Cloud Security Engineering Lead
📣 إعلان| نوع العقد | دوام كامل | |
| طبيعة الوظيفة | بالموقع | |
| الموقع | ثول |
وصف الوظيفة
About the Role
KAUST (King Abdullah University of Science and Technology) is undertaking a Cybersecurity Transformation Program focused on securing cloud and hybrid environments across its multi-cloud infrastructure. This full-time role for a Cloud Security Engineering Lead, based in Thuwal, Makkah, involves designing, implementing, and assuring secure cloud and hybrid environments. The position requires 5-10 years of experience and combines solution architecture with direct technical execution across various security domains.
Role Overview
The Cloud Security Engineering Lead will translate security requirements into deployable technical controls, lead complex implementation activities, and resolve cross-platform dependencies. This role ensures solutions are operationally supportable and measurable, working across multiple portfolio initiatives. Key projects include Microsoft 365 A5, Enterprise IAM, cloud security posture improvement, security operations integration, network security, and cyber exposure reduction. The incumbent is expected to remain hands-on in design, configuration, integration, troubleshooting, testing, remediation, and knowledge transfer, while providing technical direction to partners and internal teams.
Key Responsibilities
- Own cloud security architecture and engineering activities from design through implementation, stabilization, and operational handover within the Cybersecurity Transformation Program.
- Assess Azure, Microsoft 365, hybrid, and multi-cloud environments to identify security gaps and opportunities for control improvement.
- Design and implement secure cloud architectures aligned with KAUST security principles, enterprise architecture standards, and Zero Trust objectives.
- Provide hands-on engineering across Microsoft Entra ID, Conditional Access, Privileged Identity Management, Identity Protection, MFA, passwordless controls, Intune, Defender XDR, Defender for Cloud, Microsoft Sentinel, and Microsoft Purview.
- Engineer and improve cloud security posture management, workload protection, attack-path reduction, logging, monitoring, and security configuration across IaaS, PaaS, SaaS, endpoint, and identity environments.
- Design and implement integrations between cloud platforms and Security Operations, including SIEM/SOAR telemetry, detection use cases, KQL analytics, and incident automation.
- Apply Zero Trust principles across identity, privileged access, endpoints, applications, network access, collaboration, and data.
- Develop secure connectivity and access patterns for cloud and hybrid environments, collaborating with network security teams.
- Lead technical design decisions, configuration reviews, proof-of-concept activities, testing, troubleshooting, and remediation for assigned initiatives.
- Review and challenge designs proposed by vendors and partners to ensure alignment with KAUST standards.
- Lead or support migration and modernization activities from legacy security platforms to cloud-native capabilities.
- Manage technical dependencies with Enterprise IAM, Network Security, Cyber Exposure Reduction, Security Operations, and other teams.
- Contribute technical leadership to the Microsoft 365 A5 project, including architecture, security configuration, and operational integration.
- Define technical acceptance criteria, validation evidence, security baselines, and production-readiness requirements.
- Proactively identify and resolve architecture risks, misconfigurations, security gaps, and implementation blockers.
- Produce high-quality as-built designs, configuration standards, engineering documentation, and knowledge-transfer materials.
- Upskill internal technical teams through pairing, technical walkthroughs, and structured knowledge transfer.
Qualifications and Experience
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Engineering, or a closely related discipline. Substantial equivalent professional experience may be considered.
- Advanced Microsoft certifications in Azure architecture, security, identity, Microsoft 365 security, or security operations are strongly preferred.
- Relevant cloud or cybersecurity certifications such as CISSP, CCSP, GIAC cloud security, Microsoft Security certifications, or Google/AWS security certifications are advantageous.
- Certifications should support demonstrable hands-on enterprise cloud security engineering and implementation experience.
Required Skills
- Deep hands-on cloud security engineering expertise across Microsoft Azure and Microsoft 365, with the ability to move between architecture, configuration, integration, troubleshooting, and operationalization.
- Strong knowledge of Microsoft security technologies including Entra ID, Conditional Access, PIM, Identity Protection, Defender XDR, Defender for Cloud, Intune, Microsoft Sentinel, and Microsoft Purview.
- Strong understanding of cloud security architecture across identity, network, endpoint, workloads, applications, data, logging, monitoring, and security operations.
- Practical experience designing and implementing Zero Trust architectures and identity-centric security controls in enterprise environments.
- Strong understanding of SIEM/SOAR, detection engineering, KQL or comparable query languages, security telemetry onboarding, incident automation, and SOC integration.
- Experience with cloud security posture management, workload hardening, attack-path analysis, secure configuration baselines, and remediation across IaaS, PaaS, and SaaS.
- Ability to design secure hybrid and multi-cloud integrations, including federation, SSO, network connectivity, logging, and security control alignment.
- Strong technical governance and engineering judgment, including the ability to challenge vendor designs and translate security requirements into practical implementation decisions.
- Ability to lead multidisciplinary technical teams and delivery partners while maintaining hands-on engagement in critical technical work.
- Strong written and verbal communication skills, including the ability to explain technical risks, architecture decisions, and delivery implications to both technical and senior stakeholders.
- Evidence-led and outcome-oriented approach.
Work Environment
This full-time position is based in Thuwal, Makkah, within KAUST's dynamic environment, focusing on modern security architectures and sustainable operational handover. The role involves close collaboration with internal teams and delivery partners to modernize security operations, cloud security posture, identity, and network security.
متطلبات الوظيفة
- تتطلب ٥-١٠ سنوات خبرة
وظائف مشابهة
قد يعجبك أيضاً
- وظائف ذات صلة بـ Cloud Security Engineering Lead
- وظائف مصمم جرافيك في جدة
- وظائف HSE Engineer في جدة
- وظائف Guest Experience Expert في جدة
- وظائف Reservations Agent في جدة
- وظائف Project Manager في جدة
- مجالات وظيفية أخرى في ثول
- وظائف صيدلي في ثول
- استكشف الوظائف في أنحاء المملكة
- وظائف Videographer في الرياض
- وظائف مسوق عقاري في جدة
- وظائف مشغل ألعاب في الرياض
- وظائف أخصائي خدمة عملاء في مكة المكرمة
- وظائف E Commerce Manager في مكة المكرمة
- وظائف Senior Analyst في مكة المكرمة
- وظائف Mechanical Technician في الجبيل
- وظائف أخصائي جودة مياه في الرياض
- وظائف Technical Manager في جازان
- وظائف Showroom Sales Representative في حفر الباطن