Senior Consultant - Cybersecurity

malomatia

Doha

On-site

QAR 300,000 - 540,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

malomatia is seeking a Senior Cybersecurity Consultant to join its Cybersecurity Practice as an Incident Handler within the security operations function. You will lead detection, investigation, containment, and recovery of incidents focusing on the Microsoft security ecosystem.

The role requires hands-on expertise with Microsoft Defender (EDR/XDR), Defender for Office, Defender for Identity, Defender for Cloud Apps, and Microsoft Sentinel, Purview, and DLP across Microsoft 365 and Azure.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • 8+ years in cybersecurity operations, incident response, or security monitoring with hands-on Microsoft security tools.

Responsibilities

  • Lead end-to-end security incident handling across enterprise and cloud environments.
  • Tune and operate Microsoft Defender, Defender for Identity and Defender for Cloud Apps for threat detection and response.
  • Develop and tune analytic rules, KQL queries, runbooks, and SOAR playbooks to improve detection and response.
  • Perform forensics and root cause analysis, document timelines and post-incident reviews.

Skills

Microsoft Defender
Microsoft Sentinel
Purview
DLP
KQL
PowerShell
incident response
forensics

Education

Bachelor’s degree in Computer Science or related field

Tools

Defender
Sentinel
Purview
EDR/XDR tooling

Job description

Job Description

We are seeking a skilled Senior Cybersecurity Consultant to join our Cybersecurity Practice as an Incident Handler within our security operations function. In this role, you will lead the detection, investigation, containment, and recovery of security incidents across enterprise and cloud environments, with a strong focus on the Microsoft security ecosystem.

Your responsibilities will center on incident handling and response, threat detection and hunting, and the day-to-day operation of Microsoft security tooling including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Data Loss Prevention (DLP). You will drive incidents through the full response lifecycle and continuously improve detection and response capabilities.

You will work closely with SOC analysts, threat intelligence, and IT operations teams to triage alerts, lead investigations, coordinate containment and eradication, and conduct post-incident reviews. You will also tune detections, develop response playbooks, and support proactive threat hunting across the Microsoft 365 and Azure estate.

The role requires deep, hands-on operational expertise in incident response and the Microsoft security stack, strong analytical and forensic capabilities, and the ability to remain calm and decisive under pressure during active security incidents.

Responsibilities
  • Incident Handling & Response:Lead the end-to-end handling of security incidents, including detection, triage, investigation, containment, eradication, and recovery, in line with established incident response processes and SLAs.
  • Microsoft Defender (EDR/XDR):Operate, tune, and investigate using Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps to detect and respond to threats across endpoints, identities, email, and cloud workloads.
  • Microsoft Sentinel (SIEM/SOAR):Use Microsoft Sentinel for log analysis, correlation, and automated response. Develop and tune analytic rules, KQL queries, workbooks, and SOAR playbooks to improve detection coverage and response efficiency.
  • Microsoft Purview & Data Security:Leverage Microsoft Purview for data governance, information protection, insider risk management, and compliance. Investigate data-related alerts and support data security and DLP operations.
  • Data Loss Prevention (DLP):Configure, monitor, and respond to DLP policies across Microsoft 365 and endpoints to detect and prevent unauthorized data exfiltration, and refine policies to reduce false positives.
  • Threat Hunting & Detection Engineering:Conduct proactive threat hunting across the Microsoft 365 and Azure estate, develop new detections, and continuously improve detection logic based on threat intelligence and lessons learned.
  • Forensics & Root Cause Analysis:Perform host, endpoint, and cloud-based investigations and digital forensics to determine root cause, scope, and impact of incidents, preserving evidence in line with best practices.
  • Documentation & Reporting:Produce high-quality incident reports, timelines, and post-incident reviews. Maintain runbooks and playbooks, and provide clear incident updates to internal stakeholders and clients.
Qualifications
  • Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience: At least 8 years of experience in cybersecurity operations, incident response, or security monitoring, with significant hands-on experience operating Microsoft security tools.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
    • Microsoft Security Operations Analyst (SC-200)
    • Microsoft Certified: Cybersecurity Architect (SC-100) or Information Protection (SC-400)
    • GIAC incident response / forensics (e.g., GCIH, GCFA) or equivalent
    • ISC2 (e.g., SSCP or CISSP) or CompTIA CySA+.
  • Technical Skills: Strong hands-on experience with the Microsoft security stack, including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Microsoft 365 DLP. Proficiency with KQL for investigation and detection. Experience with EDR investigation, log analysis, SIEM/SOAR, endpoint and cloud forensics, and identity platforms (Entra ID and Active Directory). Familiarity with scripting (e.g., PowerShell) for automation is preferred.
  • Knowledge: Strong understanding of incident response methodologies and frameworks (e.g., NIST SP 800-61, SANS), the MITRE ATT&CK framework, the cyber kill chain, and modern attacker techniques. Solid grasp of cybersecurity principles including defense-in-depth, zero trust, and least privilege. Familiarity with ISO 27001 and CIS Benchmarks. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Consultant
Senior Cybersecurity Consultant

Employment • Doha

On-site
QAR 437,000 - 655,000
Senior Cybersecurity Incident Response Lead Microsoft Stack
Senior Cybersecurity Incident Response Lead Microsoft Stack

Employment • Doha

On-site
QAR 437,000 - 655,000
Cloud Security Consultant
Cloud Security Consultant

malomatia • Doha

On-site
QAR 240,000 - 360,000
Senior Incident Lead - Microsoft Defender & SIEM
Senior Incident Lead - Microsoft Defender & SIEM

malomatia • Doha

On-site
QAR 300,000 - 540,000
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
QAR 334,800 - 502,200
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Employment • Doha

On-site
QAR 360,000 - 600,000
Cybersecurity Detection Engineer
Cybersecurity Detection Engineer

Employment • Doha

On-site
QAR 180,000 - 240,000
Senior SOC Engineer
Senior SOC Engineer

Employment • Doha

On-site
QAR 250,000 - 350,000
Technical Project Manager (Cybersecruity)
Technical Project Manager (Cybersecruity)

BAE Systems • Doha

On-site
QAR 250,000 - 550,000
Incident Response Oversight Expert
Incident Response Oversight Expert

Adecco • Doha

On-site
QAR 800,000 - 1,400,000