liaison and conducts DevSecOps training.
  • Assesses APIs and microservices security with gateways and OAuth/JWT.

Responsibilities

  • Design, implement, and maintain automated security checks in CI/CD pipelines.
  • Partner with developers to enforce secure coding standards and perform code reviews.
  • Monitor cloud security alerts and triage CSPM findings by severity.
  • Review IaC templates for misconfigurations before deployment.
  • Enforce container security with image scanning and Kubernetes policies.
  • Govern secrets management to prevent hardcoded credentials.
  • Monitor SIEM/XDR/IDS/IPS and respond to incidents promptly.
  • Conduct threat modeling with development and infrastructure teams.
  • Deliver security training and foster shared DevSecOps responsibility.
  • Assess APIs and microservices security with API gateway controls and OAuth/JWT.

Skills

Threat Detection and Response
Vulnerability Management
Privilege Access Management
Security Automation and Orchestration
DevSecOps
Security Hardening and Compliance
Cloud Security
Network Security
Endpoint Security

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity

Tools

Microsoft Defender XDR
Microsoft Sentinel
Microsoft Defender for Cloud
Microsoft Defender for Endpoint
Nessus
Qualys
OpenVAS
Wallix
CyberArk
BeyondTrust
Python
Splunk Phantom
Cortex XSOAR
Azure Sentinel
GitHub Actions
AWS CodePipeline
Palo Alto Networks
Fortinet
Cisco ASA
Snort
Suricata
CrowdStrike Falcon
SentinelOne
AWS Security Hub
Azure Security Center
Defender for Cloud

Job description

JOB PURPOSE

Support the implementation and continuous enhancement of cyber security controls across applications cloud infrastructure DevOps pipelines and operational environments by monitoring security risks enforcing secure development and infrastructure practices responding to security incidents and collaborating with cross-functional teams to strengthen the organization s overall cyber resilience and secure technology operations

KEY RESPONSIBILITIES
  • Design implement and maintain automated security checks SAST DAST SCA within the CI CD pipeline to ensure vulnerabilities are detected and remediated early in the software development lifecycle following the shift-left security approach
  • Partner closely with software developers to enforce secure coding standards based on frameworks such as OWASP Top 10 conduct security-focused code reviews and provide real-time guidance on mitigating common application vulnerabilities
  • Monitor and analyze security alerts across cloud environments AWS Azure Oracle using tools such such as Microsoft Defender for Cloud AWS Guard Duty and triage cloud security posture management CSPM findings by severity and exposure risk
  • Work with the infrastructure and cloud platform engineering teams to scan and validate IaC templates Terraform for misconfigurations and policy violations before deployment embedding security-as-code principles into infrastructure provisioning
  • Enforce security controls for containerized workloads including container image scanning runtime protection Kubernetes admission policies and pod security standards in collaboration with the cloud platform engineering team
  • Implement and govern secrets management solutions e g Azure Key Vault AWS Secrets Manager to prevent hardcoded credentials in repositories and ensure secure injection of secrets at runtime across development and operations environments
  • Monitor security systems SIEM XDR IDS IPS to detect triage and respond to security incidents in a timely manner perform in-depth log analysis forensic investigation and root cause analysis across both on-premises and cloud environments
  • Conduct threat modeling sessions with development and infrastructure teams for new applications services and architectural changes to proactively identify and mitigate security risks before they enter production
  • Act as the security liaison across development cloud platform engineering and infrastructure teams deliver security awareness training conduct workshops on secure DevOps practices and foster a culture of shared security responsibility
  • Assess and secure APIs and microservices architectures by implementing API gateway security controls authentication authorization best practices OAuth JWT rate limiting and automated API security testing within the DevSecOps pipeline
EDUCATION / QUALIFICATIONSBachelor's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent major in the related field.
EXPERIENCE0-2 years of experience in the related field.
JOB SPECIFIC SKILLS & ATTRIBUTES
  • Threat Detection and Response using any of these tools (Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft Defender for Endpoint).
  • Vulnerability Management using any of these tools (Nessus, Qualys, OpenVAS).
  • Privilege Access Management (PAM) using any of these tools (Wallix, CyberArk, Beyond Trust).
  • Security Automation and Orchestration using any of these tools (Python, Splunk Phantom, Cortex XSOAR, Azure Sentinel).
  • DevSecOps use any of these tools (SonarQube, GitHub Actions, AWS Code Pipeline).
  • Security Hardening and Compliance using any of these tools (CIS Benchmarks, SITG Benchmarks, Qualys Policy Compliance).
  • Cloud Security using any of these tools (AWS Security Hub, Azure Security Center, Microsoft Defender for Cloud)
  • Network Security using any of these tools (Palo Alto Networks, Fortinet, Cisco ASA, Snort, Suricata)
  • Endpoint Security using any of these tools (Microsoft Defender for Endpoint, CrowdStrike Falcon, Sentinel One).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Assurance Analyst
Cyber Assurance Analyst

Client of 6 Pence • Bahrain

On-site
BHD 12,000 - 24,000
Sr. Zscaler Security Engineer
Sr. Zscaler Security Engineer

International Turnkey Systems - ITS • Capital Governorate

On-site
BHD 20,000 - 36,000
Security Operations Center (SOC) Manager
Security Operations Center (SOC) Manager

Aventus • Capital Governorate

On-site
BHD 34,000 - 45,000
Cloud DevOps Engineer
Cloud DevOps Engineer

Thales • Bahrain

On-site
BHD 39,000 - 56,000
Security Architect
Security Architect

Vamsystems • Manama

On-site
Cyber Security Analyst: DevSecOps & Cloud Resilience
Cyber Security Analyst: DevSecOps & Cloud Resilience

Gulf Air • Bahrain

On-site
BHD 13,000 - 27,000
Manager - System Operations (Platform Engineering)
Manager - System Operations (Platform Engineering)

Gulf Air • Manama

On-site
BHD 24,000 - 42,000
OT Cyber Security Engineer
OT Cyber Security Engineer

Yokogawa • Muharraq

On-site
BHD 18,000 - 36,000
Application Support Specialist
Application Support Specialist

Leading Edge • Manama

On-site
BHD 22,000 - 31,000
Systems Specialist - Fircosoft
Systems Specialist - Fircosoft

Capitex • Manama

On-site
BHD 33,000 - 46,000