-
General Commercial Gaming Regulatory Authority - GCGRA
View all jobs
Cyber Security Specialist
United Arab Emirates
· Full-time
·
Not Applicable
Job Description
Under the coordination of the Cyber Security Manager, the Cyber Security Specialist is responsible to validate the engineering, implementation and operational security controls that protect GCGRA business applications and enterprise IT assets. This role places a strong emphasis on cyber defence operations, vulnerability management, security assessment, incident response and threat hunting, ensuring a resilient and proactive security posture across the organization.
The Specialist leads and supports the protection of Microsoft 365 SaaS cloud business services and other corporate environments, safeguarding the confidentiality, integrity, and availability of GCGRA assets. This includes implementing and monitoring solutions like advanced threat detection, Security Information Event Management (SIEM), hardening of systems and applications, and continuously evaluating security controls against evolving threats.
As a key contributor to Security Architecture & Engineering, and Cyber Security Operations Center (CSOC) functions, the role is responsible for monitoring, analyzing, and responding to security events, as well as identifying and remediating vulnerabilities across cloud and on-premise environments. The Specialist drives proactive defence strategies by leveraging threat intelligence, conducting security assessments and incident handling, and coordinating timely mitigation of risks in mission-critical environments.
Responsibilities
Perimeter & Endpoint Security:
QUALIFICATIONS
The General Commercial Gaming Regulatory Authority (GCGRA) is the federal executive agency responsible for regulating and overseeing commercial gaming in the United Arab Emirates. We aim to drive sustainable growth by cultivating world-class commercial gaming operations and implementing efficient regulation, grounded in the principles of integrity, innovation, and responsible practices.
Established by Federal Law by Decree and headquartered in Abu Dhabi, the GCGRA is the executive authority that holds exclusive jurisdiction to regulate, license, and supervise all commercial gaming activities and facilities in the UAE.
Under the coordination of the Cyber Security Manager, the Cyber Security Specialist is responsible to validate the engineering, implementation and operational security controls that protect GCGRA business applications and enterprise IT assets. This role places a strong emphasis on cyber defence operations, vulnerability management, security assessment, incident response and threat hunting, ensuring a resilient and proactive security posture across the organization.
The Specialist leads and supports the protection of Microsoft 365 SaaS cloud business services and other corporate environments, safeguarding the confidentiality, integrity, and availability of GCGRA assets. This includes implementing and monitoring solutions like advanced threat detection, Security Information Event Management (SIEM), hardening of systems and applications, and continuously evaluating security controls against evolving threats.
As a key contributor to Security Architecture & Engineering, and Cyber Security Operations Center (CSOC) functions, the role is responsible for monitoring, analyzing, and responding to security events, as well as identifying and remediating vulnerabilities across cloud and on-premise environments. The Specialist drives proactive defence strategies by leveraging threat intelligence, conducting security assessments and incident handling, and coordinating timely mitigation of risks in mission-critical environments.
Responsibilities
Perimeter & Endpoint Security:
- Support the engineering, execute the deployment and harden GCGRA advanced security controls, including L7 firewalls, IPS, VPN, Endpoint Detection and Response (EDR/XDR) and Data Protection solutions.
- Security Monitoring & Detection: Operate and optimize SIEM/XDR/M365 security stack for continuous monitoring, alert triage, and investigation, ensuring log integrity, use case tuning, and reduced false positives. Incident Response & Threat Handling: Execute end-to-end incident response (detect, analyze, contain, eradicate, recover) supported by root cause analysis and standardized runbooks.
- Threat Hunting & Intelligence: Enhance detection through proactive threat hunting, use case refinement, and integration of global/regional threat intelligence.
- Cloud & Identity Security: Secure M365 and identity platforms by enforcing Conditional Access, monitoring anomalous activities, and aligning with Zero Trust principles.
- Security Automation & SOAR: Develop and maintain SOAR playbooks to automate response actions, improve consistency, and reduce mean time to respond (MTTR).
- Operational Coordination & Reporting: Collaborate with internal/external stakeholders, maintain operational documentation, and report on incidents, risks, and security posture.
- Security Leadership: Mentor and guide SOC analysts and engineers, fostering continuous improvement in detection and response capabilities.
- Lead the establishment and optimization of the Security Operations Center (SOC) function, including strategy design, team building, and automated response workflows.
- Vulnerability Management (RBVM): Lead end-to-end vulnerability lifecycle (scanning, prioritization, remediation) using risk-based approaches to address critical and actively exploited vulnerabilities.
- Security Assessment & Hardening: Identify misconfigurations, shadow IT, and infrastructure weaknesses; drive remediation and system hardening across cloud and on-prem environments.
- Security Posture & Compliance: Continuously assess and improve security posture in alignment with international standards (e.g., NIST, ISO 27001) and regional regulations (e.g., NESA, SIA).
- Threat & Risk Assessment: Perform targeted risk assessments on critical assets and infrastructure, defining and tracking mitigation strategies.
- Tooling & Platforms: Utilize enterprise vulnerability management and security platforms (e.g., Qualys, Tenable, Microsoft Defender) to support continuous exposure management.
- Contribute to the design and engineering of advanced cybersecurity systems to protect M365 SaaS cloud and on-premise environments.
- Project Management: Support the execution of secure engineering and system upgrades, including risk assessments, and project scheduling.
QUALIFICATIONS
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
- 5–8 years of extensive technical experience in cybersecurity, with a focus on securing complex IT infrastructures, cyber defence and security operations.
- Security Products: Proficient with M365 Security (Defender, Sentinel), endpoint protection & EDR/XDR (Defender, CrowdStrike) SIEM (Azure Sentinel, Splunk, or similar), and firewalls (Palo Alto Networks, Fortinet).
- Frameworks: Advanced knowledge of NIST, ISO 27001, CIS Controls, and UAE-specific regulatory requirements.
- Incident Response: familiar with Security Operations Centre technical controls, processes and procedures, able to manage and monitor security events and incidents in enterprise platforms.
- Threat Hunting: Proven experience in managing cybersecurity incidents and conducting threat hunting using advanced methodologies.
- Offensive Security OSCP+ (PEN-200Penetration Testing with Kali Linux), OSEP (PEN-300: Evasion Techniques and Breaching Defenses)
- CEH (Certified Ethical Hacker).
- Microsoft Security Operations Analyst Associate (SC-200).
The General Commercial Gaming Regulatory Authority (GCGRA) is the federal executive agency responsible for regulating and overseeing commercial gaming in the United Arab Emirates. We aim to drive sustainable growth by cultivating world-class commercial gaming operations and implementing efficient regulation, grounded in the principles of integrity, innovation, and responsible practices.
Established by Federal Law by Decree and headquartered in Abu Dhabi, the GCGRA is the executive authority that holds exclusive jurisdiction to regulate, license, and supervise all commercial gaming activities and facilities in the UAE.
Key Skills
Ranked by relevance
cloud
cybersecurity
incident response
cyber security
firewalls
nist
saas
siem
microsoft defender
kali linux
palo alto
splunk
linux
oscp
vpn
ips
cis
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Cyber Security Analyst
2026-04-08
Contract
Mid-Senior
Australia
Government Administration
Information Technology
View Job Details
Related
Threat Analyst 2
2026-04-11
Full-time
Not Applicable
Romania
Software Development
Information Technology
View Job Details
Related
Data / ML / AI Engineer
2026-04-10
Full-time
Not Applicable
Norway
Government Administration
Engineering
Login to Apply
- Posted
- Apr 06, 2026
- Type
- Full-time
- Level
- Not Applicable
- Location
- Abu Dhabi Emirate
Industries
Government Administration
Categories
Engineering
Information Technology
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Cyber Security Analyst
2026-04-08
Contract
Mid-Senior
Australia
Government Administration
Information Technology
View Job Details
Related
Threat Analyst 2
2026-04-11
Full-time
Not Applicable
Romania
Software Development
Information Technology
View Job Details
Related
Data / ML / AI Engineer
2026-04-10
Full-time
Not Applicable
Norway
Government Administration
Engineering