About the Role
KAUST is undertaking a Cybersecurity Transformation Program focused on secure cloud and hybrid environments across its multi-cloud environments. The organization emphasizes modern security architectures, Zero Trust, and sustainable operational handover, working closely with internal teams and delivery partners to modernize security operations, cloud security posture, identity, and network security.
Kaust is seeking a hands-on cloud security engineering role responsible for designing, implementing, and assuring secure cloud and hybrid environments across KAUST's multi-cloud environments. The role combines solution architecture with direct technical execution across cloud security, identity, endpoint, security operations, Zero Trust, and modern workplace security. The incumbent will translate security requirements into deployable technical controls, lead complex implementation activities, resolve cross-platform dependencies, and ensure solutions are operationally supportable and measurable. The role will work across multiple portfolio initiatives rather than a single technology program. As a start, Microsoft 365 A5 is one major project within the portfolio, alongside other initiatives such as Enterprise IAM, cloud security posture improvement, security operations integration, network security and segmentation, cyber exposure reduction, and related security modernization efforts. The engineer is expected to remain personally hands-on in design, configuration, integration, troubleshooting, testing, remediation, and knowledge transfer while providing technical direction to partners and internal teams.
Responsibilities
- Own cloud security architecture and engineering activities across assigned initiatives within the Cybersecurity Transformation Program, from design through implementation, stabilization, and operational handover.
- Assess Azure, Microsoft 365, hybrid, and where relevant multicloud environments to identify security gaps, technical dependencies, and opportunities for control improvement.
- Design and implement secure cloud architectures aligned with KAUST security principles, enterprise architecture standards, operational requirements, and Zero Trust objectives.
- Provide hands-on engineering across Microsoft Entra ID, Conditional Access, Privileged Identity Management, Identity Protection, MFA and passwordless controls, Intune, Defender XDR, Defender for Cloud, Microsoft Sentinel, Microsoft Purview, and related Microsoft security capabilities.
- Engineer and improve cloud security posture management, workload protection, attack-path reduction, logging, monitoring, and security configuration across IaaS, PaaS, SaaS, endpoint, and identity environments.
- Design and implement integrations between cloud platforms and Security Operations, including SIEM/SOAR telemetry, detection use cases, KQL analytics, incident automation, threat intelligence, and operational monitoring requirements.
- Apply Zero Trust principles across identity, privileged access, endpoints, applications, network access, collaboration, and data, ensuring controls operate coherently across cloud and hybrid dependencies.
- Develop secure connectivity and access patterns for cloud and hybrid environments, working with network security teams on segmentation, firewalling, secure remote access, private connectivity, DNS, and related controls where required.
- Lead technical design decisions, configuration reviews, proof-of-concept activities, testing, troubleshooting, and remediation for assigned cloud security initiatives.
- Review and challenge designs proposed by Microsoft, cloud providers, and delivery partners; ensure technical proposals meet KAUST security, architecture, resilience, logging, and operational standards.
- Lead or support migration and modernization activities from legacy security platforms to cloud-native capabilities, ensuring sequencing, coexistence, rollback, and operational continuity are addressed.
- Manage technical dependencies with Enterprise IAM, Saviynt IGA, Network Security and Segmentation, Cyber Exposure Reduction, Security Operations, endpoint management, infrastructure, and application teams.
- Contribute technical leadership to the Microsoft 365 A5 project, including architecture, security configuration, Defender, Entra, Intune, Purview, Security Operations integration, Copilot security controls, testing, pilot readiness, and technical handover as assigned.
- Define technical acceptance criteria, validation evidence, security baselines, implementation standards, and production-readiness requirements for assigned initiatives.
- Proactively identify architecture risks, misconfigurations, security gaps, implementation blockers, and vendor dependencies, and drive them to resolution with clear ownership and escalation.
- Produce high-quality as-built designs, configuration standards, engineering documentation, runbooks, operational procedures, and knowledge-transfer materials.
- Upskill internal technical teams through pairing, technical walkthroughs, design reviews, troubleshooting, and structured knowledge transfer so implemented capabilities can be sustainably operated by KAUST.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Engineering, or a closely related discipline; substantial equivalent professional experience may be considered.
- Advanced Microsoft certifications in Azure architecture, security, identity, Microsoft 365 security, or security operations are strongly preferred.
- Relevant cloud or cybersecurity certifications such as CISSP, CCSP, GIAC cloud security, Microsoft Security certifications, Google/AWS security certifications, or equivalent are advantageous.
- Certifications should support, not substitute for, demonstrable hands-on enterprise cloud security engineering and implementation experience.
Required Skills
- Deep hands-on cloud security engineering expertise across Microsoft Azure and Microsoft 365, with the ability to move comfortably between architecture, configuration, integration, troubleshooting, and operationalization.
- Strong knowledge of Microsoft security technologies including Entra ID, Conditional Access, PIM, Identity Protection, Defender XDR, Defender for Cloud, Intune, Microsoft Sentinel, and Microsoft Purview.
- Strong understanding of cloud security architecture across identity, network, endpoint, workloads, applications, data, logging, monitoring, and security operations.
- Practical experience designing and implementing Zero Trust architectures and identity-centric security controls in enterprise environments.
- Strong understanding of SIEM/SOAR, detection engineering, KQL or comparable query languages, security telemetry onboarding, incident automation, and SOC integration.
- Experience with cloud security posture management, workload hardening, attack-path analysis, secure configuration baselines, and remediation across IaaS, PaaS, and SaaS.
- Ability to design secure hybrid and, where relevant, multicloud integrations, including federation, SSO, network connectivity, logging, and security control alignment.
- Strong technical governance and engineering judgment, including the ability to challenge vendor designs and translate security requirements into practical implementation decisions.
- Ability to lead multidisciplinary technical teams and delivery partners without losing hands-on engagement in critical technical work.
- Strong written and verbal communication, including the ability to explain technical risks, architecture decisions, and delivery implications to both technical and senior stakeholders.
- Evidence-led and outcome-oriented approach, with emphasis