1. Home
  2. Jobs
  3. Apex Employment Services
  4. Cyber security Engineer - privileged Access Management
Cybersecurity

Cyber security Engineer - privileged Access Management

Apex Employment Services
Dubai, UAE Listed just now via Naukrigulf
linux cybersecurity soc siem security

Job Description Roles & Responsibilities FortiPAM — Privileged Access Management ▪ Deploy, configure, and administer FortiPAM for centralized management of privileged accounts, credentials, and sessions across on-premises, cloud, and hybrid environments. ▪ Onboard privileged and service accounts (Windows, Linux/Unix, network devices, databases, hypervisors) into vaulted credential stores with automated password rotation policies. ▪ Configure and manage secure remote access workflows (RDP, SSH, HTTPS, database consoles) via FortiPAM's session broker, including session recording, live session monitoring, and just-in-time (JIT) access provisioning. ▪ Implement approval workflows, checkout/check-in policies, and dual-control access for high-risk privileged operations. ▪ Integrate FortiPAM with Active Directory/Entra ID, LDAP, RADIUS, and SAML/SSO providers for identity federation and MFA enforcement on privileged sessions. ▪ Configure granular role-based access control (RBAC) and least-privilege policies aligned with job function and risk tier. ▪ Set up session recording storage and retention policies, and integrate recorded sessions with SIEM/SOC workflows for forensic review. ▪ Conduct periodic access reviews, orphaned and stale privileged account audits, and credential rotation compliance checks. ▪ Troubleshoot connectivity, authentication, and session-broker issues between FortiPAM and target endpoints or devices. ▪ Develop and maintain break-glass / emergency access procedures for FortiPAM outages. FortiDLP — Data Loss Prevention ▪ Design, implement, and tune FortiDLP policies to detect and prevent unauthorized transfer of sensitive data (PII, PHI, financial data, intellectual property) across endpoints, email, web, and removable media channels. ▪ Build and maintain data classification schemas and fingerprinting/pattern-matching rules (regex, exact data match, document fingerprinting, OCR-based detection for scanned or image content). ▪ Configure endpoint DLP agents for monitoring and blocking of USB, cloud upload (SaaS/CASB integration), print, clipboard, and screen-capture activities. ▪ Integrate FortiDLP with FortiMail and web/proxy gateways to enforce consistent data-protection policy across all egress channels. ▪ Analyze DLP incident alerts, tune detection thresholds to reduce false positives, and produce incident investigation reports for compliance and legal review. ▪ Collaborate with data owners and compliance teams to define sensitivity labels and policy exceptions in line with regulatory requirements, including healthcare data protection standards. ▪ Maintain audit trails and generate DLP compliance reporting for internal audits and regulatory assessments. ▪ Perform periodic policy simulation and testing (tabletop and live data-exfiltration test scenarios) to validate DLP efficacy. FortiMail — Email Security Gateway ▪ Administer FortiMail in gateway/transparent mode across a multi-tenant Microsoft 365 and hybrid Exchange environment. ▪ Configure and maintain SPF, DKIM, and DMARC records/policies across all managed domains; monitor DMARC aggregate and forensic reports for spoofing and delivery issues. ▪ Design and tune anti-spam, anti-phishing, anti-malware, impersonation analysis, and URL/attachment sandboxing policies. ▪ Configure and manage SMTP relay validation, connection security (TLS enforcement, opportunistic vs. forced TLS), and IP reputation/greylisting policies. ▪ Manage Protected Identities / executive impersonation protection features and business email compromise (BEC) detection rules. ▪ Integrate FortiMail with Microsoft Graph API for journaling, quarantine management, and mailbox-level remediation actions. ▪ Maintain multi-tenant domain onboarding, per-tenant policy segregation, and delegated administration structures. ▪ Conduct User Acceptance Testing (UAT) for FortiMail policy changes and upgrades, including test-execution documentation and vendor coordination. ▪ Monitor mail queues and bounce/NDR patterns, and troubleshoot mail-flow issues across hybrid Exchange/M365 routing. ▪ Perform regular review of quarantine, false positive/negative tuning, and end-user release-request handling. ▪ Maintain disaster recovery and high-availability configuration for FortiMail clusters. Desired Candidate Profile We are seeking a hands-on Cybersecurity Engineer to design, deploy, and manage our Privileged Access Management, Data Loss Prevention, and Email Security infrastructure built on the Fortinet security suite (FortiPAM, FortiDLP, FortiMail). The successful candidate will be responsible for securing privileged credentials and sessions, preventing sensitive data exfiltration, and protecting the organization's email ecosystem against phishing, spoofing, and business email compromise. This role requires deep technical expertise in privileged session management, data classification and policy engineering, and mail security gateway architecture, along with the ability to work cross-functionally with network, SOC, and compliance teams to continuously mature the organization's security posture. Employment Type Full-time Company Industry IT - Hardware & Networking Department / Functional Area IT Hardware SupportIT Hardware Repair & Maintenance Keywords Security InfrastructureFortipamCyberarkFortidlpSPFDKIMDMARCMTASts OperatorRABC Get real-time job updates only on our App

Ready to apply?

You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.

Apply Now

Opens the employer's site in a new tab

  • CompanyApex Employment Services
  • LocationDubai, UAE
  • CategoryCybersecurity
  • SourceNaukrigulf
  • Listedjust now

Related Cybersecurity jobs

More Cybersecurity