Overview
Information Technology Security Engineer Jobs in Dammam, Eastern, Saudi Arabia at NextEra
Title: Information Technology Security Engineer
Company: NextEra
Location: Dammam, Eastern, Saudi Arabia
Dear All,
NextEra is looking for dynamic resource in IT Security Engineer role.
Job Summary:
This role protects the organization’s Microsoft cloud, identity, endpoint, and network environments by leading threat detection, incident response, and proactive threat hunting across the Microsoft Defender ecosystem. It secures Entra ID with Zero Trust controls and manages Intune to enforce secure configuration, compliance, and patching for Windows, mobile, and macOS devices while implementing Microsoft 365 security and compliance measures. The engineer also strengthens network security through firewall/VPN hardening, segmentation, and monitoring, and maintains incident documentation, playbooks, and reporting.
Responsibilities:
- Design, deploy, and maintain Active Directory and Entra ID environments aligned with security best practices.
- Configure, manage, and optimize the Microsoft Defender suite (Endpoint, Office 365, Identity, Cloud Apps, and Microsoft 365 Defender).
- Implement and maintain Conditional Access, MFA, Identity Protection, PIM, RBAC, and identity based Zero Trust controls.
- Configure threat protection policies, attack surface reduction rules, EDR settings, and endpoint security baselines.
- Monitor risky users, risky sign ins, and identity related security events; support hybrid identity with Azure AD/Entra Connect.
- Manage Microsoft Intune for device compliance, secure configuration, patching, encryption, and application deployment across Windows, mobile, and macOS.
- Enforce MDM/MAM policies and maintain device configuration baselines.
- Configure Microsoft 365 security features including anti phishing, anti-malware, anti-spam, Safe Links, and Safe Attachments.
- Implement data protection and compliance controls such as DLP, sensitivity labels, retention policies, audit logging, and Purview solutions (e.g., Insider Risk, Records Management).
- Review and improve Microsoft Secure Score and ensure Microsoft 365 services meet security and compliance requirements.
- Support network security operations including firewall and VPN hardening, segmentation, secure access controls, and network monitoring.
- Collaborate with infrastructure teams to identify and remediate security gaps and support Zero Trust implementation across identity, endpoint, application, and network layers.
- Harden servers, endpoints, and cloud connected infrastructure.
- Participate in security assessments, audits, vulnerability remediation, and regulatory compliance efforts.
- Respond to security incidents, perform root cause analysis, and implement corrective actions.
- Maintain security documentation, incident response playbooks, and SOPs.
Required Knowledge & Skills:
- 8–12 years of hands-on experience in IT systems, infrastructure, security operations, or identity management.
- Strong experience with Microsoft Security technologies, including Microsoft Defender suite.
- Strong working knowledge of Microsoft Entra ID / Azure Active Directory.
- Experience implementing Conditional Access, MFA, RBAC, Identity Protection, and Privileged Identity Management.
- Hands-on experience with Microsoft Intune Endpoint Management, endpoint security policies and MAC device management.
- Strong understanding of Microsoft 365 security and compliance features.
- Good knowledge of Windows Server, Active Directory, Group Policy, DNS, DHCP, and hybrid identity environments.
- Understanding of network security concepts, including firewalls, VPN, segmentation, proxy, secure remote access, and network monitoring.
- Experience in vulnerability management, security hardening, endpoint protection, and threat remediation.
- Familiarity with Zero Trust security principles and least privilege access models.
- Ability to troubleshoot complex security, identity, endpoint, and infrastructure issues.
- Strong documentation, reporting, and stakeholder communication skills.
Education and Qualification:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
- Any of the following Certifications will be considered an advantage:
- Microsoft Certified: Security, Compliance, and Identity Fundamentals
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Certified: Cybersecurity Architect Expert