Website:
diwinecodetechnology.com
Job details:
Cyber Security Engineer
Location: Dubai/ Remote
Employment Type: Full-time
Experience: 3–6+ years
Department: Information Security / Technology
About the Role
We are looking for an experienced Cyber Security Engineer to join our technology team and help protect our applications, infrastructure, networks, systems, and data from cyber threats.
The ideal candidate will have strong hands-on experience in security monitoring, vulnerability management, application and network security, cloud security, incident response, and security best practices.
You will work closely with development, infrastructure, DevOps, and IT teams to identify security risks, implement effective controls, and ensure security is integrated throughout the software and infrastructure lifecycle.
Key Responsibilities
* Monitor, identify, investigate, and respond to security threats and incidents.
* Conduct vulnerability assessments and coordinate remediation of identified vulnerabilities.
* Perform security assessments of applications, APIs, networks, servers, and cloud environments.
* Implement and maintain security controls across infrastructure and applications.
* Monitor security events, logs, and alerts using SIEM and security monitoring tools.
* Investigate security incidents and perform root-cause analysis.
* Support incident response, containment, remediation, and post-incident reviews.
* Conduct vulnerability scanning and coordinate patch management.
* Work with development teams to identify and remediate application security vulnerabilities.
* Implement and maintain secure development practices and DevSecOps processes.
* Review application architecture and infrastructure designs from a security perspective.
* Assess APIs, authentication mechanisms, access controls, encryption, and data protection mechanisms.
* Implement security best practices for cloud infrastructure and services.
* Manage security policies, standards, procedures, and technical documentation.
* Conduct periodic security audits and risk assessments.
* Support penetration testing activities and remediation of findings.
* Stay up to date with emerging cyber threats, vulnerabilities, attack techniques, and security technologies.
* Work with internal teams and external security vendors where required.
Required Skills & Experience
* 3–6+ years of professional Cyber Security experience.
* Strong understanding of network security, application security, cloud security, and information security principles.
* Hands-on experience with SIEM, vulnerability scanners, EDR/XDR, firewalls, IDS/IPS, and security monitoring tools.
* Experience with security incident investigation and response.
* Strong understanding of OWASP Top 10 and common web application vulnerabilities.
* Experience with vulnerability management and remediation.
* Good understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, firewalls, and network security concepts.
* Experience with authentication and authorization mechanisms including OAuth 2.0, JWT, SSO, MFA, and RBAC.
* Good understanding of encryption, certificates, TLS/SSL, key management, and data protection.
* Experience securing REST APIs and web applications.
* Working knowledge of Linux and Windows security.
* Experience with cloud security, preferably AWS, Azure, or GCP.
* Strong understanding of identity and access management (IAM).
* Experience with security logging, monitoring, alerting, and analysis.
* Good knowledge of security frameworks and standards such as ISO 27001, NIST, CIS Controls, and SOC 2.
* Strong analytical and problem-solving skills.
Application & DevSecOps Security
* Experience identifying common application vulnerabilities such as:
* SQL Injection
* XSS
* CSRF
* SSRF
* Broken Authentication
* Broken Access Control
* Insecure APIs
* Security Misconfiguration
* Experience integrating security checks into CI/CD pipelines.
* Knowledge of SAST, DAST, SCA, container security, and dependency scanning.
* Ability to work with development teams to implement secure coding practices.
* Experience reviewing code and application architecture for security risks is preferred.
Cloud & Infrastructure Security
* Experience securing cloud environments such as AWS, Azure, or GCP.
* Knowledge of cloud IAM, networking, security groups, encryption, logging, monitoring, and secrets management.
* Understanding of Docker and Kubernetes security is preferred.
* Experience securing production environments and infrastructure.
* Knowledge of infrastructure-as-code security using tools such as Terraform is a plus.
Tools & Technologies
Experience with some of the following is preferred:
* SIEM: Microsoft Sentinel, Splunk, QRadar, Elastic
* EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne
* Vulnerability Management: Nessus, Qualys, Rapid7
* Application Security: Burp Suite, OWASP ZAP
* Cloud Security: AWS Security, Microsoft Defender for Cloud, Azure Security
* Network Security: Firewalls, IDS/IPS, VPN, WAF
* DevSecOps: SAST, DAST, SCA, CI/CD security tools
* Endpoint and identity security platforms
Certifications – Good to Have
One or more of the following certifications would be an advantage:
* CISSP
* CEH
* CompTIA Security+
* OSCP
* CISM
* AWS Security Specialty
* Azure Security Engineer Associate
* Other relevant security certifications
Qualifications
* Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or a related field.
* Strong communication and interpersonal skills.
* Strong attention to detail and security mindset.
* Ability to work independently and collaboratively with technical teams.
* Strong documentation and reporting skills.
* Ability to prioritize security risks based on business impact.
* Willingness to continuously learn and stay updated with evolving cyber threats.
What We’re Looking For
We are looking for a hands-on security professional who can identify security risks, investigate threats, implement security controls, and work closely with engineering teams to build secure systems.
The ideal candidate should be able to balance security requirements with business and technical needs and take ownership of security issues from identification through remediation.
To Apply
Please share your updated CV along with:
* Current location
* Total years of Cyber Security experience
* Key security domains of expertise
* Relevant certifications
* Current/expected salary
* Notice period
* Availability to join
Click on Apply to know more.