Cybersecurity Engineer
Role Purpose
The Cybersecurity Engineer is responsible for the day-to-day security of KDF's information systems, applications, networks, and digital services. The role covers security monitoring, vulnerability management, and incident handling, and contributes to KDF's cybersecurity governance, risk, and compliance activities under the direction of the Divisional Head – Technology & Digitalization Transformation. The position reports to the Assistant Manager – Technology & Cybersecurity.
As KDF's first dedicated cybersecurity position, the role suits a practitioner who can assess the current environment, identify gaps, and recommend practical improvements rather than wait for direction. The role also offers direct involvement in KDF's ISO 27001 certification programme.
Key Roles and Responsibilities
- Run day-to-day security monitoring across endpoint protection platforms and Microsoft Defender, investigating and escalating alerts as required.
- Investigate suspicious activity, phishing reports, and identity-related security events through to resolution.
- Conduct vulnerability scans, assess and prioritise findings, and drive remediation with infrastructure and application teams until closure.
- Handle cybersecurity incidents, including containment, evidence collection, root-cause review, and documentation.
- Administer and review multi-factor authentication, Conditional Access policies, privileged accounts, and periodic user access reviews.
- Assess KDF's current security posture, identify control gaps, and recommend improvements with clear justification and priority.
- Maintain the cybersecurity risk register and contribute to the development of policies, standards, and procedures.
- Support KDF's ISO 27001 certification programme, including control implementation, evidence preparation, and closure of nonconformities within agreed timelines.
- Maintain security records and evidence, including access review records, incident logs, vulnerability scan results, and remediation history.
- Support internal and external audits by preparing evidence and tracking closure of findings and corrective actions.
- Contribute to alignment with the NIST Cybersecurity Framework and applicable Kuwait regulatory requirements.
- Support the evaluation and implementation of additional security capabilities, including centralised log management and SIEM.
- Deliver cybersecurity awareness activities, including phishing simulations and refresher training.
- Prepare regular security reports and dashboards for management, highlighting risks, trends, and recommended actions.
Skills
Requirements
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Management Information Systems, or a related discipline. A degree or specialisation in Cybersecurity is an advantage.
- Minimum five years of hands-on cybersecurity experience, including direct responsibility for monitoring and incident handling.
- Practical working experience with Microsoft Defender for Endpoint and Office 365, and Microsoft Entra ID, including Conditional Access and MFA administration.
- Experience with vulnerability scanning tools and end-to-end remediation follow-up.
- Exposure to SIEM or centralised log management platforms, ideally Microsoft Sentinel.
- Working knowledge of ISO 27001 and the NIST Cybersecurity Framework. Prior involvement in an ISO 27001 implementation or certification is a strong advantage.
- Sound judgement and the ability to work independently in a small team with limited supervision.
- Clear written and spoken English, with the ability to explain security matters to non-technical colleagues.
Certifications
- CompTIA Security+ or Microsoft SC-200 required, or willingness to obtain within the first year.
- Microsoft SC-300, CEH, or ISO 27001 Lead Implementer an advantage.