DLP, CASB & Access Security Analyst – 24/7 Onsite Operations in Doha
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 മണിക്കൂർ മുൻപ്
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
Company Overview
Command Post QFZ LLC is a cybersecurity and artificial intelligence technology provider delivering a wide range of security services including security operations, threat intelligence, application security, AI assurance, governance, risk management, compliance, privacy, and data protection throughout the Middle East region.
Position Summary
We are looking for experienced Level 1 and Level 2 Analysts specializing in Data Loss Prevention (DLP), Cloud Access Security Broker (CASB), and Access Security. These analysts will support a significant enterprise client in Qatar and contribute to a 24/7 security monitoring team. The primary aim is to protect sensitive information, oversee cloud application activities, and investigate unauthorized or suspicious access events.
Key Responsibilities
- Continuously monitor, prioritize, and investigate alerts related to DLP, CASB, identity and privileged access, along with user activities.
- Conduct probes into incidents such as data leaks, improper file sharing, outside data transfers, large volume downloads, and use of removable media that pose risks to sensitive data.
- Analyze events occurring across endpoints, cloud platforms, identity and access management systems, and other monitoring tools.
- Review access management events, irregular authentication, privilege escalations, unauthorized access, and potential insider threats.
- Track activity on both authorized and unauthorized cloud applications utilizing Microsoft Defender for Cloud Apps, Zscaler, and similar platforms.
- Correlate alert data with organizational context including data classification, user roles, and granted permissions to assess legitimacy.
- Escalate verified security incidents and assist in containment, remediation, and access restriction procedures.
- Keep thorough and precise records of investigations, evidence, shift transitions, and operational reports.
- Contribute to enhancing policies, dashboards, platform health monitoring, and continuous improvement of DLP, CASB, and access control measures.
Required Technical Experience
Experience with one or more of the following systems is highly valued, although not mandatory to have all:
- Microsoft Defender for Cloud Apps (previously MCAS)
- Zscaler CASB, ZIA, or ZPA
- Microsoft Purview DLP and Information Protection
- Enterprise DLP platforms such as Symantec, Forcepoint, or Trellix
- SIEM solutions like Microsoft Sentinel
- Microsoft Entra ID
- Xage Security
- Privileged access management tools including CyberArk, BeyondTrust, Delinea
- Endpoint security products such as Microsoft Defender XDR
Candidate Requirements
- Prior experience with DLP, CASB, identity security, access monitoring, security operations, or cyber incident investigation.
- Good understanding of common data loss scenarios, cloud security vulnerabilities, insider threat landscapes, and improper data handling risks.
- Solid grasp of authentication and authorization mechanisms, privileged access concepts, and the principle of least privilege.
- Strong ability to analyze behavior and events linked to users, endpoints, cloud applications, identity management, and network traffic.
- Familiarity with SIEM searches, log evaluation, and correlating alerts for security insights.
- Excellent analytical thinking, investigative aptitude, documentation precision, and communication skills.
- Demonstrated ability to manage sensitive and confidential information responsibly.
- Ready to work on-site in Doha full time and participate in a rotational shift system covering 24/7 operations.
Additional Preferred Experience
- Skills in insider risk monitoring
- Background in digital forensics or incident response
- Experience with User and Entity Behavior Analytics (UEBA)
- Exposure to Endpoint Detection and Response (EDR) tools
- Hands-on DLP or CASB policy creation and tuning
- Familiarity with SOAR platforms and security process automation
- Knowledge of security in financial services, government sector, energy, or critical infrastructure
- Experience working within large enterprise Security Operations Centers (SOC) or managed security services