Cybersecurity and Digital Trust Analyst KEO International Consultants
Employer Active
Posted 7 hrs ago
Send me Jobs like this
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
Responsibilities
JOB SUMMARY
The Cybersecurity and Digital Trust Analyst is a hands-on security operations role at the heart of KEO's cloud-first, Microsoft-centric security posture. This is not a passive monitoring role the Analyst actively hunts threats, analyses security events, responds to incidents, and drives measurable improvement in KEO's security resilience across all platforms and geographies. Operating within and continuously strengthening KEO's zero-trust architecture, CSPM framework, and Digital Trust governance model, the role embeds a security-first culture across the organization and contributes to AI-driven security operations as part of KEO's ongoing digital transformation.
KEY TASKS AND RESPONSIBILITIES
Security Operations & Threat Detection
- Operate and continuously tune Microsoft Sentinel (SIEM), building and refining detection rules, KQL analytics queries, and automated SOAR response playbooks to ensure real-time threat visibility, rapid incident triage, and reduced mean time to respond (MTTR) across cloud, endpoint, identity, and network layers.
- Conduct proactive threat hunting across KEO's Azure and Microsoft 365 environments, identifying indicators of compromise and attack patterns before they escalate.
- Produce regular security operations reports, threat intelligence summaries, and dashboard insights for IT leadership.
Identity, Access & Zero-Trust Governance
- Administer and continuously improve KEO's identity and access management framework using Microsoft Entra ID, ensuring MFA enforcement, conditional access policies, privileged identity management (PIM), and zero-trust network architecture are correctly configured, monitored, and maintained.
- Apply and audit least-privilege, RBAC, and zero-trust principles across all systems and user populations, conducting regular access reviews, entitlement audits, and certification campaigns to identify and remediate excessive or inappropriate access.
Cloud Security Posture Management (CSPM)
- Continuously assess KEO's cloud security posture using Microsoft Defender for Cloud, identifying and prioritizing misconfigurations, vulnerabilities, and compliance gaps, and driving timely remediation in collaboration with the platform engineering team.
- Maintain and improve secure configuration baselines for Microsoft Azure, Microsoft 365, SharePoint, and Autodesk Construction Cloud in line with CIS benchmarks and Microsoft security best practices, ensuring all certified digital platforms consistently meet their respective security and compliance standards.
Vulnerability Management & Patch Compliance
- Operate KEO's vulnerability management programme using Microsoft Defender Vulnerability Management, identifying, assessing, and prioritizing vulnerabilities across endpoints, servers, and cloud workloads, and tracking patch compliance levels globally with escalation and coordinated remediation across platform and workplace teams.
- Perform regular security assessments of infrastructure, applications, and configurations, providing actionable remediation recommendations.
Governance, Compliance & Audit Support
- Support independent audits of KEO's access control and governance frameworks, maintaining accurate security documentation including policies, standards, risk registers, and control evidence and contributing to the development and review of cybersecurity policies that reflect current threats and regulatory requirements.
- Support IT risk assessment activities and assist with the maintenance and testing of BCP and DR procedures from a security perspective.
Collaboration & Stakeholder Engagement
Work closely with platform engineering, digital workplace, and enterprise digital solutions teams to ensure security is embedded by design across all IT initiatives, acting as a trusted advisor to business stakeholders and participating in CAB meetings to provide security assessment and sign-off for technology changes.
span>JOB-SPECIFIC COMPETENCIES /strong> /span>
- Strong analytical and investigative mindset - able to identify patterns, anomalies, and threats across large volumes of security telemetry.
- Hands-on technical proficiency with Microsoft Sentinel, Microsoft Defender suite, Entra ID, and Azure security services.
- Working knowledge of KQL (Kusto Query Language) for security analytics, threat hunting, and detection rule authoring.
- Solid understanding of zero-trust architecture principles and their practical application in a cloud-first environment.
- Proactive and self-motivated: takes initiative in identifying and addressing security gaps without waiting to be directed.
- Detail-oriented and process-disciplined, with strong documentation habits and a commitment to evidence-based operations.
- Collaborative team player who contributes to a positive, knowledge-sharing team culture.
- Continuous learner: actively keeps pace with the evolving threat landscape, new attack techniques, and emerging security tooling.
Desired Candidate Profile
Typically, 3 5+ years of experience in a dedicated cybersecurity operations or information security role within an enterprise environment.
- Proven, hands-on experience with Microsoft Sentinel (SIEM), including detection rule creation, KQL query writing, and incident investigation workflows.
- Working experience with the Microsoft Defender suite (Defender for Endpoint, Defender for Cloud, Defender for Identity, Defender for Office 365).
- Demonstrated experience with Microsoft Entra ID (Azure AD), including conditional access, MFA administration, privileged identity management (PIM)
- Practical understanding of zero-trust architecture and its implementation in a cloud-first environment.
- Experience operating cloud security posture management (CSPM) tooling and remediating cloud security findings.
- Experience with vulnerability management programs and patch compliance tracking.
- Experience supporting governance, risk, and compliance activities, including audit evidence preparation.
- Familiarity with AI-driven security operations capabilities, threat intelligence platforms, and automated incident response (SOAR) workflows.
- Knowledge of relevant regulatory frameworks and security standards (e.g. ISO 27001, NIST CSF, CIS Controls) is highly desirable.
Company Industry
- Engineering Design & Consulting
Department / Functional Area
- IT Software
Keywords
- Cybersecurity And Digital Trust Analyst
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
KEO International Consultants
KEO is a creative enterprise, where innovation is a way of life. We are uniquely resourced with end-to-end services to take clients from inspiration through conceptualization to realization of planning, design or project delivery in the built and natural environments. For over 60 years we ve led with vision, contributing to many of the world s most ambitious projects, iconic places, remarkable experiences and prosperous communities. As a highly integrated and agile AEP/PMCM firm, KEO is recognized by ENR as one of the Top 225 International Design Firms and one of the Top 20 International PM/CM Firms. We are also ranked by World Architecture as the 51st largest global architecture firm and the #1 Firm in the Middle East Region in their 2024 WA100 Survey. We invite you to join us. Why? When you join KEO, you ll discover more than just a job you ll find a supportive environment that fosters your professional development through internal global mobility and career development and does so within a culture that supports company-wide health and well-being through on-demand counselling services and regular workplace clinics. You will be invited to celebrate community events such as sports days, fun-runs, in-house sports teams and beach clean ups. In addition to your competitive package and benefits you will have access to a suite of policies that include hybrid working arrangements, individual athletic sponsorship, study assistance sponsorship, employee referral rewards.