Security Supervisor Jobs in UAE
10881 Jobs Found
About The Role<br><br>Development experience in C#, C++ or Java preferred but not required<br><br>Embedded system, firmware and IoT security preferred but not required<br><br>Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE) or Offensive Security Web Expert (OSWE) certification preferred but not required.<br><br>Cloud Security Experience Preferred<br><br>Travel up to 10% domestic and international<br><br>Requirements<br><br>The Product Security Engineer is responsible for creating and implementing cutting-edge security solutions and infrastructures that will ensure our client products are secure and resilient.<br><br>This role provides the opportunity to work cross-functionally with a variety of stakeholders including product development teams and contribute to product security deliverables and activities<br><br>Support developers of our business units in their SDLC and provide guidance regarding mitigations to emerging threats and remediation planning.<br><br>Participate in building security champions within product and R&D teams and to help mature their secure development lifecycle practices.<br><br>Collaborate effectively with cross functional teams including, R&D Quality, Manufacturing and Regulatory to achieve security risk reduction.<br><br>Develop security training and deliver to internal development teams and other stakeholders.<br><br>Evaluation of new security tools and technologies and build internal tools as needed.<br><br>Perform security tools integration such as Static Code Analysis (SAST), Software Composition Analysis (SCA) and Dynamic Application Security Testing (DAST) tools.<br><br>Other duties and responsibilities as required to support the changing security needs of the organization.<br><br>Have knowledge of industry standards and frameworks such as OWASP, NIST, SANS, MITRE ATT&CK, etc.<br><br>Strong interpersonal and communication skills<br><br>Strong technical writing and presentation skills<br><br>About The Company<br><br>At AMD, we are dedicated to safeguarding our client against cyber threats. We recognize the distinct requirements and vulnerabilities of each enterprise, which is why we offer tailor-made solutions to shield your data and assets effectively.<br><br>Our collaborative approach involves working closely with clients to devise a holistic cybersecurity strategy that harmonizes with their specific business objectives.
The Senior Manager of Governance is responsible for developing the information security and cybersecurity strategy and plan. This role aims to protect DET’s Information assets from risks, threats, and attacks by establishing robust security policies and aligning them with local and federal mandates, such as those from the Dubai Cyber Security Strategy and the Dubai Electronic Security Center.<br>The responsibilities include managing policy implementation, managing risk assessments, delivering training programs, and ensuring compliance across all technology platforms. Conducting investigations on information security policy breaches and recommending solutions. Coordinating with regulatory bodies and stakeholders to maintain and report on DET’s security posture, ensuring a secure operational environment.<br>Core Functional Responsibilities Develop the DET Group’s information security and cybersecurity strategy and plan in order to mitigate risks, attacks, and threats on the data assets of the DET Group. Design and manage new programs, projects, initiatives, and enhancement and implementation roadmap to strengthen the DET security. Manage the Information Security governance process including Policy and Standards across the DET. Ensure the alignment of the DET Group’s information security and cybersecurity strategy with local and federal strategies, such as the Dubai Cyber Security Strategy, and other requirements set by DESC. Additionally, maintain compliance with the ISO 27001:2022 standard to uphold international best practices in information security management alongside the ISR. Develop and implement of information security and cybersecurity policies, procedures, and standards for the DET Group, ensuring alignment with the ISR as well as leading practices and trends. Manage the provision of awareness and training sessions and program to all employees, leaders, strategic partners, etc. on information security and cyber security policies, to mitigate potential policy breaches. Conduct thorough and ongoing audits to ensure all employees, leaders, and strategic partners strictly adhere to DET's information security and cybersecurity policies. This includes verifying system access compliance, facilitating cybersecurity training, assessing risks, and maintaining detailed audit trails for continuous improvement and accountability. Provide support as needed, to manage any exceptions or deviations from information security and cybersecurity policies. Manage the implementation of information and cybersecurity risk assessments on DET Group, in order to gain intelligence on information security and cyber threats and risks DET is vulnerable to, based on its operations and its IT infrastructure components including applications, cloud, cryptography, and infrastructure, and accordingly recommend risk mitigation measures. Manage investigations on information security policy breaches conducted internally or through external parties, ensure policy breaches are being accurately reported, and accordingly identify solutions to policy breaches. Develop reports pertaining to information security and cybersecurity risk assessments results, as well as incidents related to information security. Ensure reports are being circulated to relevant stakeholders, and manage the delivery of presentations to the Director General as well as the Information Security Committee, as needed. Provide guidance and advice to end users, when needed, regarding potential threats and key considerations for the safe usage of systems and exchange of information. Provide guidance and subject matter expertise when it comes to the enhancement of information security controls, in coordination with the Technology team as well as IT vendors.
About UsAI71 is an applied research team dedicated to creating helpful and responsible AI agents for knowledge workers. Working closely with our industry partners, our cross-functional teams of AI experts build products grounded in the cutting edge research of our colleagues from the Technology Innovation Institute (TII). We are seeking a highly experienced and strategic Security Architect to define and lead the security architecture of our AI and data platform. In this role, you will be responsible for designing secure-by-design systems across AI workloads, data pipelines, and cloud-native infrastructure, ensuring the confidentiality, integrity, and availability of our platform at scale. You will collaborate closely with engineering, platform, and AI teams to embed security into every layer of system design, development, and deployment, while establishing standards and best practices aligned with enterprise and high-security environments.<br><br>Key Responsibilities Security Architecture and Design<br><br> Define and evolve the end-to-end security architecture for AI systems, data platforms, and cloud-native infrastructure. Establish and enforce Zero Trust principles, including identity-first security, m TLS, and fine-grained access control (RBAC/ABAC). Design secure patterns for distributed systems, event-driven architectures, and multi-tenant environments. Platform and Infrastructure Security Define security standards for Kubernetes-based platforms, including workload isolation, network policies, and runtime protection. Establish container and software supply chain security practices (e.g., image scanning, SBOM, signing, and provenance). Design secure deployment architectures for both cloud and restricted/air-gapped environments. AI and Data Security Define and implement security controls for LLM-based applications, RAG pipelines, and data platforms. Establish safeguards against AI-specific threats such as data poisoning, model extraction, and data leakage. Dev Sec Ops and Governance Embed security into Git Ops and CI/CD workflows, including policy-as-code and automated enforcement. Define and maintain secure SDLC practices aligned with ISO 27001 and internal governance frameworks. Lead threat modeling, architecture reviews, and security validations. Observability and Threat Detection Define requirements for security observability, including audit logging and anomaly detection. Ensure integration of security signals into observability platforms (e.g., Open Telemetry). Leadership and Collaboration Act as a security advisor to engineering and AI teams. Review system designs and enforce security standards. Mentor engineers and promote a strong culture of security awareness. Qualifications<br><br>Required Skills and Experience<br><br> Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field. 7+ years of experience in security engineering, architecture, or related roles. Experience designing security for distributed systems and cloud-native platforms. Strong understanding of Zero Trust, IAM, cryptography, and secure communication. Experience with Dev Sec Ops practices and secure CI/CD pipelines. Preferred Skills Experience securing AI/ML systems or data platforms. Familiarity with streaming technologies (e.g., Kafka, NATS). Experience in regulated or high-security environments. Certifications such as CISSP or CSSLP. Proficiency in Python or Bash for automation. Why Join Us? Work on cutting-edge AI technologies with a focus on security and ethics. Shape the security architecture of a next-generation AI platform. Collaborate with a diverse and talented team. Competitive salary, equity options, and benefits. Opportunities for growth and leadership.
Career Area:<br><br>Business Services<br><br>Job Description:<br><br>Your Work Shapes the World at Caterpillar Inc. <br><br>When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here – we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.<br><br>Lead Global Security. Protect Our People. Strengthen Business Resilience.<br><br>Solar Turbines is seeking an accomplished Global Security Manager to lead and advance our worldwide security strategy, protecting our people, facilities, assets, information, reputation, and operations across a complex global environment. This senior leadership role provides strategic direction for enterprise security, workplace violence prevention, crisis management, investigations, business resilience, and risk management while partnering closely with executive leadership, Legal, Human Resources, EHSS, and Caterpillar Global Security.<br><br>WHAT YOU WILL DO:<br><br>Global Security Leadership<br><br> Develop and execute a comprehensive global security strategy aligned with business objectives. Lead and support Regional Security Managers, Facility Security Managers, and technical specialists. Drive compliance with the Risk-Based Security Program and governance standards. Build strong partnerships with executive leadership, Legal, HR, EHSS, and Caterpillar Global Security.<br><br>Security Risk Management & Asset Protection<br><br> Conduct enterprise-wide security risk assessments and threat analyses. Identify significant security risks and implement mitigation strategies. Design and oversee multi-layered approaches to employee, facility, information, and asset protection. Monitor emerging global risks, industry trends, and security technologies.<br><br>Investigations & Compliance<br><br> Collaborate on and implement investigative strategies while maintaining attorney-client privilege and confidentiality. Collect and analyze facts within approved investigative scopes. Review allegations and establish investigative requirements. Lead complex internal investigations and forensic reviews. Partner with Legal, HR, and Compliance leaders on policy violations and security concerns.<br><br>Crisis Management & Business Resilience<br><br> Lead development and execution of global crisis management and emergency response programs. Establish and strengthen Regional Incident Management Teams. Coordinate crisis response and executive communications. Develop tabletop exercises and preparedness programs.<br><br>Employee & Workplace Security<br><br> Lead workplace violence prevention, threat assessment, and response programs. Promote security awareness and training initiatives. Ensure employee safety, travel security, and duty-of-care compliance.<br><br>Premises Security & Global Operations<br><br> Direct physical security programs for offices, manufacturing sites, and warehouses. Conduct physical security audits and assessments. Maintain relationships with law enforcement, government agencies, and emergency responders.<br><br>WHAT YOU WILL HAVE:<br><br> Degree or equivalent experience in Security, Risk, Crisis Management, Criminal Justice, or related field. 10+ years of leadership experience in corporate security, law enforcement, military, intelligence, or emergency services. Experience leading global security, crisis management, and risk programs. Fluent written and spoken English.<br><br>Preferred<br><br> Master's degree in Crisis Management, Security Management, or related discipline. CPP, PSP, SRMC, NEBOSH, or equivalent certification. Experience in manufacturing, industrial, energy, or oil and gas environments.<br><br>Reports To: VP, Global Process Excellence<br><br>Travel: Up to 50% Global Travel<br><br>Why Join Us<br><br>This is a unique opportunity to shape and lead the global security strategy of a world-class organization while protecting people, assets, operations, and reputation worldwide.<br><br>This position requires working onsite five days a week.<br><br>Relocation is available for this position.<br><br>Visa Sponsorship is not available for this position.<br><br>Posting Dates:<br><br>Caterpillar is an Equal Opportunity Employer. Qualified applicants of any age are encouraged to apply<br><br>Not ready to apply? Join our Talent Community.
We are looking for a Network Security Specialist to support the implementation, administration, and operation of enterprise network security solutions. The role focuses on firewall management, VPN operations, security policy implementation, troubleshooting, and maintaining secure network environments. The successful candidate will work closely with network and security teams to ensure reliable and secure connectivity across enterprise infrastructure.<br>Key Responsibilities Configure, manage, and support enterprise firewall platforms including Fortinet, Palo Alto Networks, and Cisco ASA. Perform firewall policy updates, rule reviews, NAT configuration, and security policy optimisation. Configure and support SSL VPN and IPSec VPN solutions. Monitor network security events and support incident investigation and response activities. Troubleshoot firewall, VPN, connectivity, and security-related issues. Assist with firewall upgrades, migrations, patches, and configuration improvements. Maintain network security documentation, operational procedures, and configuration records. Support security audits, compliance activities, and change management processes.<br>Required Skills & Experience5–6 years of experience in network security operations. Hands-on experience managing firewall technologies such as Fortinet Forti Gate, Palo Alto Networks firewalls, or Cisco ASA. Strong understanding of firewall concepts, security policies, NAT, routing, SSL VPN, and IPSec VPN. Experience performing firewall configuration changes, troubleshooting, and security rule management. Exposure to security management platforms such as Forti Manager, Forti Analyzer, or Panorama. Understanding of IDS/IPS technologies and network security monitoring. Relevant certifications such as Fortinet certifications, PCNSA/PCNSE, CCNA, or CCNP.<br>Preferred Skills Experience with cloud firewall technologies and hybrid network environments. Familiarity with ITSM tools, incident management, and change management processes. Strong documentation, communication, and troubleshooting skills.
We are looking for a Network Security Specialist to support the implementation, administration, and operation of enterprise network security solutions. The role focuses on firewall management, VPN operations, security policy implementation, troubleshooting, and maintaining secure network environments. The successful candidate will work closely with network and security teams to ensure reliable and secure connectivity across enterprise infrastructure.<br>Key Responsibilities Configure, manage, and support enterprise firewall platforms including Fortinet, Palo Alto Networks, and Cisco ASA. Perform firewall policy updates, rule reviews, NAT configuration, and security policy optimisation. Configure and support SSL VPN and IPSec VPN solutions. Monitor network security events and support incident investigation and response activities. Troubleshoot firewall, VPN, connectivity, and security-related issues. Assist with firewall upgrades, migrations, patches, and configuration improvements. Maintain network security documentation, operational procedures, and configuration records. Support security audits, compliance activities, and change management processes.<br>Required Skills & Experience5–6 years of experience in network security operations. Hands-on experience managing firewall technologies such as Fortinet Forti Gate, Palo Alto Networks firewalls, or Cisco ASA. Strong understanding of firewall concepts, security policies, NAT, routing, SSL VPN, and IPSec VPN. Experience performing firewall configuration changes, troubleshooting, and security rule management. Exposure to security management platforms such as Forti Manager, Forti Analyzer, or Panorama. Understanding of IDS/IPS technologies and network security monitoring. Relevant certifications such as Fortinet certifications, PCNSA/PCNSE, CCNA, or CCNP.<br>Preferred Skills Experience with cloud firewall technologies and hybrid network environments. Familiarity with ITSM tools, incident management, and change management processes. Strong documentation, communication, and troubleshooting skills.
Job Description<br><br>At WSP, our Security Risk Management team delivers comprehensive design and advisory services to protect people, assets, and operations. We specialize in Security Threat and Risk Assessments, Project Security Briefs, and Security Strategies tailored to the unique needs of each project.<br><br>We are seeking a Senior Security Consultant to join our growing team. This is an exciting opportunity to work on landmark developments and critical infrastructure projects across the region, influencing how security integrates into world-class built environments.<br><br>Responsibilities<br><br> Represent WSP’s Security Risk Management team with clients and stakeholders. Lead and deliver security risk assessments, strategic design work, and audits of existing facilities. Collaborate with multi-disciplinary teams to integrate security into complex built environment projects. Mentor junior team members and contribute to knowledge sharing. Support business development by identifying opportunities, attending client meetings, and converting leads into project wins. <br><br><br>Qualifications<br><br> Bachelor’s degree in Security Risk Management, Physical Security Engineering, or Business Administration (MBA preferred). 5+ years’ experience in physical security within the built environment and or management consulting. Professional certifications such as CPP, PSP, or CSC (highly desirable). Proven track record delivering high-profile projects across commercial, mixed-use, residential, and critical infrastructure sectors. Strong client engagement and business development skills. Proficiency in industry-standard tools (e.g., BIM).
Job Description<br><br>At WSP, our Security Risk Management team delivers comprehensive design and advisory services to protect people, assets, and operations. We specialize in Security Threat and Risk Assessments, Project Security Briefs, and Security Strategies tailored to the unique needs of each project.<br><br>We are seeking a Senior Security Consultant to join our growing team. This is an exciting opportunity to work on landmark developments and critical infrastructure projects across the region, influencing how security integrates into world-class built environments.<br><br>Responsibilities<br><br> Represent WSP’s Security Risk Management team with clients and stakeholders. Lead and deliver security risk assessments, strategic design work, and audits of existing facilities. Collaborate with multi-disciplinary teams to integrate security into complex built environment projects. Mentor junior team members and contribute to knowledge sharing. Support business development by identifying opportunities, attending client meetings, and converting leads into project wins. <br><br><br>Qualifications<br><br> Bachelor’s degree in Security Risk Management, Physical Security Engineering, or Business Administration (MBA preferred). 5+ years’ experience in physical security within the built environment and or management consulting. Professional certifications such as CPP, PSP, or CSC (highly desirable). Proven track record delivering high-profile projects across commercial, mixed-use, residential, and critical infrastructure sectors. Strong client engagement and business development skills. Proficiency in industry-standard tools (e.g., BIM).
Job Description<br><br>At WSP, our Security Risk Management team delivers comprehensive design and advisory services to protect people, assets, and operations. We specialize in Security Threat and Risk Assessments, Project Security Briefs, and Security Strategies tailored to the unique needs of each project.<br><br>We are seeking a Senior Security Consultant to join our growing team. This is an exciting opportunity to work on landmark developments and critical infrastructure projects across the region, influencing how security integrates into world-class built environments.<br><br>Responsibilities<br><br> Represent WSP’s Security Risk Management team with clients and stakeholders. Lead and deliver security risk assessments, strategic design work, and audits of existing facilities. Collaborate with multi-disciplinary teams to integrate security into complex built environment projects. Mentor junior team members and contribute to knowledge sharing. Support business development by identifying opportunities, attending client meetings, and converting leads into project wins. <br><br><br>Qualifications<br><br> Bachelor’s degree in Security Risk Management, Physical Security Engineering, or Business Administration (MBA preferred). 5+ years’ experience in physical security within the built environment and or management consulting. Professional certifications such as CPP, PSP, or CSC (highly desirable). Proven track record delivering high-profile projects across commercial, mixed-use, residential, and critical infrastructure sectors. Strong client engagement and business development skills. Proficiency in industry-standard tools (e.g., BIM).
Job Description<br><br>At WSP, our Security Risk Management team delivers comprehensive design and advisory services to protect people, assets, and operations. We specialize in Security Threat and Risk Assessments, Project Security Briefs, and Security Strategies tailored to the unique needs of each project.<br><br>We are seeking a Senior Security Consultant to join our growing team. This is an exciting opportunity to work on landmark developments and critical infrastructure projects across the region, influencing how security integrates into world-class built environments.<br><br>Responsibilities<br><br> Represent WSP’s Security Risk Management team with clients and stakeholders. Lead and deliver security risk assessments, strategic design work, and audits of existing facilities. Collaborate with multi-disciplinary teams to integrate security into complex built environment projects. Mentor junior team members and contribute to knowledge sharing. Support business development by identifying opportunities, attending client meetings, and converting leads into project wins. <br><br><br>Qualifications<br><br> Bachelor’s degree in Security Risk Management, Physical Security Engineering, or Business Administration (MBA preferred). 5+ years’ experience in physical security within the built environment and or management consulting. Professional certifications such as CPP, PSP, or CSC (highly desirable). Proven track record delivering high-profile projects across commercial, mixed-use, residential, and critical infrastructure sectors. Strong client engagement and business development skills. Proficiency in industry-standard tools (e.g., BIM).
Join our team and play a key role in maintaining EKFC's strong cybersecurity posture. The Cybersecurity Specialist will contribute to threat mitigation, risk management, and the protection of our digital assets, ensuring the security and resilience of our technology environment.<br>Key responsibilities:Conduct regular security and vulnerability assessments to identify and evaluate potential risks to information systems. Develop and implement effective incident response plans through established protocols to minimize damage and recovery time. Develop, implement, and enforce security policies, procedures and controls to protect the organization’s assets and ensure compliance with relevant regulations and standards (e.g., ISO27001, ISR, ICS and NESA). Monitor network traffic for suspicious activities for maintaining a secure environment and early threat detection Conduct security awareness training for employees to promote best practices for data security throughout the organization Conduct regular code reviews and penetration testing of various cybersecurity systems and applications for identifying vulnerabilities and improving software quality. Use security information and event management (SIEM) tools to provide a centralized view of security-related data and simplify monitoring and analysis. Prepare regular reports on security status and incidents for ongoing monitoring and review of compliance efforts. Collaborate with IT teams to secure infrastructure and applications tailored to the organization’s specific needs. Provide input on security implications for new projects or systems to ensure security considerations are integrated into the design and implementation phase.<br>Education Qualifications:Bachelor’s degree in computer science, Maths etc or equivalent Professional certifications in Cybersecurity (Comp TIA Security+, Certified Ethical Hacker (CEH), Comp TIA Cybersecurity Analyst (CySA+)<br>Work Experience: Minimum 5 years of IT Experience with extensive focus on IT Security covering IT Audit, IT Risk and Cybersecurity Must have worked in Information Security/Risk in a Global organisation with Complex/Hybrid IT Environment Strong knowledge of IT Infrastructure – both On Premise and Cloud, BYOD, Application development etc. Must have followed IT GRC Methodologies<br>Skills:Strong problem solving, analytical and time management skills Security Frameworks - ISO2700130000/CIS Critical security controls, NESA etc. Vulnerability Assessment and Penetration Testing (VAPT) IT Security/Cybersecurity ITSM and COBIT skills Strong interpersonal and communication skills.
Overview<br><br>M42 is a global health champion powered by artificial intelligence (AI), technology and genomics to advance innovation in health for people and the planet. Headquartered in Abu Dhabi, M42 combines its specialized, state-of-the-art facilities with integrated health solutions like genomics and biobanks, and harnesses advanced technologies to deliver precise, preventive and predictive care, to disrupt traditional healthcare models and positively impact lives globally.<br><br>The role is responsible for developing, implementing, and maintaining an Information Security Framework, including policies, standards, and processes aligned with international best practices and regulatory requirements. The position plays a critical role in managing information security risks, ensuring regulatory compliance, overseeing security projects, responding to incidents, and strengthening security awareness across the organization. The role will also evaluate and supervise information security controls, develop security metrics, and build strong relationships with internal and external stakeholders to support M42’s healthcare objectives.<br><br>Responsibilities<br><br>Develop, implement, and maintain an enterprise-wide Information Security Framework aligned with international standards (e.g., ISO 27001, ISO 27701, HIPAA) and regulatory requirements (e.g., ADHICS, ADGM, GDPR, NESA). Define and execute the information security and compliance strategy in alignment with M42 objectives, recommending appropriate controls, tools, and technologies. Establish and operate a healthcare-focused information security risk management framework aligned with M42 enterprise risk management practices. Conduct technology risk assessments for new business initiatives and IT projects, including driving Risk Control Self-Assessments (RCSA). Ensure appropriate management visibility of security risks, including impact, mitigation plans, and associated costs. Perform regulatory gap analysis, industry benchmarking, and control maturity assessments to identify improvement opportunities. Develop, monitor, and report information security and IT risk metrics, including KRIs and KPIs. Lead the planning and delivery of information security initiatives and projects in line with regulatory and business requirements. Investigate, manage, and respond to information security and data privacy incidents, including maintaining and testing the incident response plan. Oversee the implementation, monitoring, and effectiveness of information security and IT controls across the healthcare environment. Coordinate with IT GRC, internal audit, and external audit teams to implement regulatory and audit recommendations. Manage regulatory submissions (including ADHICS) and remediate identified compliance gaps. Direct internal teams and external service providers to ensure the protection of information assets and adherence to security policies and standards. Build strong relationships with key stakeholders across M42 IT and Healthcare functions and represent Information Security in internal and external audits.<br><br>Qualifications<br><br>Bachelor’s or Master’s degree in IT, Computer Science, Software Engineering, or a related field.5-10 years of professional experience in Information Security, with a minimum of 5 years within the healthcare industry. Proven experience in information security governance, risk management, compliance, and security operations. Strong knowledge of healthcare and data protection regulations (e.g., ADHICS, HIPAA, GDPR, HITRUST, DOH). Hands-on experience conducting technology risk assessments and Risk Control Self-Assessments (RCSA). Solid understanding of international security standards and frameworks (e.g., ISO 27001, ISO 27701). Experience working with cloud security architectures and cloud service models. Excellent written and verbal communication skills, with the ability to explain security and risk concepts to technical and non-technical audiences. Strong stakeholder management skills, including engagement with senior leadership, auditors, and regulators. Relevant industry certifications such as CISA, CISM, CISSP, CCSP, or cloud security certifications (Azure/AWS). Experience working in the UAE or similar regulated healthcare environments (preferred). ITIL v4 certification (preferred).
Responsibilities<br><br> JOB DESCRIPTION <br><br>You Will Help Deliver High-quality Client Engagements By<br><br>Understanding clients’ business challenges, cloud ambitions, regulatory requirements, and threat landscape Advising clients on secure cloud adoption, lift-and-shift migration, and landing zone security design Designing and implementing security controls across Azure landing zones, including identity, networking, logging, governance, encryption, workload protection, and monitoring Supporting security architecture across Azure, Microsoft 365, AWS, and OCI environment Helping clients navigate cybersecurity regulations, security frameworks, and cloud compliance requirements Advising on cloud security governance, operating models, control frameworks, and risk management Assessing existing cloud environments against security baselines such as CIS, NIST, ISO, CAF, and cloud provider best practices Helping clients optimize their digital and technical security controls across multiple layers of the cloud architecture stack Using security architecture to define and support broader security transformation programs Delivering automation of security controls, security posture reporting, and risk dashboards where relevant Supporting small and medium-sized engagements independently and participating as a key team member in larger transformation programs Supporting presales, proposal development, and business development activities Building constructive and trusted relationships with clients, both at technical and senior stakeholder level Acting as a trusted advisor and role model for quality, integrity, and risk management practices Contributing to the continued development of KPMG’s cloud security services and professional network<br><br>The Person<br><br>We are looking for someone with a strong track record in cloud security architecture and consulting, with the ability to combine hands-on technical experience with strong client advisory skills.<br><br>The Ideal Candidate Should Have<br><br>Proven experience in cloud security architecture, preferably with strong hands-on experience in Microsoft Azure and Microsoft 365Practical experience with secure cloud migration, lift-and-shift scenarios, and Azure landing zone design or implementation Strong understanding of Azure landing zone security, including management groups, subscriptions, RBAC, Azure Policy, Defender for Cloud, logging, network security, private endpoints, Key Vault, backup, and workload protection Experience assessing, designing, or implementing security controls across multiple layers of the IT architecture stack Strong knowledge of Identity and Access Management, including Microsoft Entra ID, Conditional Access, Privileged Identity Management, workload identities, and identity governance Experience with cloud security assessments, security configuration reviews, privacy and regulatory risk assessments, and control framework mapping Experience with Dev Sec Ops concepts, infrastructure-as-code, policy-as-code, security automation, and continuous control monitoring is highly desirable Experience delivering cybersecurity services in a commercial or consulting environment Experience in one or more cloud service provider environments: Microsoft Azure, AWS, OCI, or GCPAbility to analyze complex problems, identify core issues, and recommend practical and proportionate solutions Ability to communicate clearly with both technical teams and senior stakeholders Ability to translate complex cybersecurity topics into clear business risk, impact, and remediation advice Ability to work at sustained levels of high intensity while maintaining quality, structure, and professionalism Previous Big4 experience is a must for this role<br><br>Qualifications And Certifications<br><br>The candidate should ideally have a combination of cloud, security, and architecture certifications. We do not expect every candidate to hold all certifications, but one or more of the following would be highly valued.<br><br>Microsoft Certified: Cybersecurity Architect Expert – SC-100Microsoft Certified: Cloud and AI Security Engineer Associate – SC-500Microsoft Certified: Identity and Access Administrator Associate – SC-300Microsoft Certified: Information Security Administrator Associate – SC-401Microsoft Azure architecture or administrator certifications such as AZ-104 or AZ-305 are also beneficial AWS Certified Security – Specialty AWS Certified Solutions Architect – Professional Google Cloud Professional Cloud Security Engineer CISSP, CISM, CCSP, or comparable cybersecurity experience SABSA, TOGAF, or comparable architecture experience is preferred
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>We are seeking Associate – Information Security who manages and monitors the organization’s information security framework, ensuring compliance with internal policies, regulatory standards, and industry best practices. The role supports enterprise security, data governance, risk management, and business continuity initiatives; conducts security assessments and risk reviews; monitors cybersecurity controls and KPIs; and identifies and mitigates security risks across systems & vendors</p><ul><li>Contribute to the development, implementation, and continuous enhancement of the organization's information security governance framework, standards, and operating procedures.</li><li>Assess the effectiveness of security controls and recommend improvements to strengthen the overall cybersecurity posture across technology environments and third-party engagements.</li><li>Perform regular security reviews, control assessments, and compliance evaluations to identify risks, vulnerabilities, and opportunities for improvement.</li><li>Support the governance and oversight of information security initiatives, ensuring alignment with organizational objectives and regulatory expectations.</li><li>Review security configurations, user privileges, network controls, and infrastructure settings to verify compliance with security best practices and identify potential weaknesses.</li><li>Establish and monitor security performance indicators and risk metrics, providing meaningful reporting to support informed decision-making.</li><li>Participate in technology initiatives and transformation programs by performing security reviews, identifying potential risks, and recommending practical mitigation strategies throughout the project lifecycle.</li><li>Develop, maintain, and periodically test cybersecurity incident response capabilities to ensure effective preparation, response, and recovery from security events.</li><li>Support compliance activities related to information security, data protection, and regulatory obligations, including internal and external audit engagements.</li><li>Monitor the effectiveness of cybersecurity platforms and privileged access controls while supporting the implementation of new security technologies and continuous improvement initiatives.</li><li>Review business resilience, disaster recovery, and continuity arrangements to ensure appropriate planning, testing, and operational readiness.</li><li>Work closely with risk management and assurance functions to identify emerging cyber risks, evaluate their impact, and support the implementation of effective mitigation measures.</li><li>Evaluate security-related operational processes and internal controls, recommending enhancements to reduce exposure to cyber threats, data compromise, and operational risk.</li><li>Maintain risk documentation and follow up on mitigation plans, ensuring identified actions are tracked, monitored, and completed within agreed timelines.</li><li>Support enterprise risk, data governance, and fraud prevention initiatives by promoting consistent implementation of security and governance controls across the organization.</li><li>Deliver cybersecurity awareness sessions and promote a security-first culture through ongoing education and engagement initiatives.</li><li>Assist with maintaining compliance against recognized industry standards and regulatory frameworks, coordinating assessments, certifications, and remediation activities where required.</li><li>Stay up to date with emerging cybersecurity threats, new technologies, and industry best practices, and recommend improvements to strengthen the organization's overall security posture.</li></ul><p><br></p> </div><h2 class="h5">Skills</h2>
<div data-jb-field="skills"><p>Requirements</p><p><b>Education & Skills</b></p><ul><li>Bachelor’s degree in a related field</li><li>Master’s or specialization in Computer Science, Engineering, or IT <i>(Preferred)</i></li><li>Professional cybersecurity certification (e.g., CISSP, CCSP, CISM)</li><li>Proficient in English</li></ul><p><b>Experience & Knowledge</b></p><ul><li>3-5 years of hands-on experience in Information Security GRC, including architecture, review, and deployment of next-generation firewalls, WAFs, DLP, PAM, IAM solutions</li><li>3+ years implementing ISO standards, NIST frameworks, CIS benchmarking, and developing KPIs/KRIs</li><li>Experience with enterprise-level integrations, DevSecOps lifecycle, and Cloud platforms (Azure, AWS, GCP), API management, and microservices architecture</li><li>Ability to align information security strategies with technical projects and mitigate risks for digital transformation initiatives</li></ul><p><b>Abilities & Specific Requirements</b></p><ul><li>Must be Emirati with Family Book</li><li>Able to manage multiple priorities under pressure and meet deadlines</li><li>Works effectively and responsibly without supervision</li><li>Can execute clear strategies and corporate requirements</li><li>Adaptable to start-up or fast-paced environments; flexible and agile thinker <i>(Preferred)</i></li><li>Applies a structured, analytical approach to challenges</li><li>Demonstrates critical thinking and problem-solving capabilities</li></ul><p><br></p></div>
About Us Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.<br><br><br>The opportunity Security Engineer - Endpoint Detection & Response (Elastic EDR), Core42 - Abu Dhabi, UAE. We are seeking a highly skilled Security Engineer with hands-on expertise in the Elastic Security Platform, including Elastic Agent, Elastic Defend, Elasticsearch, Kibana, detection rules, threat hunting and incident response. The successful candidate will be responsible for designing, implementing, managing and optimising the organisation's EDR platform to ensure continuous monitoring, threat detection, incident investigation and response across enterprise environments. The role requires close collaboration with Security Operations, Incident Response, Platform Engineering, Infrastructure and Compliance teams to strengthen cyber defence capabilities and maintain security compliance requirements. The focus of this position is Elastic EDR engineering.<br>Your key responsibilities <br>Elastic EDR administration & engineering Design, deploy, configure and maintain Elastic EDR infrastructure and endpoint security agents Manage Elastic Agent lifecycle activities, including deployment, upgrades, troubleshooting and policy management Develop and maintain EDR baselines, security policies and endpoint hardening standards Ensure high availability, scalability, performance and health of the Elastic Security platform Integrate Elastic EDR with SIEM, SOAR, IAM, vulnerability management and threat intelligence platforms Upgrade, patch and maintain existing clusters<br>Detection engineering Develop, tune and maintain detection rules and security use cases within Elastic Security Enhance threat detection capabilities to reduce false positives and improve security visibility Design and implement behavioural analytics, anomaly detection and advanced threat detection logic Create custom dashboards, alerts, reports and visualisations within Kibana<br>Threat hunting & incident response Conduct proactive threat hunting activities using Elastic Security datasets Investigate endpoint security incidents, malware infections, insider threats and advanced attacks Analyse telemetry, process activities, file events, registry modifications, network connections and user behaviour Support digital forensics and incident response investigations Identify root causes and recommend mitigation strategies<br>Security monitoring & optimisation Monitor EDR platform performance, coverage and security effectiveness Perform continuous tuning of endpoint security controls Establish KPIs and operational metrics for EDR effectiveness Validate security controls through attack simulation and red team exercises<br>Integration & automation Integrate Elastic EDR with IDP, LDAP, AI and ML integrations, vulnerability management solutions, SIEM platforms, threat intelligence feeds and SOAR workflows Integrate with Open Stack, Open Shift, NVIDIA and AMD systems Automate security operations using APIs, scripts and orchestration tools<br>Governance & compliance Ensure EDR deployment aligns with NIST SP 800-53, ISO 27001, SOC 2, CIS Controls and internal security standards and policies Support audit activities and provide security evidence when required Maintain security documentation, procedures and operational runbooks<br>What we’re looking for<br> (a) Required skills / qualifications Bachelor's degree in Cyber Security, Computer Science, Information Security or a related discipline5 to 7 years of experience in security engineering, incident response, threat hunting or detection engineering Experience supporting enterprise-scale EDR deployments (10,000+ endpoints preferred) Hands-on expertise across Elastic Security, Elastic Defend, Elastic Agent, Elasticsearch and Kibana Detection rule engineering, threat hunting and log analysis Endpoint security, Windows security and Linux security MITRE ATT&CK framework, incident response and malware analysis fundamentals<br>(b) Preferred skills / qualifications Python and Bash scripting Experience with threat intelligence platforms Certifications: Elastic Certified Engineer, Elastic Security Analyst<br>What working at Core42 offers <br>With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance. We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results. <br>Competitive Salary: We offer an attractive salary package based on your skills and experience Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your family Learning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.
<p>The Information Security Specialist is responsible for safeguarding the organization’s systems, data, and technology infrastructure by implementing and maintaining effective security controls and monitoring activities.
This role supports the organization’s security and compliance objectives by identifying risks, responding to security incidents, and ensuring alignment with regulatory and industry standards.</p><p>• Monitor and respond to security incidents and alerts, supporting investigation, escalation, and resolution.
• Maintain and implement security controls to protect systems, applications, and data against internal and external threats.
• Perform security monitoring using SIEM and other security tools, analysing logs and events to identify potential threats and recommend remediation.
• Support vulnerability management activities, including identifying, prioritising, and tracking remediation of security weaknesses.
• Conduct security risk assessments and support internal and external security audits.
• Ensure compliance with security standards and regulatory requirements, including PCI-DSS.
• Implement and maintain Web Application Firewalls (WAF), DDoS protection, firewall technologies, and cloud-native security controls (e.g. Cloudflare, Akamai, Azure/AWS security services where applicable).
• Support application security throughout the software development lifecycle, including static application security testing (SAST) using tools such as Veracode, Checkmarx, Trivy or similar.
• Assist with container and cloud workload security, including Docker, Kubernetes and container image scanning.
• Perform or support penetration testing, vulnerability assessments and security validation activities using industry-standard tools (e.g. Kali Linux, Burp Suite, OWASP methodologies).
• Develop and maintain automation scripts using Python, PowerShell or Bash to improve security operations and monitoring.
• Collaborate closely with Engineering, Infrastructure, DevOps and Compliance teams to embed security into development and operational processes.
• Maintain security documentation, operational procedures and technical standards to support audit readiness and operational consistency.</p>
Role: Information Security Specialist (Remote) Location: Remote (Work from Anywhere) Job Type: Contract Payout: $60 - $100/hour<br>Role Overview:We are hiring for one of our clients, seeking an Info Sec Expert to work on a contract basis. This role will focus on maintaining robust security protocols, identifying vulnerabilities, and implementing solutions to protect sensitive data across all systems.<br>Key Responsibilities:• Conduct regular security assessments, audits, and penetration testing to identify vulnerabilities in systems and networks.• Develop and enforce security policies, procedures, and best practices to ensure compliance with industry standards and regulations.• Monitor security systems and respond to incidents, including investigating breaches and implementing corrective actions.• Collaborate with IT teams to integrate security measures into system development and deployment processes.• Provide security awareness training and guidance to employees to reduce human-related security risks.<br>Required Skills & Qualifications:• Experience with security frameworks such as NIST, ISO 27001, or CIS Controls is required.• Proficiency in vulnerability scanning tools like Nessus, Qualys, or Open VAS is required.• Knowledge of network security protocols, firewalls, and intrusion detection/prevention systems is required.• Familiarity with compliance regulations such as GDPR, HIPAA, or SOC 2 is required.• Strong analytical and problem-solving skills with the ability to interpret complex security logs and reports.<br>More About the Opportunity:This role offers a unique opportunity to work with a global leader in the Technology, Information and Internet industry, contributing to the protection of critical infrastructure and customer data. The position involves high-impact work with measurable outcomes in security risk reduction.<br>Equal Opportunity Employer:We hire based on skills and expertise. All qualified candidates are welcome regardless of background, experience, or prior employment history. Applications are reviewed solely on demonstrated technical ability and qualifications.<br>Apply Now!
Role: Information Security Specialist (Remote) Location: Remote (Work from Anywhere) Job Type: Contract Payout: $60 - $100/hour<br>Role Overview:We are hiring for one of our clients, seeking an Info Sec Expert to work on a contract basis. This role will focus on maintaining robust security protocols, identifying vulnerabilities, and implementing solutions to protect sensitive data across all systems.<br>Key Responsibilities:• Conduct regular security assessments, audits, and penetration testing to identify vulnerabilities in systems and networks.• Develop and enforce security policies, procedures, and best practices to ensure compliance with industry standards and regulations.• Monitor security systems and respond to incidents, including investigating breaches and implementing corrective actions.• Collaborate with IT teams to integrate security measures into system development and deployment processes.• Provide security awareness training and guidance to employees to reduce human-related security risks.<br>Required Skills & Qualifications:• Experience with security frameworks such as NIST, ISO 27001, or CIS Controls is required.• Proficiency in vulnerability scanning tools like Nessus, Qualys, or Open VAS is required.• Knowledge of network security protocols, firewalls, and intrusion detection/prevention systems is required.• Familiarity with compliance regulations such as GDPR, HIPAA, or SOC 2 is required.• Strong analytical and problem-solving skills with the ability to interpret complex security logs and reports.<br>More About the Opportunity:This role offers a unique opportunity to work with a global leader in the Technology, Information and Internet industry, contributing to the protection of critical infrastructure and customer data. The position involves high-impact work with measurable outcomes in security risk reduction.<br>Equal Opportunity Employer:We hire based on skills and expertise. All qualified candidates are welcome regardless of background, experience, or prior employment history. Applications are reviewed solely on demonstrated technical ability and qualifications.<br>Apply Now!
Role: Information Security Specialist (Remote) Location: Remote (Work from Anywhere) Job Type: Contract Payout: $60 - $100/hour<br>Role Overview:We are hiring for one of our clients, seeking an Info Sec Expert to work on a contract basis. This role will focus on maintaining robust security protocols, identifying vulnerabilities, and implementing solutions to protect sensitive data across all systems.<br>Key Responsibilities:• Conduct regular security assessments, audits, and penetration testing to identify vulnerabilities in systems and networks.• Develop and enforce security policies, procedures, and best practices to ensure compliance with industry standards and regulations.• Monitor security systems and respond to incidents, including investigating breaches and implementing corrective actions.• Collaborate with IT teams to integrate security measures into system development and deployment processes.• Provide security awareness training and guidance to employees to reduce human-related security risks.<br>Required Skills & Qualifications:• Experience with security frameworks such as NIST, ISO 27001, or CIS Controls is required.• Proficiency in vulnerability scanning tools like Nessus, Qualys, or Open VAS is required.• Knowledge of network security protocols, firewalls, and intrusion detection/prevention systems is required.• Familiarity with compliance regulations such as GDPR, HIPAA, or SOC 2 is required.• Strong analytical and problem-solving skills with the ability to interpret complex security logs and reports.<br>More About the Opportunity:This role offers a unique opportunity to work with a global leader in the Technology, Information and Internet industry, contributing to the protection of critical infrastructure and customer data. The position involves high-impact work with measurable outcomes in security risk reduction.<br>Equal Opportunity Employer:We hire based on skills and expertise. All qualified candidates are welcome regardless of background, experience, or prior employment history. Applications are reviewed solely on demonstrated technical ability and qualifications.<br>Apply Now!
Join the Cybersecurity Marketplace Redefining How Startups Access Security Leadership<br>Fractional CISO - Independent Consultant Remote · Flexible Engagement · Multiple Positions Available<br>The opportunity<br>We're building the first dedicated marketplace connecting startups with world-class fractional CISOs and we're looking for experienced security leaders to be part of it from day one. Startups are scaling fast and facing real security challenges. They need senior guidance, but not a full-time hire. That's where you come in.<br>As a fractional CISO on our platform, you set your terms, choose your clients, and deliver the strategic security leadership that early-stage companies desperately need on a schedule that works for you.<br>What you'll do<br>Depending on client engagements, your work will typically include developing security strategies and roadmaps aligned to startup growth stages, advising on compliance frameworks (SOC 2, ISO 27001, GDPR), leading risk assessments and security architecture decisions, preparing startups for investor due diligence and enterprise sales security reviews, and building security culture from the ground up in fast-moving teams.<br>Who you are<br>You have 10+ years in cybersecurity with at least 3 years in a CISO or senior security leadership role. You've worked with or inside startups and understand their speed, constraints, and priorities. You can translate complex security risk into plain business language and you're comfortable owning the security conversation at board and executive level. You're looking for variety, autonomy, and the ability to make real impact across multiple companies simultaneously.<br>What we offer Early access to a curated pipeline of vetted startup clients, a platform built specifically for security professionals (not a generic freelance marketplace), full control over your rate, availability, and engagement terms, a community of peers at the same level, and visibility to hundreds of businesses actively looking for fractional security leadership.<br>This is not a job. It's a practice. We're not hiring employees, we're partnering with independent security leaders who want to build something on their own terms. If you've been thinking about going fractional, or you're already doing it and want better client access, this is your platform.<br>Apply to join the marketplace We're onboarding our founding cohort of fractional CISOs now. Spots are limited to maintain quality on both sides of the marketplace.<br>Apply today and shape the future of startup security.