Khadamat Facilities Management

Join us

Cyber Security Specialist

Position Purpose

The Cyber Security Specialist is responsible for establishing, managing, and continuously improving the cyber security posture of Khadamat across all business units and contracts. This role functions as the senior point of accountability for all cyber security matters, including governance, risk management, compliance, cloud security, and coordination with the external Managed Security Service Provider (MSSP).

Role Description

Cyber Security Governance & Leadership

  • Serve as the primary focal point for all cyber security matters for Khadamat.
  • Develop, implement, and maintain cyber security policies, procedures, frameworks, and baseline security controls that align with ISO 27001, NIST, and UAE regulatory requirements.
  • Lead cyber security planning, strategy, risk assessments, and maturity improvement initiatives for all Khadamat contracts and business units.
  • Ensure cyber security is integrated into new projects, applications, and cloud services from the design stage onward following the “Security by Design” approach.
  • Represent the cyber security function in management meetings, client engagements, and audit reviews.

Vendor & MSSP Management

  • Oversee and manage the outsourced Managed Security Service Provider (MSSP) covering:
    • 24x7x365 SOC monitoring
    • Incident response & digital forensics
    • Vulnerability assessment and management
    • Penetration testing
    • Active Directory and firewall security reviews
  • Ensure service quality, SLA adherence, timely reporting, and alignment with Khadamat’s security governance.
  • Provide support to the Senior Systems Administrator by handling security-related escalations and inquiries with vendors of CAFM, timetabling systems, ERP cloud platforms, and future digital solutions, ensuring strong governance and oversight.
  • Lead security reviews of third-party vendors and ensure onboarding / offboarding processes include security control checks.

Security Operations & Incident Response

  • Coordinate all security incidents, investigations, and forensics activities with the MSSP, ensuring timely containment, eradication, recovery, and RCA reporting.
  • Oversee phishing simulation campaigns and employee security awareness programs for all Khadamat employees and contractors.
  • Monitor and manage escalations related to malware infections, suspicious activities, compromised accounts, and data leakage events.
  • Maintain documentation related to incidents, evidence collection, and preventive actions.

Vulnerability Management & Compliance

  • Conduct internal vulnerability assessments and risk evaluations on Khadamat-owned systems and cloud platforms.
  • Review MSSP vulnerability reports and ensure remediation actions are executed by the correct internal or external stakeholders.
  • Support compliance requirements for audits, client reviews, merger integration tasks, and IT contractual obligations.
  • Maintain a risk register and coordinate mitigation actions with Systems Administration and Network teams.

Cloud Security Oversight

  • Oversee cyber security controls for cloud-hosted applications including:
    • CAFM Evolution
    • Timetabling System
    • Dynamics 365 / Finance & Operations
    • Any new cloud-based SaaS or PaaS platforms
  • Ensure identity and access management (IAM), MFA, logging, API security, and vendor responsibilities are continuously enforced.
  • Periodically validate data protection, encryption, and backup policies for all cloud services.

Corporate IT Security Support

  • Advise and guide network administrators and system administrators on best-practice security configurations for:
    • Active Directory
    • M365 / Defender Suite
    • Windows Server security hardening
    • Endpoint protection
    • Network segmentation & firewall rules
  • Review and approve security configurations, exceptions, and change requests.
  • Support secure configuration of new acquisitions under Khadamat’s merger programs.

Finance, Procurement & Asset Management

  • Support annual cyber security budget planning, procurement of tools/services, and strategic investment decisions.
  • Participate in vendor evaluations, product comparisons, and RFP processes related to cyber security services.

Stakeholder Engagement

  • Respond to internal and external stakeholders’ requests related to cyber security in a timely and professional manner.
  • Prepare reports, dashboards, and presentations for senior management, clients, auditors, and risk committees.

Quality

  • Contribute to internal documentation, security manuals, SOPs, and governance frameworks.
  • Support ISO compliance audits, internal audits, and any client-specific cybersecurity reviews.

Compliance

  • Ensure that cyber security operations meet UAE regulatory requirements and international standards.
  • Regularly perform compliance checks related to data protection, access control, system hardening, and audit logs.

Risk Management

  • Identify cyber risks across Khadamat operations and escalate high-risk issues to the Head of IT.
  • Maintain a proactive approach to cyber threat detection, prevention, and response.

Ad Hoc Responsibilities

  • Perform additional cyber security duties as assigned and provide expert guidance for IT projects and digital transformation initiatives.

HSE Responsibilities

  • To comply with the organization’s QHSE policies and procedures at all times and to work safely at all times and report all hazards and incidents to Departmental Supervisors/Managers.
  • To actively participate in all QHSE training, programs, audits and inspections when required and, as necessary and to exercise a personal duty of care for their own health, safety and welfare and to that of others.
  • To lead by example and ensure to protect the environment by conservation of electricity, water and other natural resources, and minimizing generation of waste.

Information Security Responsibilities

  • Protect all information assets (digital and physical) from unauthorized access, disclosure, alteration, and destruction.

Knowledge, Skills, and Experience

Key Skills & Attitude

  • Strong technical understanding of cyber security technologies, architectures, and best practices.
  • Effective communication skills in English—verbal and written.
  • Ability to work under pressure and handle security incidents professionally.
  • Critical thinking, analytical mindset, and strong problem-solving skills.
  • Ability to manage external vendors and ensure contractual KPI delivery.
  • Be innovative, creative and solution focused.
  • An ability to work with existing and new IT systems technology.

Background, Experience and Attributes

Essential

  • Bachelor’s degree in computer science, Information Technology, Cyber Security, or equivalent.
  • Minimum 5–7 years of combined experience in systems administration & cybersecurity roles.
  • Hands-on experience with security controls in Windows Server, M365 Defender, Active Directory, cloud platforms, and enterprise monitoring.
  • Experience coordinating with SOC teams, MSSPs, or incident response vendors.
  • Strong understanding of cyber security frameworks (e.g., ISO 27001, NIST CSF, CIS Controls).
  • Proven ability to manage multiple tasks across multiple business units.
  • Experience conducting vulnerability assessments and coordinating remediation.
  • Understanding of cloud security concepts (IAM, MFA, logging, encryption, shared responsibility model).

Preferred

  • Cybersecurity certifications such as: CISSP, CISM, CEH, Security+, or equivalent.
  • Experience supporting large multi-site organizations.
  • Experience with SOC tools, SIEM dashboards, and incident response workflows.

Internal Training Requirements

  • Customer Care
  • Health and Safety
  • Quality Procedures
  • Site familiarization