ROLE OBJECTIVE The Senior Specialist – Service Operations is a hands-on technical authority responsible for the day-to-day delivery, engineering, and continuous improvement of OTECH's core managed cybersecurity services with deep ownership of Vulnerability Management, Email Security, Web Application Security, and Endpoint Security service lines. The role serves as a senior point of escalation for the Service Operations team, drives complex client engagements end-to-end, and partners with the Team Lead on service strategy, technical governance, and team capability uplift. The Senior Specialist is expected to operate independently across the full-service lifecycle from onboarding and design through steady-state operations, incident response, and continuous service improvement while ensuring all delivery aligns with ITIL, ISO 20000, ISO 27001, and OTECH's contractual SLAs. RESPONSIBILITIES Vulnerability Management Service Delivery • Own end-of-the-end delivery of the Vulnerability Management service across the client portfolio. • Triage and prioritize vulnerabilities using risk-based scoring, threat context, and asset criticality. • Maintain the monthly vulnerability tracker and executive dashboards with clear remediation ownership. • Lead client review meetings and advise on remediation strategy at technical and management levels. Email Security Service Delivery • Lead design, hardening, and operational support of managed email security platforms across client environments. • Drive migration and onboarding projects include cutover planning and post-migration validation. • Diagnose and remediate email authentication issues (SPF, DKIM, DMARC) and advise clients on email security strategy. • Act as senior escalation points for complex email security incidents. Web Application Security Service Delivery • Own configuration, tuning, and remediation work for managed WAF services across client applications. • Author and refine WAF policies aligned with OWASP Top 10 and client business logic. • Produce change and remediation documentation to support client change advisory boards. • Provide expert support for application onboarding from discovery through steady-state handover. Endpoint Security Service Delivery • Lead operational delivery of managed endpoint security services including deployment, agent health, and coverage assurance. • Conduct coverage gap analyses across client estates and produces client-facing remediation plans. • Tune detection rules and response playbooks in coordination with the SOC. • Support endpoint-related incident response including triage, containment, and root-cause analysis. Stakeholder Coordination and Customer Communication • Serve as the senior technical interface for assigned clients across the four service lines. • Produce executive-level reports, technical briefings, and client review packs in English and Arabic where required. • Lead client onboarding and operational handover activities. • Proactively escalate risks, service degradation, and contractual deviations to the Team Lead. • Represent OTECH in client CAB, security review, and operational governance meetings. Leadership, Mentoring, and Team Capability • Act as a technical mentor and escalation point for Specialist and Junior Specialist team members. • Lead peer knowledge-transfer sessions, technical workshops, and capability uplift initiatives. • Support the Team Lead in capacity planning, workload balancing, and individual development planning. • Deputize for the Team Lead in operational meetings and technical reviews when required. Learning and Development • Maintain deep, current awareness of OTECH service portfolios, client contracts, and threat landscape developments. • Pursue advanced certifications across the four service pillars. • Actively contribute to internal communities of practice and represent OTECH at industry events where appropriate. ROLE SPECIFICATIONS Qualification Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or equivalent. Master's degree preferred. Certification ITIL v4 Foundation mandatory. At least one professional security certification required (e.g. CISSP, Security+, CySA+, CISM, CEH, OSCP, or GIAC). Relevant vendor and technology certifications across vulnerability management, email security, web application security, and endpoint security platforms are strongly preferred. Experience 5–7 years of hands-on experience in cybersecurity operations or managed security service delivery, with demonstrated technical depth across vulnerability management, email security, web application security, and endpoint security. Prior MSSP or large enterprise SOC environment exposure is strongly preferred. Skills Advanced operational and engineering knowledge across the four service pillars: vulnerability management (scanning, risk-based prioritization, remediation tracking, and executive reporting); email security (platform administration, hardening, migration, and email authentication including SPF, DKIM, and DMARC); web application security (WAF policy design, tuning, and OWASP Top 10 mitigation); and endpoint security (EDR/XDR deployment, tuning, coverage assurance, and incident support). Strong working knowledge of ITSM platforms, ITIL processes, scripting for automation and reporting, and client-facing communication including executive-level reporting. Arabic/English bilingual capability is an advantage. Competency Type Competency Proficiency level Behavioural Communication Expert Behavioural Collaboration Advanced Behavioural Planning & Coordination Advanced Core Integrity Advanced Core Operational excellence Advanced Technical Vulnerability Management Expert Technical Email Security Expert Technical Web Application Security Expert Technical Endpoint Security Expert Technical Incident & Problem Management Advanced Technical Security Reporting Advanced
اشترك مجاناً واختر تخصصاتك، وسنرسل لك الوظائف المناسبة مباشرة على واتساب
اشترك عبر واتساب مجاناً