Senior Consultant - Cybersecurity
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
We are looking for an experienced Senior Cybersecurity Consultant to join our Cybersecurity Practice as a pivotal Incident Handler within our security operations team. The successful candidate will take the lead in identifying, investigating, containing, and resolving security incidents across both enterprise and cloud environments, with an emphasis on the Microsoft security landscape.
Key Responsibilities
- Manage the complete lifecycle of security incidents including detection, triage, investigation, containment, elimination, and recovery in accordance with established processes and service level agreements (SLAs).
- Operate and fine-tune Microsoft Defender tools (EDR/XDR variants covering Endpoint, Office 365, Identity, and Cloud Apps) to detect and respond to security threats across devices, identities, emails, and cloud services.
- Utilize Microsoft Sentinel for security information and event management (SIEM) and security orchestration, automation, and response (SOAR) functions including log analysis, alert correlation, and developing analytic rules and workbooks to augment detection and response efficiency.
- Employ Microsoft Purview for managing data governance, information protection, insider risk oversight, and compliance; handle investigations related to data alerts and support data loss prevention (DLP) operations.
- Configure and monitor DLP policies within Microsoft 365 and endpoint environments to thwart unauthorized data leakage and minimize false alerts through continuous refinement.
- Engage in proactive threat hunting within the Microsoft 365 and Azure environments; devise new detection techniques and enhance detection logic leveraging threat intelligence and past incident insights.
- Conduct detailed host, endpoint, and cloud digital forensic investigations to ascertain incident root causes, extent, and impact while meticulously preserving evidence adhering to best practices.
- Generate comprehensive incident documentation including reports, timelines, and post-incident analyses; maintain runbooks and playbooks; communicate incident status and outcomes clearly to internal and client stakeholders.
Required Qualifications & Experience
- A bachelor’s or equivalent degree in Computer Science, Information Security, or a related discipline.
- Minimum of 8 years’ experience in cybersecurity operations, incident response, or security monitoring, specifically with extensive hands-on use of Microsoft security tools.
- Preferred certifications include Microsoft Security Operations Analyst (SC-200), Microsoft Certified Cybersecurity Architect (SC-100), Information Protection (SC-400), GIAC incident response/forensics (such as GCIH or GCFA), ISC2 credentials (like SSCP or CISSP), and CompTIA CySA+.
- Technical expertise with Microsoft Defender suite, Microsoft Sentinel, Microsoft Purview, and Microsoft 365 DLP. Proficiency in Kusto Query Language (KQL) for investigations and detection development.
- Experience in endpoint detection and response investigations, log analytics, SIEM/SOAR tools application, and endpoint/cloud forensic analysis, along with knowledge of identity platforms including Entra ID and Active Directory.
- Preferred scripting knowledge in PowerShell for automation purposes.
- Strong familiarity with incident response frameworks and methodologies such as NIST SP 800-61 and SANS, MITRE ATT&CK, the cyber kill chain, and contemporary attacker tactics.
- Comprehensive understanding of cybersecurity best practices including defense-in-depth strategies, zero trust architectures, least privilege enforcement, ISO 27001 standards, and CIS benchmarks.
- Awareness of Qatar National Information Assurance (NIA) standards is advantageous.
Minimum education
Bachelor's Degree
Skills
Tools & software
Microsoft Active Directory
required
Microsoft Sentinel
required
Microsoft Defender
required
How they work
Teamwork & Collaboration
Problem Solving
Attention to Detail
Stress Management