Senior Cybersecurity Expert
Abu Dhabi, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 5–8 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Astra Tech
Astra Tech is a prominent technology company based in the UAE, dedicated to developing digital infrastructure that enhances everyday life through AI-driven fintech, communications, and digital service platforms. Our guiding principle, the Blueprint of Simplicity, shapes technology around authentic human behaviors to facilitate effortless connections, financial accessibility, and smooth daily experiences.
Our flagship platform, Botim, is a leading regional fintech communication tool integrating secure VoIP with AI-driven financial utilities, supporting over 150 million users globally. Botim Money simplifies money management for individuals and SMEs, including payments, money transfers, and credit access. Our lending system, Quantix, delivers rapid, regulated credit solutions, including innovative offerings like CashNow for immediate financial access.
Role Overview
We are looking for a seasoned Senior Cybersecurity Expert to join our team and provide advanced offensive security skills and expertise in secrets management and secure engineering practices. This position involves hands-on work securing Azure Cloud infrastructure, Office 365 environments, enterprise key and secret management, security operations through SOC, and integrating security in DevSecOps pipelines.
Key Responsibilities
- Secure Azure tenants by managing Entra ID, Conditional Access, Defender for Cloud, NSGs, Private Link, Key Vault, Policies, Landing Zone architectures, and adherence to security benchmarks.
- Manage Office 365 security tools including Defender for Office 365, DLP, CASB, Cloud App Security, Conditional Access, CSPM, MDC, MDE, MFA, and PIM.
- Design and manage enterprise key lifecycle processes using Azure Key Vault, Managed HSM, BYOK/HYOK strategies, certificate rotation, envelope encryption, and PKI integration.
- Implement and maintain Privileged Access Management solutions like CyberArk, BeyondTrust, or PAM360 with capabilities including vault setup, session control, just-in-time / just-enough access, credential rotation, and hybrid identity Tier-0 defense.
- Integrate security measures within CI/CD pipelines employing Azure DevOps, GitHub Actions, or GitLab, using SAST, DAST, SCA, infrastructure as code scanning (Terraform/Bicep), container/image scanning, secrets detection, and enforce policy as code.
- Operate Microsoft Sentinel for security operations, including data connector configuration, advanced hunting and analytics with KQL, UEBA rule creation, watchlist management, automation with SOAR playbooks, incident handling, MITRE ATT&CK framework mapping, and threat intelligence consumption.
Qualifications and Experience
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field.
- Between 5 and 8 years of direct experience in cybersecurity engineering or in security operations roles within enterprises or service providers.
- Demonstrable professional experience securing Microsoft Azure workloads, particularly across multi-subscription setups, hybrid identities, and network configurations.
- Strong offensive security capabilities, including hands-on web and API penetration testing backed by formal reporting to enterprise stakeholders.
- Proficiency with security tools such as PAM solutions (CyberArk, BeyondTrust, PAM360), Azure Key Vault and Hardware Security Modules, Burp Suite Pro, security scanners integrated with CI/CD pipelines, and infrastructure as code tools.
Level
Senior
Minimum education
Bachelor's Degree