Cloud Security Engineering Lead

KAUST (King Abdullah University of Science and Technology)

Thuwal

On-site

SAR 320,000 - 520,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

KAUST (King Abdullah University of Science and Technology) invites a hands-on cloud security engineer to design, implement, and assure secure cloud and hybrid environments across KAUST's multi-cloud setup.

You will blend solution architecture with practical execution across Azure, Entra ID, Defender XDR, and related Microsoft security capabilities, leading complex deployments and ensuring operational readiness with partners and internal teams.

Qualifications

  • Hands-on cloud security engineering across Microsoft Azure and 365.
  • Experience with Entra ID, Conditional Access, PIM, and Defender XDR.
  • Knowledge of SIEM/SOAR, KQL analytics, and SOC integration.
  • Hands-on with cloud security posture management and hybrid/multicloud designs.

Responsibilities

  • Own cloud security architecture and engineering across initiatives from design to handover.
  • Assess Azure, Microsoft 365, hybrid and multicloud environments for gaps and improvements.
  • Design secure cloud architectures aligned with Zero Trust and KAUST standards.
  • Provide hands-on engineering across Microsoft security capabilities and tooling.
  • Lead technical design decisions, testing, remediation, and vendor reviews.
  • Develop secure connectivity and integration patterns for cloud and hybrid environments.
  • Mentor internal teams and ensure production readiness and documentation.

Skills

Azure security
Zero Trust
Entra ID
Defender XDR
PIM
MS 365 security
SIEM/SOAR
KQL analytics
Identity protection
Privileged access

Education

Bachelor's degree in CS or related field

Tools

Azure
Microsoft Entra ID
Defender XDR
Microsoft Sentinel
Purview
Intune
Defender for Cloud

Job description

KAUST is undertaking a Cybersecurity Transformation Program focused on secure cloud and hybrid environments across its multi-cloud environments. The organization emphasizes modern security architectures, Zero Trust, and sustainable operational handover, working closely with internal teams and delivery partners to modernize security operations, cloud security posture, identity, and network security.

Kaust is seeking a hands-on cloud security engineering role responsible for designing, implementing, and assuring secure cloud and hybrid environments across KAUST's multi-cloud environments. The role combines solution architecture with direct technical execution across cloud security, identity, endpoint, security operations, Zero Trust, and modern workplace security. The incumbent will translate security requirements into deployable technical controls, lead complex implementation activities, resolve cross-platform dependencies, and ensure solutions are operationally supportable and measurable. The role will work across multiple portfolio initiatives rather than a single technology program. As a start, Microsoft 365 A5 is one major project within the portfolio, alongside other initiatives such as Enterprise IAM, cloud security posture improvement, security operations integration, network security and segmentation, cyber exposure reduction, and related security modernization efforts. The engineer is expected to remain personally hands-on in design, configuration, integration, troubleshooting, testing, remediation, and knowledge transfer while providing technical direction to partners and internal teams.

Responsibilities
  • Own cloud security architecture and engineering activities across assigned initiatives within the Cybersecurity Transformation Program, from design through implementation, stabilization, and operational handover.
  • Assess Azure, Microsoft 365, hybrid, and where relevant multicloud environments to identify security gaps, technical dependencies, and opportunities for control improvement.
  • Design and implement secure cloud architectures aligned with KAUST security principles, enterprise architecture standards, operational requirements, and Zero Trust objectives.
  • Provide hands-on engineering across Microsoft Entra ID, Conditional Access, Privileged Identity Management, Identity Protection, MFA and passwordless controls, Intune, Defender XDR, Defender for Cloud, Microsoft Sentinel, Microsoft Purview, and related Microsoft security capabilities.
  • Engineer and improve cloud security posture management, workload protection, attack-path reduction, logging, monitoring, and security configuration across IaaS, PaaS, SaaS, endpoint, and identity environments.
  • Design and implement integrations between cloud platforms and Security Operations, including SIEM/SOAR telemetry, detection use cases, KQL analytics, incident automation, threat intelligence, and operational monitoring requirements.
  • Apply Zero Trust principles across identity, privileged access, endpoints, applications, network access, collaboration, and data, ensuring controls operate coherently across cloud and hybrid dependencies.
  • Develop secure connectivity and access patterns for cloud and hybrid environments, working with network security teams on segmentation, firewalling, secure remote access, private connectivity, DNS, and related controls where required.
  • Lead technical design decisions, configuration reviews, proof-of-concept activities, testing, troubleshooting, and remediation for assigned cloud security initiatives.
  • Review and challenge designs proposed by Microsoft, cloud providers, and delivery partners; ensure technical proposals meet KAUST security, architecture, resilience, logging, and operational standards.
  • Lead or support migration and modernization activities from legacy security platforms to cloud-native capabilities, ensuring sequencing, coexistence, rollback, and operational continuity are addressed.
  • Manage technical dependencies with Enterprise IAM, Saviynt IGA, Network Security and Segmentation, Cyber Exposure Reduction, Security Operations, endpoint management, infrastructure, and application teams.
  • Contribute technical leadership to the Microsoft 365 A5 project, including architecture, security configuration, Defender, Entra, Intune, Purview, Security Operations integration, Copilot security controls, testing, pilot readiness, and technical handover as assigned.
  • Define technical acceptance criteria, validation evidence, security baselines, implementation standards, and production-readiness requirements for assigned initiatives.
  • Proactively identify architecture risks, misconfigurations, security gaps, implementation blockers, and vendor dependencies, and drive them to resolution with clear ownership and escalation.
  • Produce high-quality as-built designs, configuration standards, engineering documentation, runbooks, operational procedures, and knowledge-transfer materials.
  • Upskill internal technical teams through pairing, technical walkthroughs, design reviews, troubleshooting, and structured knowledge transfer so implemented capabilities can be sustainably operated by KAUST.
Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Engineering, or a closely related discipline; substantial equivalent professional experience may be considered.
  • Advanced Microsoft certifications in Azure architecture, security, identity, Microsoft 365 security, or security operations are strongly preferred.
  • Relevant cloud or cybersecurity certifications such as CISSP, CCSP, GIAC cloud security, Microsoft Security certifications, Google/AWS security certifications, or equivalent are advantageous.
  • Certifications should support, not substitute for, demonstrable hands-on enterprise cloud security engineering and implementation experience.
Required Skills
  • Deep hands-on cloud security engineering expertise across Microsoft Azure and Microsoft 365, with the ability to move comfortably between architecture, configuration, integration, troubleshooting, and operationalization.
  • Strong knowledge of Microsoft security technologies including Entra ID, Conditional Access, PIM, Identity Protection, Defender XDR, Defender for Cloud, Intune, Microsoft Sentinel, and Microsoft Purview.
  • Strong understanding of cloud security architecture across identity, network, endpoint, workloads, applications, data, logging, monitoring, and security operations.
  • Practical experience designing and implementing Zero Trust architectures and identity-centric security controls in enterprise environments.
  • Strong understanding of SIEM/SOAR, detection engineering, KQL or comparable query languages, security telemetry onboarding, incident automation, and SOC integration.
  • Experience with cloud security posture management, workload hardening, attack-path analysis, secure configuration baselines, and remediation across IaaS, PaaS, and SaaS.
  • Ability to design secure hybrid and, where relevant, multicloud integrations, including federation, SSO, network connectivity, logging, and security control alignment.
  • Strong technical governance and engineering judgment, including the ability to challenge vendor designs and translate security requirements into practical implementation decisions.
  • Ability to lead multidisciplinary technical teams and delivery partners without losing hands-on engagement in critical technical work.
  • Strong written and verbal communication, including the ability to explain technical risks, architecture decisions, and delivery implications to both technical and senior stakeholders.
  • Evidence-led and outcome-oriented approach, with emphasis
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Domain Architect
Cyber Security Domain Architect

Lever, Inc. • Saudi Arabia

Remote
SAR 650,000 - 900,000
Fully remote
Enterprise impact
Azure/VMware focus
+3
Cloud Security & Zero Trust Lead Engineer
Cloud Security & Zero Trust Lead Engineer

KAUST (King Abdullah University of Science and Technology) • Thuwal

On-site
SAR 320,000 - 520,000
Cybersecurity / Security Architect
Cybersecurity / Security Architect

Jodayn • Riyadh

On-site
SAR 300,000 - 420,000
Systems Security Lead
Systems Security Lead

Secure Maximum Company • Riyadh

On-site
SAR 280,000 - 360,000
Cloud Architect
Cloud Architect

Emkan Holding • Al Khobar

On-site
SAR 980,000 - 1,320,000
Cloud Architect
Cloud Architect

Jodayn • Riyadh

On-site
SAR 350,000 - 520,000
Cloud Engineer
Cloud Engineer

Cyberani by aramco digital • Riyadh

On-site
SAR 180,000 - 300,000
Cloud Expert/Architect (with GCP)
Cloud Expert/Architect (with GCP)

Your ITeams Sp. z o.o. • Riyadh

On-site
SAR 300,000 - 540,000
Stable employment
Flexible working hours
Annual Training & Development Budget
+4
Senior Security Engineer - (Saudi National)- Riyadh, KSA
Senior Security Engineer - (Saudi National)- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 210,000 - 330,000
Cyber Security Specialist
Cyber Security Specialist

Sahm Capital • Riyadh

On-site
SAR 180,000 - 240,000