{bc}
linkedin

Security Consulting Engineer

IFZA Dubai
Dubai, UAE
Full-time
Mid-Senior
Onsite
Discovered 1 weeks ago
Cloud securityApplication security assessmentCI/CD security integrationZoho One security administrationSIEM, log analysis, and incident responseAzure security services
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Cloud securityApplication security assessmentCI/CD security integration
Smart Apply

Full Job Posting

Role Overview

The Security Consulting Engineer will own the security posture of SaaS platforms including Zoho, Azure cloud infrastructure, and software delivery pipelines.

The role spans cloud security architecture, application security, secure software delivery, and enterprise SaaS governance.

The role works with DevOps, IT, and Engineering teams to embed continuous security practices across the technology stack.

Cloud Security

  • Maintain controls across Azure virtual networks, network security groups, private endpoints, and Azure Firewall.
  • Own firewall policy design, FQDN allow-listing, egress control, DDoS protection, and WAF policies.
  • Monitor Azure environments for misconfigurations, threats, and compliance violations.
  • Conduct cloud risk assessments and maintain security architecture documentation.

Application Security and DevSecOps

  • Review web applications and APIs for authentication, authorization, business logic, injection, SSRF, and OWASP Top 10 issues.
  • Conduct threat modeling and secure design reviews for new features and architecture changes.
  • Define secure coding standards and review API and microservice designs.
  • Integrate SAST, DAST, SCA, and secrets detection into CI/CD pipelines.
  • Manage container security, automate security testing, and coordinate vulnerability remediation.

Zoho and SaaS Security

  • Own security configuration and governance across the Zoho One suite.
  • Manage user access, role-based permissions, data sharing policies, MFA, IP restrictions, and session controls.
  • Monitor audit logs and investigate suspicious activity or data access anomalies.
  • Assess third-party integrations, extensions, and webhook endpoints for security and privacy risks.
  • Maintain a SaaS security inventory, conduct access reviews, and evaluate new SaaS tools.

Security Operations and Governance

  • Operate and tune SIEM capabilities for cloud and SaaS log ingestion, alerting, and incident response.
  • Lead incident response for cloud, pipeline, and SaaS-related events.
  • Develop security policies, runbooks, and compliance documentation.
  • Conduct vulnerability assessments and coordinate penetration testing.

Required Experience

  • At least 8 years of hands-on experience in cloud security, application security, or information security.
  • Proven experience securing production environments across multiple cloud providers.
  • Hands-on experience with application security assessments and CI/CD security tool integration.
  • Experience administering and securing Zoho or equivalent enterprise SaaS platforms.
  • Demonstrated experience with SIEM platforms, log analysis, and incident response.

Technical Skills

  • Azure security services include Defender for Cloud, Azure Firewall, Front Door, and Key Vault.
  • Application security skills include OWASP Top 10, Burp Suite, API security testing, and secure code review.
  • DevSecOps tools include GitHub Actions, Jenkins, GitLab CI, SonarQube, Snyk, Trivy, and Checkov.
  • Container security includes Docker image scanning and managed container platform security.
  • Scripting and automation may use Python, Bash, PowerShell, or Terraform.
  • Security frameworks include OWASP, NIST, CIS Benchmarks, and Zero Trust.

Desired Qualifications

  • AZ-500, CCSP, or equivalent certification is desirable.
  • Experience with Zoho Creator, Zoho Analytics, or custom Zoho integration security is desirable.
  • Kubernetes or AKS security familiarity is desirable.
  • Exposure to ISO 27001, SOC 2 Type II, GDPR, HIPAA, or PCI-DSS is desirable.
  • Red team, penetration testing, bug bounty, or Terraform security scanning experience is desirable.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at IFZA Dubai