DLP, CASB & Access Security Analyst – 24/7 Operations
Location: Doha, Qatar
Working Arrangement: Full-time, on-site at client premises
Company: Command Post
About Command Post
Command Post is a cybersecurity and AI technology company delivering security operations, threat intelligence, application security, AI assurance, governance, risk, compliance, privacy and data protection services across the Middle East.
Role
We are seeking experienced L1 & L2 DLP, CASB and Access Security Analysts to support a large enterprise customer in Qatar. The successful candidates will operate as part of a 24/7 security monitoring service focused on protecting sensitive information, monitoring cloud application activity and investigating suspicious or unauthorised access.
Key Responsibilities
- Monitor, triage and investigate DLP, CASB, identity, privileged-access and user-activity alerts.
- Investigate data leakage, inappropriate file sharing, external transfers, mass downloads, removable-media usage and other suspicious handling of sensitive information.
- Analyse activity across endpoints, cloud applications, identity platforms, access-management systems and monitoring technologies.
- Investigate access management, unusual authentication activity, excessive privileges, unauthorised access and potential insider-risk events.
- Monitor sanctioned and unsanctioned cloud applications using Microsoft Defender for Cloud Apps, Zscaler and related platforms.
- Correlate alerts with business context, data classifications, user roles and approved access to determine whether activity is malicious, unauthorised or legitimate.
- Escalate confirmed incidents and support containment, remediation and access-restriction activities.
- Maintain accurate investigation records, evidence, shift handovers and operational reports.
- Support policy tuning, dashboard development, platform monitoring and continuous improvement of DLP, CASB and access-security controls.
Technology Experience
Experience with one or more of the following is highly desirable:
- Microsoft Defender for Cloud Apps, formerly MCAS
- Zscaler CASB, ZIA or ZPA
- Microsoft Purview DLP and Information Protection
- Symantec, Forcepoint, Trellix or other enterprise DLP platforms
- Microsoft Sentinel or other SIEM platforms
- Microsoft Entra ID
- Xage Security
- CyberArk, BeyondTrust, Delinea or other privileged-access platforms
- Microsoft Defender XDR or other endpoint-security technologies
Candidates are not expected to have experience with every listed platform. Relevant experience with comparable enterprise security technologies will be considered.
Required Experience
- Experience in DLP, CASB, identity security, access monitoring, security operations or incident investigation.
- Understanding of data-loss scenarios, cloud-security risks, insider threats and inappropriate data handling.
- Knowledge of authentication, authorisation, privileged access and least-privilege principles.
- Ability to analyse user, endpoint, application, identity and network activity.
- Familiarity with SIEM searches, log analysis and alert correlation.
- Strong analytical, investigation, documentation and communication skills.
- Ability to handle sensitive and confidential information professionally.
- Willingness to work full-time on-site in Doha and participate in a 24/7 rotational shift schedule.
Advantageous Experience
- Insider-risk monitoring
- Digital forensics or incident response
- User and Entity Behaviour Analytics
- Endpoint Detection and Response
- DLP or CASB policy configuration and tuning
- SOAR and security automation
- Financial services, government, energy or critical-infrastructure environments
- Large enterprise SOC or managed-security service experience