417,786open jobs
14,314companies
60,729added this week
Browse all
Location
In office (Doha)
Seniority
Senior · 8+ years exp
Overview
Company
Impact
Profile match
Malomatia is a Qatar-born technology services and digital transformation provider founded to support the nation's public and private sectors. The company specializes in delivering integrated IT solutions, including cybersecurity, cloud services, data and AI, enterprise application modernization, and large-scale contact center operations. By partnering with government agencies, healthcare institutions, and major enterprises, it plays a key role in driving technology-led innovation and economic diversification.

We are seeking a skilled Senior Cybersecurity Consultant to join our Cybersecurity Practice as an Incident Handler within our security operations function. In this role, you will lead the detection, investigation, containment, and recovery of security incidents across enterprise and cloud environments, with a strong focus on the Microsoft security ecosystem.

Your responsibilities will center on incident handling and response, threat detection and hunting, and the day-to-day operation of Microsoft security tooling including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Data Loss Prevention (DLP). You will drive incidents through the full response lifecycle and continuously improve detection and response capabilities.

You will work closely with SOC analysts, threat intelligence, and IT operations teams to triage alerts, lead investigations, coordinate containment and eradication, and conduct post-incident reviews. You will also tune detections, develop response playbooks, and support proactive threat hunting across the Microsoft 365 and Azure estate.

The role requires deep, hands-on operational expertise in incident response and the Microsoft security stack, strong analytical and forensic capabilities, and the ability to remain calm and decisive under pressure during active security incidents.

  • Incident Handling & Response: Lead the end-to-end handling of security incidents, including detection, triage, investigation, containment, eradication, and recovery, in line with established incident response processes and SLAs.
  • Microsoft Defender (EDR/XDR): Operate, tune, and investigate using Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps to detect and respond to threats across endpoints, identities, email, and cloud workloads.
  • Microsoft Sentinel (SIEM/SOAR): Use Microsoft Sentinel for log analysis, correlation, and automated response. Develop and tune analytic rules, KQL queries, workbooks, and SOAR playbooks to improve detection coverage and response efficiency.
  • Microsoft Purview & Data Security: Leverage Microsoft Purview for data governance, information protection, insider risk management, and compliance. Investigate data-related alerts and support data security and DLP operations.
  • Data Loss Prevention (DLP): Configure, monitor, and respond to DLP policies across Microsoft 365 and endpoints to detect and prevent unauthorized data exfiltration, and refine policies to reduce false positives.
  • Threat Hunting & Detection Engineering: Conduct proactive threat hunting across the Microsoft 365 and Azure estate, develop new detections, and continuously improve detection logic based on threat intelligence and lessons learned.
  • Forensics & Root Cause Analysis: Perform host, endpoint, and cloud-based investigations and digital forensics to determine root cause, scope, and impact of incidents, preserving evidence in line with best practices.
  • Documentation & Reporting: Produce high-quality incident reports, timelines, and post-incident reviews. Maintain runbooks and playbooks, and provide clear incident updates to internal stakeholders and clients.
  • Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience: At least 8 years of experience in cybersecurity operations, incident response, or security monitoring, with significant hands-on experience operating Microsoft security tools.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
    • Microsoft Security Operations Analyst (SC-200)
    • Microsoft Certified: Cybersecurity Architect (SC-100) or Information Protection (SC-400)
    • GIAC incident response / forensics (e.g., GCIH, GCFA) or equivalent
    • ISC2 (e.g., SSCP or CISSP) or CompTIA CySA+.

  • Technical Skills: Strong hands-on experience with the Microsoft security stack, including Microsoft Defender (EDR/XDR), Microsoft Sentinel, Microsoft Purview, and Microsoft 365 DLP. Proficiency with KQL for investigation and detection. Experience with EDR investigation, log analysis, SIEM/SOAR, endpoint and cloud forensics, and identity platforms (Entra ID and Active Directory). Familiarity with scripting (e.g., PowerShell) for automation is preferred.
  • Knowledge: Strong understanding of incident response methodologies and frameworks (e.g., NIST SP 800-61, SANS), the MITRE ATT&CK framework, the cyber kill chain, and modern attacker techniques. Solid grasp of cybersecurity principles including defense-in-depth, zero trust, and least privilege. Familiarity with ISO 27001 and CIS Benchmarks. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
417,786 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Doha
In office • Full-Time • Sydney
DevOps
Splunk
Azure
Cybersecurity
Microsoft Sentinel
ISO 27001
Apply
$22k – $52k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Malaysia
DevOps
GCP
Azure
AWS
Apply
$66k – $142k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Madrid
Python
Java
PowerShell
Java
Spring Boot
DevOps
Terraform
Ansible
GCP
OpenShift
Helm
Azure
CI/CD
AWS
Kubernetes
Configuration Management
Apply
$20k – $50k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
Java
TypeScript
Node JS
COBOL
Python
Poetry
Java
Maven
Spring Boot
Spring MVC
Gradle
COBOL
IBM MQ
Databases
PostgreSQL
RabbitMQ
ActiveMQ
Apache Kafka
Kafka
Frontend
GraphQL
Angular
React.js
Mobile
JUnit
DevOps
gRPC
GCP
OpenShift
WebSockets
Azure
CI/CD
AWS
Kubernetes
QA
Pytest
Apply
$145k – $218k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Mississauga
Python
Java
AI/ML
LangChain
Claude
NLP
Llama
TensorFlow
PyTorch
RAG
Hugging Face
OCR
DevOps
GCP
Azure
AWS
Docker
Kubernetes
Apply
In office • Bachelor's Degree • Doha
Apex
Apex
MuleSoft
DevOps
OpenShift
Azure DevOps
Azure
CI/CD
QA
Swagger
Postman
Apply
In office • 10+ years exp • Bachelor's Degree • Doha
Databases
Databricks
DevOps
Azure
Cybersecurity
Microsoft Entra ID
Analytics
Power BI
Apply
NOC Team Lead 2 days ago
In office • 5+ years exp • Doha
DevOps
AIOps
Incident Management
SLI/SLO/SLA
Apply
In office • 6+ years exp • Bachelor's Degree • Doha
SQL
Databases
Oracle
DevOps
Incident Management
Management
ServiceNow
Apply
In office • 3+ years exp • Bachelor's Degree • Doha
DevOps
CI/CD
Cybersecurity
Burp Suite
Snyk
OWASP Top 10
OWASP ASVS
QA
Postman
Apply
Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Doha
Management
Microsoft Project
Apply
In office • Full-Time • 5+ years exp • Doha
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Doha
Apply
Machine Operator 1 day ago
In office • Full-Time • Doha
Design
Adobe Photoshop
Adobe Illustrator
Apply
In office • Full-Time • 2+ years exp • High School Diploma • Doha
Apply
See all jobs
This is one of many
417,786 more open roles from verified company boards, updated every day.