Job Description

K Ey Responsibilities

Solution Architecture & Technical Presales

  • Lead technical discovery and qualification; translate business, risk and compliance requirements into target security architectures across identity, endpoint, email, data, cloud, network and SOC domains.
  • Identity & Zero Trust: design Conditional Access policy frameworks, privileged access management, identity governance (access reviews, entitlement management, lifecycle workflows), hybrid identity, MFA / passwordless, and Zero Trust network access (Entra Global Secure Access, Cisco Duo / Secure Access, Fortinet ZTNA, Check Point Harmony SASE).
  • Endpoint & XDR: architect EDR / XDR deployments across Windows, macOS, Linux and mobile — onboarding strategy, attack-surface-reduction and hardening baselines, automated investigation and response, identity threat detection (Defender for Identity), vulnerability management — using Defender XDR, FortiEDR / FortiXDR, Check Point Harmony Endpoint or Cisco Secure Endpoint.
  • Email & Collaboration Security: design layered email protection (Defender for Office 365 / Exchange Online Protection with Mimecast, Check Point Harmony Email or Cisco Secure Email), including connector, MX and outbound-routing design, DMARC / DKIM / SPF, attack simulation and awareness training.
  • SIEM, SOAR & SOC Modernisation: design Sentinel and FortiSIEM / FortiSOAR solutions — data-connector strategy, log ingestion tiering and Data Collection Rules, analytics and hunting content, SOAR playbooks, single vs multi-workspace and multi-tenant (Lighthouse) designs, Security Copilot — plus migration runbooks from Splunk, QRadar, ArcSight and LogRhythm and MDR / managed SOC service definitions.
  • Data Security & DLP: design data-classification and DLP programmes with Purview (sensitivity labels, auto-labelling, Endpoint / Cloud / Exchange DLP, Insider Risk, Data Lifecycle, eDiscovery) and Forcepoint DLP / Risk-Adaptive Protection / Forcepoint ONE, including co-existence designs where Purview labels act as Forcepoint classifiers.
  • Cloud Security Posture: architect CSPM / CNAPP and CASB / SSPM solutions — Defender for Cloud (multi-cloud AWS / GCP onboarding, workload protection, regulatory compliance dashboards), Defender for Cloud Apps, Check Point CloudGuard, Fortinet FortiCNAPP, Cisco Multicloud Defense.
  • Network Security & SASE: design NGFW, segmentation, SD-WAN and SSE architectures with Fortinet Security Fabric (FortiGate, FortiManager, FortiAnalyzer), Check Point Quantum / Maestro, Cisco Secure Firewall, Umbrella and Secure Access, and Azure Firewall Premium / WAF / DDoS Protection.
  • Integration architecture: produce reference designs showing telemetry and control-plane integration between network, endpoint and email controls and the SIEM / XDR layer (API connectors, CEF / Syslog via AMA, automated response through FortiGate, Check Point and Cisco APIs).
  • Deliver compelling demonstrations, proofs of concept, pilots and hands-on workshops; own the technical close on every opportunity you are assigned to.
  • Respond to RFPs, RFIs and tenders with high-quality technical write-ups, compliance matrices and architecture diagrams, and lead technical clarification sessions with evaluation committees.
  • Produce Statements of Work, high-level designs and effort estimates, and run a structured handover to the delivery / SOC teams on every won deal.

Commercial Modelling – Bills of Materials & Licensing

  • Build licensing models across Microsoft 365 E3 → E5 step-ups, E5 Security and E5 Compliance add-ons, F-series, and standalone SKUs (Entra ID P1 / P2 / Suite, Defender for Endpoint P1 / P2, Defender for Office 365 P1 / P2, Intune Plans, Purview add-ons), mapping each customer requirement to the minimum SKU that unlocks the capability.
  • Model cloud consumption for security workloads: SIEM ingestion (pay-as-you-go vs commitment tiers, Basic / Auxiliary log tiers, retention and archive), per-resource CSPM / CWPP pricing, firewall / WAF / DDoS, automation and log-analytics costs, and Security Copilot SCU sizing — presented as monthly and annual run-rate with 3-year projections.
  • Build BoMs and subscription models: Fortinet (hardware bundles, FortiCare / FortiGuard tiers, FortiFlex points), Check Point (appliances, software blades / Infinity subscriptions, Harmony per-user), Cisco (Enterprise Agreements, Duo / Umbrella / Secure Access tiers, Secure Firewall Threat Defense licences), Forcepoint and Mimecast per-user plans — with renewal co-termination and multi-year options.
  • Produce TCO and consolidation business cases quantifying licence rationalisation (e.g. retiring standalone MFA, EDR, CASB or email security), SIEM ingestion vs incumbent SIEM licensing, hardware-refresh avoidance and operational savings from unified XDR — and justify best-of-breed retention where platform-native controls do not meet the requirement (data sovereignty, OT / network segmentation, regulatory constraints, feature gaps).

Security Practice Development

  • Act as the primary SME for identity / Zero Trust, XDR, SIEM / SOC and data-security solutions: maintain reference architectures, demo and lab environments, assessment playbooks (Zero Trust maturity, Secure Score, data-risk and SOC maturity assessments) and standard proposal content.
  • Support the practice roadmap: capability mapping across security domains, identifying skill gaps, and mentoring presales and delivery engineers.
  • Build relationships with vendor partner-facing teams (partner development managers, technical specialists, channel SEs) and contribute to joint account plans and co-sell motions.
  • Stay current on vendor roadmaps, competitive positioning and partner-programme requirements; maintain the certifications needed to keep partner tiers and deal-registration eligibility.

Sales Enablement & Go-to-Market

  • Partner with account managers on opportunity qualification, deal strategy and forecasting; contribute to pipeline generation through customer events, webinars, briefings and assessment-led campaigns.
  • Enable the account-management team on security propositions, talk tracks and qualification questions across all solution domains.
  • Contribute to solution playbooks and bundled offerings for priority domains: Zero Trust, Data Protection, Cloud / SaaS Security Posture, GRC and SOC Modernisation / MDR.
  • Maintain accurate opportunity, BoM and technical-status records in CRM and vendor deal-registration portals.

Experience

Required Skills & Experience

  • 10 years + in cybersecurity, including at least 6+ years in a customer-facing presales, solution-architecture or consulting role with a system integrator, MSSP, reseller or vendor.
  • Demonstrable track record of designing and winning enterprise or public-sector opportunities in at least three of: identity & Zero Trust, XDR, SIEM / SOAR, DLP / data security, CSPM / CNAPP, email security, NGFW / SASE.
  • Hands-on or design-level experience with Entra / Defender XDR / Sentinel / Purview and with at least two of: Fortinet, Check Point, Cisco Security, Forcepoint, Mimecast.
  • Experience with SIEM migration and SOC modernisation projects and with positioning MDR or managed security services.
  • UAE market experience including familiarity with UAE IA / NESA, DESC and sector regulators.

Technical Competency Matrix

Solution Domain

Technologies & Platforms

Expected Depth

Identity, Access & Zero Trust

Entra ID (Conditional Access, PIM, ID Governance, Global Secure Access), Cisco Duo, Cisco ISE / NAC, Fortinet ZTNA (FortiClient / FortiSASE), Check Point Harmony SASE; PAM / IGA (CyberArk, BeyondTrust, SailPoint) at positioning level

Expert – design and lead

Endpoint Security & XDR

Defender for Endpoint / Defender XDR, Defender for Identity, Defender Vulnerability Management, Intune security baselines; FortiEDR / FortiXDR, Check Point Harmony Endpoint, Cisco Secure Endpoint; CrowdStrike / SentinelOne (partner-led)

Expert – design and lead

Email & Collaboration Security

Defender for Office 365, Exchange Online Protection; Mimecast (SEG, Targeted Threat Protection, Awareness Training, Archiving, DMARC); Check Point Harmony Email & Collaboration; Cisco Secure Email

Expert – design and lead

SIEM, SOAR & SOC Modernisation

Sentinel (connectors, AMA / DCR, log tiering, analytics, hunting, Logic Apps playbooks, Lighthouse), Security Copilot; FortiSIEM / FortiSOAR; migration from Splunk, QRadar, ArcSight, LogRhythm; MDR / managed SOC service design

Expert – design and lead

Data Security & DLP

Purview (sensitivity labels, auto-labelling, Endpoint / Cloud / Exchange DLP, Insider Risk, Data Lifecycle, eDiscovery), Forcepoint DLP / Risk-Adaptive Protection, Forcepoint ONE, data classification and DSPM tooling

Expert – design and lead

Cloud Security Posture (CSPM / CNAPP / CASB)

Defender for Cloud (Defender CSPM, Servers, Containers, Storage, SQL; AWS / GCP onboarding), Defender for Cloud Apps (CASB, SaaS security posture, app governance); Check Point CloudGuard, Fortinet FortiCNAPP, Cisco Multicloud Defense; third-party SSPM

Strong – design

Network Security & SASE

Fortinet Security Fabric (FortiGate NGFW / SD-WAN, FortiManager, FortiAnalyzer), Check Point Quantum (Maestro, Smart-1), Cisco Secure Firewall / FMC, Umbrella, Secure Access SSE; Azure Firewall Premium, WAF (App Gateway / Front Door), DDoS Protection

Strong – design

GRC & Security Advisory

Zero Trust and security-maturity assessments, Secure Score / Compliance Manager, NIST CSF, ISO 27001, UAE IA / NESA, DESC, Qatar NCSA, PCI DSS; risk assessments and roadmap workshops

Working – advise

Certifications

Required

Required (or achieved within 6 months of joining):

  • Microsoft SC-100 (Cybersecurity Architect Expert) and at least two of SC-200, SC-300, SC-400, AZ-500.
  • One vendor presales / design certification from the third-party portfolio (Fortinet NSE 4–7 / FCP-FCSS, Check Point CCSA / CCSE, Cisco CCNP Security, Forcepoint or Mimecast certified engineer).

Preferred

  • Prior presales experience with Microsoft Security in a partner or Microsoft-aligned role, including co-sell and funded-programme engagement, is strongly preferred.
  • CISSP, CCSP, CISM or equivalent.
  • Additional Microsoft certifications (MS-102, MD-102, AZ-305) or vendor architect-level credentials (Fortinet NSE 7 / FCSS, Check Point CCSM, Cisco CCIE Security).
  • ISO 27001 Lead Implementer / Auditor or NIST CSF familiarity.

Professional & Soft Skills

  • Executive presence: able to run a CISO-level conversation on strategy and risk, then whiteboard the architecture with the security engineering team in the same meeting.
  • Strong commercial acumen: licensing optimisation, consolidation business cases and TCO modelling across platform and point-solution offerings.
  • Excellent written English for proposals, tenders and design documents; Arabic is an advantage.
  • Self-directed, organised and comfortable managing multiple concurrent opportunities across two regions in a shared-specialist model.
  • Collaborative mindset — works effectively with account managers, regional presales anchors, cloud / workplace sales teams, vendor partners and delivery / SOC.

Location: Dubai - SSTC, Dubai, Dubai, United Arab Emirates


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: United Arab Emirates City: Dubai
Company Website: https://noventiq.ae/ Job Function: Cybersecurity
Company Industry/
Sector:
IT Services and IT Consulting

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn