371,442open jobs
9,588companies
49,492added this week
Browse all
Salary
$160k – $220k per year
Location
In office (Saratoga)
Seniority
Principal
Employment
Full-Time
Overview
Company
Impact
Profile match
An award-winning real estate agency based in the Dubai Marina, Espace offers industry-leading service and extensive knowledge through a team of friendly and multilingual property experts.

What is this role:

    We are seeking a deeply technical, hacker-savvy Principal Cybersecurity Lead to defend the company as an active operator, security engineer, and incident leader. This person will understand how modern attackers discover, enter, persist, move laterally, exfiltrate data, and hide. They will continuously track active threat campaigns, newly exploited vulnerabilities, attacker tools, and changes in the global threat landscape, then convert that intelligence into practical defenses.

    This is not a policy-only, advisory-only, or dashboard-only position. The successful candidate will make consequential security decisions, personally investigate suspicious activity, write production-quality detection and response code, interrogate network and endpoint telemetry, validate controls through authorized adversarial testing, and drive incidents to a technically sound conclusion. They must be willing to go deep enough to understand the vulnerability, exploit path, affected systems, attacker behavior, business impact, containment choice, and permanent corrective action.

What you will do:

    Threat intelligence and attacker awareness

    • Continuously monitor active threat campaigns, ransomware groups, state-sponsored actors, criminal ecosystems, exploit trends, malware families, phishing infrastructure, and newly weaponized vulnerabilities relevant to the company.
    • Translate threat intelligence into detection hypotheses, hunting queries, control changes, exposure reviews, and prioritized defensive action - not passive reporting.
    • Maintain a current view of attacker tactics, techniques, and procedures using practical frameworks such as MITRE ATT&CK while recognizing where real-world behavior departs from frameworks.
    • Build trusted relationships with relevant industry, vendor, law-enforcement, and information-sharing communities as appropriate.
    • Enterprise security architecture and attack-surface ownership

      • Understand and secure enterprise routing, switching, segmentation, DNS, DHCP, VPN, wireless, firewalls, proxies, email, identity providers, directory services, SaaS, cloud, remote access, endpoints, servers, containers, and CI/CD environments.
      • Map external and internal attack surfaces, trust boundaries, privileged paths, crown-jewel systems, internet exposure, shadow IT, third-party access, and plausible attack chains.
      • Drive secure architecture decisions across identity, zero-trust access, network segmentation, secrets, cryptography, logging, endpoint protection, cloud controls, backup resilience, and recovery.
      • Partner with infrastructure, product, software, IT, legal, privacy, and physical-security teams to reduce systemic risk without creating unusable controls.
      • Detection engineering, coding and automation

        • Write, review, test, and maintain code that detects malicious or abnormal behavior across network, endpoint, identity, application, and cloud telemetry.
        • Develop behavioral analytics, correlation logic, enrichment pipelines, investigation tools, automated containment workflows, and repeatable forensic utilities.
        • Create high-quality SIEM/EDR/NDR detections and hunting content; measure precision, recall, coverage, false positives, alert latency, and operational value.
        • Use languages such as Python, Go, Rust, PowerShell, shell, SQL, or equivalent as the problem requires; work comfortably with APIs, event streams, structured logs, packet data, and large security datasets.
        • Apply software-engineering discipline to security code: version control, peer review, tests, deployment controls, observability, rollback, documentation, and secure secrets handling.
        • Threat hunting, insider risk and incident response

          • Proactively hunt for weak signals, anomalous sequences, living-off-the-land activity, identity abuse, covert persistence, unauthorized privilege, lateral movement, unusual data access, and exfiltration.
          • Investigate potential internal and external threats lawfully and proportionately, using authorized data sources, need-to-know access, privacy safeguards, and documented evidence handling.
          • Lead triage, scoping, containment, eradication, recovery, forensics, root-cause analysis, and post-incident improvement for serious events.
          • Preserve evidence and timelines suitable for executive, legal, regulatory, insurance, and law-enforcement needs when applicable.
          • Design and run incident simulations, purple-team exercises, detection validation, and authorized adversary emulation; ensure findings become durable engineering improvements.
          • Vulnerability and exposure management

            • Own risk-based vulnerability management across infrastructure, endpoints, cloud, applications, dependencies, appliances, and third-party services.
            • Distinguish theoretical severity from real exploitability by considering exposure, privileges, reachable attack paths, available exploits, compensating controls, asset value, and active exploitation.
            • Drive remediation of critical weaknesses and validate fixes through retesting, telemetry, and control verification.
            • Establish emergency processes for zero-days and mass-exploitation events, including rapid inventory, containment, patching, workaround validation, and executive updates.
            • Leadership and security operations

              • Act as the company's senior technical decision-maker during serious cyber events. Decide when to isolate systems, disable accounts, block traffic, interrupt business processes, invoke outside support, or accept short-term operational risk - and document the evidence and reasoning behind those decisions.
              • Set the technical direction, operating model, priorities, metrics, and quality bar for detection, response, threat hunting, vulnerability management, and security engineering.
              • Recruit, mentor, and raise the capability of security engineers and analysts while remaining personally capable of deep technical investigation and coding.
              • Communicate risk in concrete business terms: what can happen, how likely it is, what evidence exists, what must be done, who owns it, and by when.
              • Build trusted escalation paths and an on-call model that supports decisive action without normalizing burnout or uncontrolled surveillance.
              • Decision ownership and technical depth

                • Own security decisions from incomplete initial signal through validated conclusion; state what is known, what is unknown, the confidence level, the immediate risk, and the next decision point.
                • Dive personally into the highest-risk vulnerabilities and incidents. Read logs, inspect packets, trace identities and privileges, review configurations and code, reproduce issues safely, challenge assumptions, and verify that remediation actually closes the attack path.
                • Prioritize vulnerabilities by real business exposure and attacker opportunity rather than CVSS score alone; connect individual weaknesses into plausible multi-step attack chains.
                • Refuse both analysis paralysis and reckless action. Make reversible decisions quickly when possible, escalate irreversible decisions appropriately, and update direction as evidence changes.
                • Maintain clear ownership through closure: containment is not completion. Require root cause, durable remediation, detection coverage, regression testing, and accountable follow-through.

What you will bring to this role:

    • Substantial hands-on experience defending complex corporate environments and leading high-severity investigations from initial signal through containment and root cause.
    • Demonstrated hacker mindset and practical knowledge of exploitation, persistence, credential theft, identity attacks, lateral movement, evasion, command-and-control, and exfiltration - applied only in authorized and ethical contexts.
    • Deep understanding of TCP/IP, DNS, HTTP/TLS, routing, segmentation, firewalls, proxies, VPNs, wireless, endpoint internals, Windows and Linux, identity systems, cloud services, and enterprise logging.
    • Strong programming ability and evidence of building security detections, analytics, automation, or investigation tooling used in real operations.
    • Expertise with SIEM, EDR/XDR, NDR, IAM, cloud security telemetry, vulnerability tooling, packet/log analysis, and digital-forensics methods; vendor-specific experience is less important than first-principles understanding.
    • Ability to reason from incomplete or conflicting evidence, form and test hypotheses, quantify confidence, and recognize when an alert is noise, an isolated event, or part of a larger campaign.
    • Demonstrated record of making high-impact security decisions under time pressure and personally validating the technical evidence rather than delegating all analysis to vendors or junior staff.
    • Sound judgment regarding privacy, employee monitoring, legal authorization, evidence preservation, disclosure, and the boundary between defensive validation and unauthorized access.
    • Clear written and verbal communication with engineers, executives, legal counsel, employees, customers, and external responders during high-pressure events.

Bonus points:

    • Experience in a technology company with valuable intellectual property, distributed operations, sensitive customer data, or high-availability infrastructure.
    • Defense-industry cybersecurity experience is a plus, including supporting CMMC readiness and self-assessment, collecting and maintaining defensible control evidence, tracking remediation, and completing authorized self-reporting accurately and on time.
    • Experience establishing or materially improving a threat-hunting, detection-engineering, incident-response, or security-operations function.
    • Background in reverse engineering, malware analysis, exploit analysis, cloud incident response, identity forensics, or network protocol analysis.
    • Experience with threat-informed defense, purple teaming, security data engineering, and detection-as-code.
    • Relevant research, open-source security contributions, conference work, responsible disclosures, certifications, or competitive security experience - valued as evidence, not substitutes for demonstrated capability.

Additional Requirements

    This is a fast-paced, high-impact environment - flexibility to occasionally work extended hours or weekends during critical periods is expected.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
371,442 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Saratoga
OKTA- IAM Engineer 5 hours ago
$87k – $178k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree
PowerShell
Python
DevOps
IAM
Cybersecurity
CyberArk
HIPAA
Least Privilege
Microsoft Entra ID
Okta
Apply
$16k – $47k per year (Estimated) • In office • Full-Time • 4+ years exp • Bengaluru
Python
Databases
Apache Kafka
DevOps
Ansible
CI/CD
Configuration Management
Git
GitHub
GitLab
GitLab CI
Jenkins
Puppet
Splunk
Ubuntu
Management
Confluence
ServiceNow
Apply
$85k – $110k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
Java
SQL
AI/ML
Copilot
DevOps
AWS
CI/CD
Docker
Git
GitLab
Jenkins
Kubernetes
Apply
$38k – $81k per year (Estimated) • Remote/Hybrid • Full-Time • France
PowerShell
Python
DevOps
Hyper-V
VMWare
Apply
$96k – $209k per year • Remote • Full-Time • 6+ years exp • Bachelor's Degree
Python
Scala
SQL
Python
pySpark
Databases
Apache Kafka
Databricks
AI/ML
Spark
DevOps
Azure
Azure DevOps
CI/CD
Terraform
Cybersecurity
HIPAA
Analytics
Power BI
Tableau
Marketing
Salesforce
Apply
$160k – $200k per year • In office • Full-Time • 10+ years exp • Saratoga
Bash
Python
AI/ML
Anomaly Detection
DevOps
AWS
Azure
GCP
Grafana
Kibana
Prometheus
SLI/SLO/SLA
Apply
$150k – $250k per year • In office • Full-Time • 5+ years exp • Saratoga
Python
Databases
InfluxDB
TimescaleDB
PostgreSQL
AI/ML
Time Series Forecasting
DevOps
AWS
AWS CDK
CI/CD
Git
Terraform
Analytics
ETL/ELT
IoT
LoRaWAN
Matter
Zigbee
Apply
$150k – $225k per year • In office • Full-Time • 5+ years exp • Saratoga
Python
SQL
Python
Django
FastAPI
Flask
Databases
PostgreSQL
Redis
DevOps
Amazon EC2
Amazon S3
AWS
AWS CDK
AWS Lambda
CI/CD
Git
Rest API
Terraform
WebSockets
IoT
MQTT
Apply
$140k – $160k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Saratoga
Python
DevOps
CI/CD
Git
Proxmox VE
VMWare
Cybersecurity
Tcpdump
Wireshark
Management
Jira
Apply
$119k – $237k per year (Estimated) • In office • Full-Time • Arlington
Apply
$160k – $200k per year • In office • Full-Time • 10+ years exp • Saratoga
Bash
Python
AI/ML
Anomaly Detection
DevOps
AWS
Azure
GCP
Grafana
Kibana
Prometheus
SLI/SLO/SLA
Apply
$150k – $250k per year • In office • Full-Time • 5+ years exp • Saratoga
Python
Databases
InfluxDB
TimescaleDB
PostgreSQL
AI/ML
Time Series Forecasting
DevOps
AWS
AWS CDK
CI/CD
Git
Terraform
Analytics
ETL/ELT
IoT
LoRaWAN
Matter
Zigbee
Apply
$150k – $225k per year • In office • Full-Time • 5+ years exp • Saratoga
Python
SQL
Python
Django
FastAPI
Flask
Databases
PostgreSQL
Redis
DevOps
Amazon EC2
Amazon S3
AWS
AWS CDK
AWS Lambda
CI/CD
Git
Rest API
Terraform
WebSockets
IoT
MQTT
Apply
$113k – $189k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Saratoga
Design
AutoCAD
Apply
$140k – $160k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Saratoga
Python
DevOps
CI/CD
Git
Proxmox VE
VMWare
Cybersecurity
Tcpdump
Wireshark
Management
Jira
Apply
See all jobs
This is one of many
371,442 more open roles from verified company boards, updated every day.