Senior Cybersecurity Consultant

Employment

Doha

On-site

QAR 437,000 - 655,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Employment is seeking a Senior Cybersecurity Consultant to join our Cybersecurity Practice as an Incident Handler. You will lead detection, investigation, containment and recovery of security incidents across enterprise and cloud environments, with a strong focus on Microsoft Defender, Sentinel, Purview, and DLP.

You will collaborate with SOC analysts and IT operations to triage alerts, coordinate containment and eradication, and develop playbooks for proactive threat hunting across the

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 8+ years of experience in cybersecurity operations, incident response, or security monitoring with hands-on Microsoft security tools.
  • Relevant professional certifications such as SC-200, SC-100, SC-400, GIAC/ISC2 are highly desirable.
  • Strong hands-on experience with the Microsoft security stack and cloud/endpoint forensics.

Responsibilities

  • Incident Handling & Response: lead end-to-end management of incidents per IR processes and SLAs.
  • Operate and tune Microsoft Defender (EDR/XDR) across endpoints, identities, email, and cloud workloads.
  • Use Microsoft Sentinel for log analysis, correlation, and automated response; develop rules and playbooks.
  • Leverage Microsoft Purview and DLP to govern data and protect information assets.
  • Threat hunting across Microsoft 365 and Azure; develop new detections and improve detection logic.
  • Forensics: conduct host, endpoint, and cloud investigations and preserve evidence.
  • Documentation: produce incident reports, timelines, and post-incident reviews; maintain runbooks.

Skills

Incident response
Threat hunting
Forensic analysis
Detections engineering

Education

Bachelor's in CS or Info Security

Tools

Microsoft Defender
Microsoft Sentinel
Microsoft Purview
DLP (Data Loss Prevention)
KQL
PowerShell
Entra ID
Active Directory

Job description

Industry Information Technology and Services

Job Description

We are seeking a skilled Senior Cybersecurity Consultant to join our Cybersecurity Practice as an Incident Handler within our security operations function. In this role, you will lead the detection, investigation, containment, and recovery of security incidents across enterprise and cloud environments, with a strong focus on the Microsoft security ecosystem.

Your responsibilities will center on incident handling and response, threat detection and hunting, and the day-to-day operation of Microsoft security tooling including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Data Loss Prevention (DLP). You will drive incidents through the full response lifecycle and continuously improve detection and response capabilities.

You will work closely with SOC analysts, threat intelligence, and IT operations teams to triage alerts, lead investigations, coordinate containment and eradication, and conduct post-incident reviews. You will also tune detections, develop response playbooks, and support proactive threat hunting across the Microsoft 365 and Azure estate.

The role requires deep, hands-on operational expertise in incident response and the Microsoft security stack, strong analytical and forensic capabilities, and the ability to remain calm and decisive under pressure during active security incidents.

Responsibilities
  • Incident Handling & Response:Lead the end-to-end handling of security incidents, including detection, triage, investigation, containment, eradication, and recovery, in line with established incident response processes and SLAs.
  • Microsoft Defender (EDR/XDR):Operate, tune, and investigate using Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps to detect and respond to threats across endpoints, identities, email, and cloud workloads.
  • Microsoft Sentinel (SIEM/SOAR):Use Microsoft Sentinel for log analysis, correlation, and automated response. Develop and tune analytic rules, KQL queries, workbooks, and SOAR playbooks to improve detection coverage and response efficiency.
  • Microsoft Purview & Data Security:Leverage Microsoft Purview for data governance, information protection, insider risk management, and compliance. Investigate data-related alerts and support data security and DLP operations.
  • Data Loss Prevention (DLP):Configure, monitor, and respond to DLP policies across Microsoft 365 and endpoints to detect and prevent unauthorized data exfiltration, and refine policies to reduce false positives.
  • Threat Hunting & Detection Engineering:Conduct proactive threat hunting across the Microsoft 365 and Azure estate, develop new detections, and continuously improve detection logic based on threat intelligence and lessons learned.
  • Forensics & Root Cause Analysis:Perform host, endpoint, and cloud-based investigations and digital forensics to determine root cause, scope, and impact of incidents, preserving evidence in line with best practices.
  • Documentation & Reporting:Produce high-quality incident reports, timelines, and post-incident reviews. Maintain runbooks and playbooks, and provide clear incident updates to internal stakeholders and clients.
Qualifications
  • Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience: At least 8 years of experience in cybersecurity operations, incident response, or security monitoring, with significant hands-on experience operating Microsoft security tools.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:Microsoft Security Operations Analyst (SC-200) Microsoft Certified: Cybersecurity Architect (SC-100) or Information Protection (SC-400) GIAC incident response / forensics (e.g., GCIH, GCFA) or equivalent ISC2 (e.g., SSCP or CISSP) or Comp TIA CySA+.
  • Technical Skills: Strong hands‑on experience with the Microsoft security stack, including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Microsoft 365 DLP. Proficiency with KQL for investigation and detection. Experience with EDR investigation, log analysis, SIEM/SOAR, endpoint and cloud forensics, and identity platforms (Entra ID and Active Directory). Familiarity with scripting (e.g., Power Shell) for automation is preferred.
  • Knowledge: Strong understanding of incident response methodologies and frameworks (e.g., NIST SP 800-61, SANS), the MITRE ATT&CK framework, the cyber kill chain, and modern attacker techniques. Solid grasp of cybersecurity principles including defense-in‑depth, zero trust, and least privilege. Familiarity with ISO 27001 and CIS Benchmarks. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Response Lead Microsoft Stack
Senior Cybersecurity Incident Response Lead Microsoft Stack

Employment • Doha

On-site
QAR 437,000 - 655,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Employment • Doha

On-site
QAR 360,000 - 600,000
Senior SOC Engineer
Senior SOC Engineer

Employment • Doha

On-site
QAR 250,000 - 350,000
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
Cybersecurity Detection Engineer
Cybersecurity Detection Engineer

Employment • Doha

On-site
QAR 180,000 - 240,000
IT Security Specialist
IT Security Specialist

Employment • Doha

On-site
QAR 180,000 - 300,000
SOC Thread Specialist
SOC Thread Specialist

Employment • Doha

On-site
QAR 350,000 - 700,000
Technical Project Manager (Cybersecruity)
Technical Project Manager (Cybersecruity)

BAE Systems • Doha

On-site
QAR 250,000 - 550,000
Senior Consultant - Cybersecurity
Senior Consultant - Cybersecurity

Employment • Doha

On-site
QAR 180,000 - 240,000
Senior Cybersecurity Certification Consultant
Senior Cybersecurity Certification Consultant

Alftek • Doha

On-site
QAR 360,000 - 480,000