AVAR is looking for a highly skilled IT Engineer to take full ownership of its IT infrastructure design, implementation, and management. As part of our team in Head Office - Dubai, you'll work in an ONSITE environment applying a security-first mindset to architect and maintain our robust, enterprise-grade systems. This is a hands-on position with end-to-end responsibility, blending deep technical expertise in networking, system engineering, and information security. You will lay the foundation for and support a secure, resilient network that meets the needs of users across wired, wireless, and remote environments while driving best practices and compliance in all infrastructure operations.
Responsibilities
Design and implement secure, segmented enterprise network infrastructure with multi-VLAN architecture.
Configure Layer 2/3 switching, routing, and build core IT systems from the ground up.
Deploy advanced network protection controls such as DHCP snooping, Dynamic ARP Inspection, and port security.
Configure and manage next-generation firewalls, adopting a default-deny model and implementing threat protection mechanisms like IPS, antivirus, and application control.
Enforce network access control and port-based authentication (802.1X) and dynamic VLAN assignment.
Deploy and manage enterprise wireless solutions supporting corporate and secure guest networks.
Ensure all infrastructure aligns with internal security policies and proactively address gaps while supporting audits.
Provide direct hands-on support across systems, infrastructure, and end-user environments, leading incident response for IT outages and disruptions.
Must have requirements
Minimum 5 years of professional experience in IT infrastructure (network & systems engineering).
At least 3 years in a lead or ownership position supporting environments with 100+ users.
Demonstrable hands-on expertise in enterprise networking (L2/L3), VLANs, high availability routing, AV and firewall deployments (NGFW, IPS, SSL inspection).
Strong experience with network security, policy management, and enforcement of 802.1X authentication.
Deep exposure to deployment and management of secure wireless infrastructures (WPA3-Enterprise, RADIUS), and guest isolation.
Proven ability to implement VPN technologies (IPsec/SSL, MFA integration).
Comprehensive knowledge of Active Directory architecture, Group Policy, RBAC, and identity security best practices.
Proficiency in endpoint security, device hardening, disk encryption, and patch management via centralized tools.
Backup and recovery management (NAS, enterprise backup tools), hybrid cloud networking (Azure, AWS or similar).
Exceptional attention to detail, strong ownership mindset, and thorough documentation skills.
Excellent communication skills aimed at both technical and non-technical stakeholders.
Commitment to continuous learning and staying updated with evolving technologies and threats.
Nice to have requirements
Exposure to penetration testing methods and vulnerability management.
Experience with SIEM and security monitoring tools.
Familiarity with detection rules, log analysis, and automated incident response processes.
Background in mentoring, knowledge sharing, and building team capability.