Cybersecurity Specialist - IAM and Vulnerability Management
BlackStone eIT · 13 days ago
Provide secured remote operational support across identity and access management and vulnerability management. The role performs approved technical activities and tracking; access approvals, security policy, risk acceptance and regulatory accountability. • Support user, privileged and service-account administration through approved requests and access workflows. • Assist with periodic access reviews, joiner/mover/leaver controls and evidence preparation. • Operate approved vulnerability scanning and reporting tools and validate findings with system owners. • Maintain vulnerability, exception and remediation trackers and coordinate technical follow-up. • Support IAM, MFA, privileged-access and directory-service incidents within authorised access boundaries. • Provide metrics, evidence and trend analysis for security reporting and governance reviews. • Escalate overdue, critical or policy-related matters to the onsite Security Engineer. • Maintain operational procedures, access-control records and vulnerability-management documentation. • Minimum 5 years of relevant IAM and/or vulnerability-management experience, with credible practical exposure to both domains. • Experience with Microsoft identity services, SailPoint, CyberArk or equivalent IAM/PAM platforms. • Experience with enterprise vulnerability-scanning and remediation-tracking platforms. • Microsoft Identity, SailPoint, CyberArk, CEH, OSCP, GPEN or equivalent certification preferred. • Strong understanding of privileged access, least privilege, remediation governance and audit evidence. Preferred Profile • Previous experience supporting UAE government or regulated cybersecurity environments. • Working knowledge of TDRA-hosted environments and related security-access processes. • Experience operating through secured remote-access and privileged-session controls. Expected Contribution • Access and vulnerability activities are completed only through approved workflows. • Critical findings and overdue actions are escalated with clear ownership. • Evidence and trackers remain accurate, current and audit-ready.