Masdr provides integrated digital data and business solutions to public and private sector organizations, enabling operational efficiency, enhanced customer experience, data-driven decision-making, and compliance with regulatory and cybersecurity requirements through advanced digital technologies and enterprise platforms.
Job Purpose
Lead and directly execute the administration, operation, and continuous improvement of enterprise systems, identity platforms, digital workplace technologies, endpoint governance, and messaging security. The role is responsible for ensuring secure, reliable, and scalable operations while acting as the hands‑on technical owner during the initial phase, establishing operational standards, technical foundations, and service maturity as the organization grows.
Generic Accountabilities:
Leadership & Technical Direction
- Provide hands‑on technical leadership for the Cybersecurity Operations function.
- Plan, prioritize, and oversee cybersecurity operational activities.
- Mentor team members and promote technical excellence and knowledge sharing.
Operational Excellence
- Establish and continuously improve cybersecurity operational processes, standards, procedures, and documentation.
- Ensure the effective and reliable delivery of cybersecurity services.
- Collaborate with internal stakeholders to implement and maintain cybersecurity capabilities.
- Provide technical oversight of external vendors, managed security service providers (MSSPs), and implementation partners.
Audit & Compliance Support
- Support audits by providing technical evidence and coordinating the remediation of technical findings.
- Maintain documentation supporting compliance with applicable security and regulatory requirements.
Performance & Continuous Improvement
- Monitor operational performance, report key cybersecurity metrics, and drive continuous improvement initiatives.
Job‑Specific Accountabilities:
Security Operations
- Lead and actively participate in daily cybersecurity operations.
- Develop and maintain operational procedures, playbooks, and response workflows.
SIEM & Security Monitoring
- Design, implement, administer, and maintain the enterprise SIEM platform.
- Develop detection rules, dashboards, alerts, and monitoring use cases.
- Monitor, investigate, and respond to security events.
EDR / XDR
- Deploy, configure, administer, and maintain enterprise EDR/XDR solutions.
- Investigate endpoint threats and coordinate containment and recovery.
- Lead technical investigation and response to cybersecurity incidents.
- Perform root cause analysis and coordinate containment, eradication, recovery, and remediation.
- Maintain and test incident response plans and procedures.
Threat Monitoring & Threat Hunting
- Perform proactive threat monitoring and threat hunting activities.
- Analyze threat intelligence and identify indicators of compromise (IOCs) and emerging threats.
Security Operations Center (SOC)
- Coordinate internal or outsourced SOC operations.
- Review escalated incidents and ensure compliance with operational service levels.
Identity & Privileged Access Management (IAM/PAM)
- Design, implement, administer, and maintain Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions.
- Manage privileged accounts, authentication, authorization, credential protection, and privileged session monitoring.
- Ensure compliance with identity and privileged access policies.
Vulnerability Management
- Implement, administer, and maintain enterprise vulnerability management solutions.
- Perform vulnerability scanning, assessments, risk prioritization, and remediation validation.
Security Hardening
- Implement and maintain security baselines across enterprise infrastructure, operating systems, databases, virtualization platforms, cloud platforms, and network devices.
- Validate compliance with approved hardening standards and security baselines.
Technical Security Controls
- Design, implement, administer, and maintain enterprise technical security controls, including MFA, endpoint protection, encryption, secure remote access, certificate management, logging, monitoring, network security, and application security controls.
- Ensure security technologies are securely configured and maintained.
Security Assessments
- Perform technical security assessments, configuration reviews, and security validation activities.
- Support penetration testing and coordinate remediation of identified security findings.
- Assess new technologies and solutions to ensure security requirements are incorporated before deployment.
Operational Readiness & Reporting
- Maintain cybersecurity operational documentation, runbooks, technical procedures, and recovery plans.
- Support disaster recovery exercises, technical audits, and compliance assessments.
- Produce operational reports, dashboards, KPIs, and security metrics.
Job Requirements:
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
- Professional cybersecurity certifications (e.g., CISSP, Security+, CySA+, GCIH, or equivalent).
Experience
Minimum 5–6 years of progressive experience in Cybersecurity Operations, Information Security, or Security Engineering.
Minimum 3 years of hands‑on experience implementing and administering enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, Vulnerability Management, and Security Monitoring.
Experience leading cybersecurity operations, incident response, and security engineering initiatives.
- Experience working in enterprise or cloud environments and coordinating with internal teams, vendors, and managed security service providers (MSSPs).