F5/CloudFlare/LB/GTM- Network_Security_Engineer

Malomatia

Doha

On-site

QAR 180,000 - 280,000

Full time

26 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Malomatia is seeking an L2 Cloud Security Engineer to support day-to-day security operations across multi-cloud estates (Azure, OCI, GCP). You will handle identity and access requests, triage security alerts, implement changes, and manage PKI and certificates per established runbooks.

The role emphasizes hands-on work with Entra ID, Defender, Intune, and certificate management, with escalation to L3 when needed. Strong incident/change discipline is required in a fast-paced environment.

Qualifications

  • Bachelor's/college degree in Computer Science, IT, or related field.
  • 4–6 years IT experience with 2–3 years in cloud security/operations (L2).
  • Hands-on with Entra ID, RBAC, PIM, App Registrations, Conditional Access.
  • Experience with ITSM processes (incidents & changes) is required.
  • Certifications such as AZ-500, SC-300, SC-200, SC-900 desirable.

Responsibilities

  • Identity and Access Management: PIM, app registrations, managed identities, CA/MFA troubleshooting, SSO onboarding.
  • Security Automation: monitor and fix Logic Apps security automations.
  • Cloud Security Operations: alert triage, incident response, Azure Policy remediation, Defender for Cloud/Servers/AKS monitoring.
  • PKI and Certificate Management: certificate lifecycle, key management, inventory and renewal.
  • Operations and Documentation: ITSM tickets, runbooks, on-call support.

Skills

Entra ID
Azure RBAC
Azure Policy
Defender for Cloud
Intune
Logic Apps
PIM
PowerShell
Azure CLI
KQL

Education

Bachelor's degree in Computer Science/Information Technology

Tools

Azure Key Vault
GCP Certificate Authority Service
OCI
Microsoft Entra ID

Job description

Job Description

The L2 Cloud Security Engineer will support day-to-day security operations across our multi-cloud estate (Azure, OCI, and GCP). This is a hands-on, ticket-driven engineering role: you will action identity and access requests, triage and resolve security alerts, implement standard and pre-approved changes, and perform routine operational tasks across Microsoft Entra ID, Microsoft Defender, Intune, Logic Apps automation, and certificate/key management (GCP PKI, Azure Key Vault).
You will work within the operations team, picking up tickets from the queue, following runbooks and standard operating procedures, troubleshooting and resolving issues within agreed SLAs, and escalating complex or high-severity matters to the L3 Technical Lead with clear, well-documented findings.

Responsibilities

Identity and Access Management (Entra ID / Azure)

  • Privileged Identity Management (PIM):Process standard role-assignment and access-elevation requests, validate approvals before actioning, and support scheduled access reviews by collecting evidence and following up on outstanding reviewers.
  • App Registrations:Create app registrations and service principals per approved requests, rotate expiring secrets and certificates, and apply API permissions as specified in the request.
  • Managed Identities:Provision system-assigned and user-assigned managed identities and assign the requested RBAC roles for application and platform teams.
  • Conditional Access and MFA:Troubleshoot sign-in and MFA issues using sign-in logs, apply pre-approved Conditional Access changes, and manage user and group exclusions per change requests.
  • SSO / Federation:Support onboarding of applications to SSO using established templates and troubleshoot common federation and SAML/OIDC issues, escalating non-standard integrations.

Security Automation

  • Logic Apps Automation:Monitor existing Logic Apps security automations (IOC blocking, agent health checks, DNS change alerting), investigate failed runs, perform first-line fixes, and make minor updates under guidance.

Cloud Security Operations

  • Alert Triage and Incident Response:Triage security alerts and incidents from the queue, perform initial investigation and containment per playbooks, and upscale confirmed or high-severity incidents to L3 with documented evidence.
  • Azure Policy:Identify and remediate non-compliant resources flagged by Azure Policy, and apply policy assignments and exemptions per approved change requests.
  • Defender for Cloud:Review secure score and security recommendations daily, raise and track remediation tasks with resource owners, and report progress against agreed targets.
  • Defender for Servers and Containers:Monitor threat alerts on server and container workloads (including AKS), perform initial investigation, and process just-in-time (JIT) VM access requests.
  • Endpoint Security and Device Management:Perform routine administration of Microsoft Defender for Endpoint and Intune, including device onboarding, compliance troubleshooting, and application and certificate profile deployment.

PKI and Certificate Management

  • Certificate Lifecycle:Process certificate issuance, renewal, and revocation requests against internal CAs (including private CAs hosted in GCP) in line with existing PKI policy and standards.
  • Key Management:Manage keys and secrets in Azure Key Vault, including scheduled rotation and access-policy or RBAC updates per approved requests.
  • Inventory and Monitoring:Maintain certificate and key inventory records, monitor upcoming expiries, and raise renewal tickets well ahead of expiry dates.

Operations and Documentation

  • ITSM and Change Management:Work tickets within SLA, keep ticket notes accurate and complete, and raise standard change requests with implementation and rollback steps.
  • Runbooks and Knowledge Base: Follow and help maintain runbooks and SOPs, and document resolutions so recurring issues can be handled consistently.
  • Shift and On-call Support:Participate in shift handovers and an on-call rotation as required, ensuring open items are clearly communicated.
Qualifications
  • Education:Bachelor's / college degree in Computer Science, Information Technology, or a related field.
  • Experience:4-6 years of IT experience, including at least 2-3 years of hands-on cloud security or cloud operations work at L2 level. Practical experience administering Microsoft Entra ID (RBAC, PIM, App Registrations, Conditional Access) and operating Microsoft Defender products is required. Experience working tickets within an incident and change management process (ITSM) is required. Exposure to GCP or OCI is a plus.
  • Certifications:Relevant professional certifications are desirable. These may include, but are not limited to:
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • Vendor-agnostic certifications (CompTIA Security+, CCSK, etc.)
  • Technical Skills:Hands-on experience with Microsoft Entra ID, Azure RBAC, Azure Policy, Microsoft Defender for Cloud, Defender for Servers and Endpoint, Microsoft Intune, and Azure Key Vault. Familiarity with Logic Apps, Defender for Containers / AKS, and GCP Certificate Authority Service. Basic scripting ability (PowerShell, Azure CLI, or KQL) for investigation and routine tasks.
  • Knowledge:Solid understanding of identity and access concepts, PKI fundamentals (certificate lifecycle, key management, trust chains), and common cloud security threats. Ability to follow runbooks accurately, prioritise a ticket queue, and know when and how to elevate.
  • Soft Skills:Clear written and verbal communication, strong attention to detail in ticket documentation, and the ability to work effectively in a team and under time pressure.
About Us

About Malomatia

malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals.

Our mission

Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions.

Our vision

To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem.

Driving change that makes a real impact

Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future.

About the Team

Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.

Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.

Join us in shaping the future of technology in Qatar

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Malomatia • Doha

On-site
QAR 180,000 - 300,000
Senior Cloud Consultant
Senior Cloud Consultant

malomatia • Doha

On-site
QAR 180,000 - 300,000
No perks listed
Network_Security_Techinical_Lead
Network_Security_Techinical_Lead

Malomatia • Doha

On-site
QAR 150,000 - 190,000
On-call rotation
Travel to datacenter/client sites
Cloud Security Engineer
Cloud Security Engineer

Malomatia • Doha

On-site
QAR 180,000 - 300,000
Senior Network Security Engineer
Senior Network Security Engineer

Malomatia • Doha

On-site
QAR 320,000 - 520,000
Cloud Security Consultant
Cloud Security Consultant

Malomatia • Doha

On-site
QAR 180,000 - 320,000
Senior Consultant - Infrastructure Architecture
Senior Consultant - Infrastructure Architecture

malomatia • Doha

On-site
QAR 300,000 - 540,000
Application Security Lead
Application Security Lead

Malomatia • Doha

On-site
QAR 180,000 - 280,000
Senior Consultant - Cybersecurity
Senior Consultant - Cybersecurity

Employment • Doha

On-site
QAR 180,000 - 240,000
Senior Consultant - Infrastructure Architecture Doha, Qatar Posted on 08/31/2026 Trending
Senior Consultant - Infrastructure Architecture Doha, Qatar Posted on 08/31/2026 Trending

Malomatia • Doha

On-site
QAR 300,000 - 600,000