- Home
- Jobs
- Apex Employment Services
- Cyber security Engineer - privileged Access Management
Cyber security Engineer - privileged Access Management
Job Description Roles & Responsibilities FortiPAM — Privileged Access Management ▪ Deploy, configure, and administer FortiPAM for centralized management of privileged accounts, credentials, and sessions across on-premises, cloud, and hybrid environments. ▪ Onboard privileged and service accounts (Windows, Linux/Unix, network devices, databases, hypervisors) into vaulted credential stores with automated password rotation policies. ▪ Configure and manage secure remote access workflows (RDP, SSH, HTTPS, database consoles) via FortiPAM's session broker, including session recording, live session monitoring, and just-in-time (JIT) access provisioning. ▪ Implement approval workflows, checkout/check-in policies, and dual-control access for high-risk privileged operations. ▪ Integrate FortiPAM with Active Directory/Entra ID, LDAP, RADIUS, and SAML/SSO providers for identity federation and MFA enforcement on privileged sessions. ▪ Configure granular role-based access control (RBAC) and least-privilege policies aligned with job function and risk tier. ▪ Set up session recording storage and retention policies, and integrate recorded sessions with SIEM/SOC workflows for forensic review. ▪ Conduct periodic access reviews, orphaned and stale privileged account audits, and credential rotation compliance checks. ▪ Troubleshoot connectivity, authentication, and session-broker issues between FortiPAM and target endpoints or devices. ▪ Develop and maintain break-glass / emergency access procedures for FortiPAM outages. FortiDLP — Data Loss Prevention ▪ Design, implement, and tune FortiDLP policies to detect and prevent unauthorized transfer of sensitive data (PII, PHI, financial data, intellectual property) across endpoints, email, web, and removable media channels. ▪ Build and maintain data classification schemas and fingerprinting/pattern-matching rules (regex, exact data match, document fingerprinting, OCR-based detection for scanned or image content). ▪ Configure endpoint DLP agents for monitoring and blocking of USB, cloud upload (SaaS/CASB integration), print, clipboard, and screen-capture activities. ▪ Integrate FortiDLP with FortiMail and web/proxy gateways to enforce consistent data-protection policy across all egress channels. ▪ Analyze DLP incident alerts, tune detection thresholds to reduce false positives, and produce incident investigation reports for compliance and legal review. ▪ Collaborate with data owners and compliance teams to define sensitivity labels and policy exceptions in line with regulatory requirements, including healthcare data protection standards. ▪ Maintain audit trails and generate DLP compliance reporting for internal audits and regulatory assessments. ▪ Perform periodic policy simulation and testing (tabletop and live data-exfiltration test scenarios) to validate DLP efficacy. FortiMail — Email Security Gateway ▪ Administer FortiMail in gateway/transparent mode across a multi-tenant Microsoft 365 and hybrid Exchange environment. ▪ Configure and maintain SPF, DKIM, and DMARC records/policies across all managed domains; monitor DMARC aggregate and forensic reports for spoofing and delivery issues. ▪ Design and tune anti-spam, anti-phishing, anti-malware, impersonation analysis, and URL/attachment sandboxing policies. ▪ Configure and manage SMTP relay validation, connection security (TLS enforcement, opportunistic vs. forced TLS), and IP reputation/greylisting policies. ▪ Manage Protected Identities / executive impersonation protection features and business email compromise (BEC) detection rules. ▪ Integrate FortiMail with Microsoft Graph API for journaling, quarantine management, and mailbox-level remediation actions. ▪ Maintain multi-tenant domain onboarding, per-tenant policy segregation, and delegated administration structures. ▪ Conduct User Acceptance Testing (UAT) for FortiMail policy changes and upgrades, including test-execution documentation and vendor coordination. ▪ Monitor mail queues and bounce/NDR patterns, and troubleshoot mail-flow issues across hybrid Exchange/M365 routing. ▪ Perform regular review of quarantine, false positive/negative tuning, and end-user release-request handling. ▪ Maintain disaster recovery and high-availability configuration for FortiMail clusters. Desired Candidate Profile We are seeking a hands-on Cybersecurity Engineer to design, deploy, and manage our Privileged Access Management, Data Loss Prevention, and Email Security infrastructure built on the Fortinet security suite (FortiPAM, FortiDLP, FortiMail). The successful candidate will be responsible for securing privileged credentials and sessions, preventing sensitive data exfiltration, and protecting the organization's email ecosystem against phishing, spoofing, and business email compromise. This role requires deep technical expertise in privileged session management, data classification and policy engineering, and mail security gateway architecture, along with the ability to work cross-functionally with network, SOC, and compliance teams to continuously mature the organization's security posture. Employment Type Full-time Company Industry IT - Hardware & Networking Department / Functional Area IT Hardware SupportIT Hardware Repair & Maintenance Keywords Security InfrastructureFortipamCyberarkFortidlpSPFDKIMDMARCMTASts OperatorRABC Get real-time job updates only on our App
Ready to apply?
You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.
Apply NowOpens the employer's site in a new tab
- CompanyApex Employment Services
- LocationDubai, UAE
- CategoryCybersecurity
- SourceNaukrigulf
- Listedjust now
Related Cybersecurity jobs
Strategic Finance & Investment Banking Manager
ABOUT THNDR Thndr is Egypt's leading digital retail investment platform and the country's first investment supermarket. We were ranked the number one fastest…
Senior Research Officer - MSNA
POSITION PROFILE This position is situated within the Research Systems Unit (RSU) of the Global Programmes Section. Under the overall guidance of the Research…
Security Solutions Specialist - Network Operations
Operate and maintain FortiNAC (or equivalent NAC platform) for day-to-day endpoint visibility, profiling, posture assessment, and access enforcement. Monitor…
Design Engineer (Geotechnical / Piling)
Perform detailed geotechnical analysis and design of various piling solutions, including driven piles, bored piles, and micropiles, ensuring structural…