IFZA Dubai logo

Security Consulting Engineer

IFZA Dubai

On-site๐Ÿ‡ฆ๐Ÿ‡ชDubai, DU, UAEseniorPosted 4h ago

Visa & sponsorship

  • Employers in UAE sponsor the residence visa by default, and nothing in the posting says otherwise.

Job description

Role:

We are looking for a driven Security Consulting Engineer to own the security posture of SaaS platforms (including Zoho), Azure cloud infrastructure, and software delivery pipelines. This role sits at the intersection of cloud security architecture, application security, secure software delivery, and enterprise SaaS governance - making it a unique opportunity for engineers who thrive across multiple security domains.

You will be responsible for embedding security into every layer of our technology stack: from Azure workloads and CI/CD pipelines to Zoho application configurations and third-party SaaS integrations. You will work closely with DevOps, IT, and Engineering teams to ensure security is shared, continuous practice rather than a checkpoint.

Key Responsibilities:

Cloud Security (Azure)

  • Maintain security controls across Azure environments - Virtual Networks, Network Security Groups (NSGs), Private Endpoints, and Azure Firewall

  • Own outbound/inbound network security posture, including Azure Firewall policy design, FQDN allow-listing, and egress control

  • Monitor cloud infrastructure for misconfigurations, threats, and compliance violations using Microsoft Defender for Cloud

  • Conduct cloud risk assessments and maintain cloud security architecture documentation

  • Implement DDoS protection and WAF policies (Azure Front Door / Application Gateway)

Application Security

  • Perform application security reviews across web applications and APIs - authentication/authorization flaws, business logic issues, injection, SSRF, and OWASP Top 10 categories

  • Conduct threat modeling and secure design review for new features and architecture changes

  • Define and enforce secure coding standards and developer security guidelines

  • Review API and microservice designs for authentication, input validation, and data exposure risks

Secure Software Delivery (DevSecOps)

  • Integrate security scanning into CI/CD pipelines (SAST, DAST, SCA, secrets detection)

  • Implement and manage container security controls for Azure Container Apps (image scanning, registry security, runtime configuration)

  • Automate security testing and compliance checks across deployment workflows

  • Manage vulnerability remediation workflows in collaboration with development teams

  • Conduct security risk assessments across software delivery pipelines, code repositories, and deployment environments to identify, prioritize, and remediate risks before they reach production

Zoho & SaaS Platform Security

  • Own security configuration and governance of Zoho One (CRM, Desk, People, Books, Cliq, One)

  • Manage Zoho user access controls, role-based permissions, and data sharing policies

  • Monitor Zoho audit logs and investigate suspicious activity or data access anomalies

  • Configure Zoho security policies including MFA enforcement, IP restrictions, and session controls

  • Assess third-party Zoho integrations, extensions, and webhook endpoints for security and data privacy risks

  • Maintain SaaS security inventory and conduct periodic access reviews across all platforms

  • Evaluate and onboard new SaaS tools through a security review process

Security Operations & Governance

  • Operate and tune SIEM platform for cloud and SaaS log ingestion, alerting, and incident response

  • Lead security incident response for cloud, pipeline, and SaaS-related events

  • Develop and maintain security policies, runbooks, and compliance documentation

  • Conduct regular vulnerability assessments and penetration testing coordination

Required Experience:

  • 8+ years of hands-on experience in cloud security, application security, or information security

  • Proven experience securing production environments on multi-Cloud providers.

  • Hands-on experience performing application security assessments (manual + tool-assisted)

  • Hands-on experience integrating security tools into CI/CD pipelines

  • Experience administering and securing Zoho or equivalent enterprise SaaS platforms

  • Demonstrated experience with SIEM platforms, log analysis, and incident response

Technical Skills

  • Cloud platform:

    Azure security services (Defender for Cloud, Azure Firewall, Front Door, Key Vault)

  • Application security:

    OWASP Top 10, Burp Suite, API security testing, secure code review

  • DevSecOps tooling:

    GitHub Actions, Jenkins, or GitLab CI; SonarQube, Snyk, Trivy, Checkov

  • Container security:

    Docker image scanning; experience securing serverless/managed container platforms (e.g., Azure Container Apps)

  • SIEM & monitoring:

    Microsoft Sentinel or equivalent

  • Scripting & automation:

    Python, Bash, PowerShell, or Terraform

  • Security frameworks:

    OWASP, NIST, CIS Benchmarks, Zero Trust

  • Zoho administration:

    security configuration across Zoho One suite

Desired qualifications:

  • Certifications: AZ-500, CCSP, or equivalent

  • Experience with Zoho Creator, Zoho Analytics, or custom Zoho integrations security

  • Familiarity with Kubernetes/AKS security (if organization later adopts it)

  • Exposure to compliance frameworks: ISO 27001, SOC 2 Type II, GDPR, HIPAA, PCI-DSS

  • Background in red team / penetration testing or bug bounty participation

  • Experience with infrastructure-as-code security scanning (Terraform)