B
IT Security Operations Engineer
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 5–8 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
The IT Security Operations Engineer plays a crucial role within the Security Operations Center (SOC), tasked with identifying, investigating, and mitigating cybersecurity threats to safeguard the organization's information assets' confidentiality, integrity, and availability. This position leverages a variety of security tools, threat intelligence, and incident response strategies to enhance detection and response capabilities continuously.
Key Responsibilities
- Continuously monitor security alerts from platforms such as SIEM, EDR/XDR, IDS/IPS, and DLP, analyzing them to identify potential risks.
- Conduct thorough triage and investigation of security events to assess threat levels and impacts, adhering to incident response protocols and service level agreements.
- Manage incident escalations, support containment, eradication, recovery steps, and perform root cause analyses in collaboration with diverse technical teams.
- Engage in proactive threat hunting by utilizing threat intelligence sources, analyzing logs, and detecting suspicious activities including phishing, malware, ransomware, and intrusion attempts.
- Develop, maintain, and fine-tune detection rules, correlation logic, and security playbooks to enhance detection accuracy and reduce false alarms.
- Support vulnerability management efforts by facilitating scanning, assessment, remediation coordination, and tracking to maintain security posture.
- Maintain and optimize security platforms including SIEM, SOAR, endpoint security solutions, firewalls, and other monitoring tools, incorporating automation and scripting to streamline operations.
- Perform in-depth analysis of security incidents using diverse forensic and telemetry tools, identifying attack vectors and indicators of compromise, and documenting findings for remediation.
- Prepare comprehensive reports on threat trends, vulnerabilities, incident responses, and SOC metrics while ensuring all security documentation and audit requirements are met.
- Provide mentorship and knowledge sharing for junior SOC team members and contribute towards improving SOC processes and toolsets.
Required Skills and Competencies
- Proficiency with SIEM solutions such as Splunk, IBM QRadar, or Microsoft Sentinel.
- Experience with endpoint detection and response platforms and network security systems including IDS/IPS and DLP.
- Strong incident response expertise covering event triage, containment, eradication, recovery, and root cause analysis.
- Capabilities in threat hunting, detection engineering, and development of correlation rules and use cases.
- Familiarity with threat intelligence indicators, feeds, and analysis of emerging attack vectors.
- Experience with security automation tools such as SOAR and scripting languages like Python, PowerShell, or Bash.
- Knowledge of vulnerability assessment processes and patch management coordination.
- Operating system proficiency in both Windows and Linux environments.
- Competence in cloud security across AWS, Azure, and GCP platforms.
- Strong skills in security analysis including log examination, packet capture interpretation, and forensic investigations.
Experience and Eligibility
- Minimum of 5 to 8 years in SOC operations, cybersecurity incident response, or related IT security fields.
- Hands-on experience working within SLA-driven SOC environments and ability to operate in 24/7 or rotating shifts as required.
Skills
How they work
Stress Management
required