Al-Futtaim and Federal Youth Authority Partner on Emirati Businesses
Sep 13, 2026
Applications close Oct 23, 2026
Al-Futtaim is hiring an Information Security Analyst for its cyber defense function in Dubai, working at the group level rather than within a single business unit. Al-Futtaim is a large, diversified conglomerate spanning automotive, retail, real estate, and financial services across the region, which means the security team here is protecting a genuinely wide and varied technology footprint, not a single tidy environment – retail POS systems, dealership and financial platforms, corporate IT, and e-commerce all fall within scope in one way or another.
The core of the job is detection and response work: developing and tuning detection use cases and correlation rules so the security monitoring tooling actually catches meaningful threats rather than generating noise, reviewing alerts, and investigating potential incidents to determine whether they’re real and how serious they are. Alongside that sits ongoing work on security controls – helping assess, implement, and validate the technical and procedural controls that reduce risk across group systems – and a significant documentation responsibility, since every incident, investigation, and control change needs clear, accurate reporting for both internal stakeholders and, where relevant, compliance purposes.
This role sits within the group’s cyber defense or security operations structure, working alongside other security analysts and engineers, and coordinating with IT teams across different business units when an incident or control change touches their systems. It’s a hands-on, technically grounded role rather than a purely policy-focused one.
It suits someone with solid information security experience who enjoys the investigative, detail-oriented side of security work – someone who’s comfortable digging into logs and alerts, thinking like an attacker when building detection logic, and writing things up clearly enough that a non-technical stakeholder can understand what happened and why it mattered.
A group of Al-Futtaim's size and diversity - spanning automotive, retail, real estate, and financial services - represents a large and genuinely attractive attack surface, and a cyber defense analyst is part of the front line protecting that surface from disruption or data loss. Well-tuned detection use cases mean real threats get caught and investigated quickly rather than getting lost in alert noise, which directly reduces how long an attacker can sit undetected inside any part of the environment. Strong incident investigation and clear documentation matter beyond the immediate technical fix too - they shape how quickly the business can understand the scope of an incident, communicate accurately with leadership, and meet any regulatory or compliance obligations tied to data protection or financial services oversight. Because the group spans several regulated or customer-sensitive sectors, a security failure in one business unit can have reputational and operational consequences well beyond that unit alone, so consistent detection and control work at the group level protects the wider business, not just individual systems. Reliable security controls also underpin customer trust in areas like retail payment systems and financial services platforms, where a breach would have direct commercial consequences. In short, this role is part of what keeps day-to-day operations across a very large, varied organization running without disruption from cyber incidents.
Working cyber defense at group level inside a conglomerate this diverse is a genuinely broad technical education, because the environment isn't one homogenous stack - it spans retail technology, automotive and dealership systems, real estate operations, and financial services platforms, each with different risk profiles and compliance considerations. Building and tuning detection use cases sharpens a skill set that's consistently in demand across the security industry, since organizations everywhere struggle to get detection logic right, and hands-on experience doing it well is far more valuable on a CV than certifications alone. Incident investigation experience builds the kind of structured, evidence-based analytical thinking that transfers directly to more senior security roles - incident response lead, threat intelligence, or security operations management - and also to adjacent fields like risk or compliance if someone's interests shift that way over time. The reporting and documentation side of the job, often underrated, builds the communication skills that separate senior analysts from junior ones: being able to explain a technical incident clearly to non-technical leadership is a genuinely rare and valuable skill. Being part of a large group's dedicated cyber defense function also means exposure to enterprise-grade tooling, processes, and governance structures that are harder to encounter at a smaller company, which is valuable experience for anyone aiming toward a CISSP, senior SOC analyst, or security engineering track. For someone building a long-term security career, this kind of role - varied environment, real incident exposure, structured team - is exactly the sort of experience that opens doors to more senior cyber defense or security architecture positions down the line.
Consider including these terms in your resume for this role:
Walk me through how you would develop or tune a detection use case for a specific threat scenario.
Looks for practical understanding of detection engineering, not just theory.
Describe an incident you investigated. How did you determine its severity and scope?
Assesses real investigative experience and structured incident handling.
How do you approach reducing false positives without missing genuine threats?
Tests judgment around alert tuning and detection quality trade-offs.
What security frameworks or standards have you worked with, and how did you apply them?
Confirms practical familiarity with frameworks like MITRE ATT&CK, ISO 27001, or NIST rather than just name recognition.
How do you document and communicate an incident to a non-technical stakeholder?
Evaluates written communication skill and ability to translate technical detail.
Give an example of a security control you helped implement or improve.
Looks for hands-on control implementation experience, not just monitoring.
How would you approach securing an environment that spans very different business types, like retail, automotive, and financial services?
Gauges adaptability and understanding of varied risk profiles across a diversified organization.
Sep 13, 2026
Aug 23, 2026
Aug 23, 2026