B

IT Security Operations Engineer

BigData Technology Solutions

Dubai, United Arab Emirates · Full Time

Be the first to apply

Experience
5–8 yrs
Salary
Openings
1
Posted
3 weeks ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Job Overview

The IT Security Operations Engineer plays a crucial role within the Security Operations Center (SOC), tasked with identifying, investigating, and mitigating cybersecurity threats to safeguard the organization's information assets' confidentiality, integrity, and availability. This position leverages a variety of security tools, threat intelligence, and incident response strategies to enhance detection and response capabilities continuously.

Key Responsibilities

  • Continuously monitor security alerts from platforms such as SIEM, EDR/XDR, IDS/IPS, and DLP, analyzing them to identify potential risks.
  • Conduct thorough triage and investigation of security events to assess threat levels and impacts, adhering to incident response protocols and service level agreements.
  • Manage incident escalations, support containment, eradication, recovery steps, and perform root cause analyses in collaboration with diverse technical teams.
  • Engage in proactive threat hunting by utilizing threat intelligence sources, analyzing logs, and detecting suspicious activities including phishing, malware, ransomware, and intrusion attempts.
  • Develop, maintain, and fine-tune detection rules, correlation logic, and security playbooks to enhance detection accuracy and reduce false alarms.
  • Support vulnerability management efforts by facilitating scanning, assessment, remediation coordination, and tracking to maintain security posture.
  • Maintain and optimize security platforms including SIEM, SOAR, endpoint security solutions, firewalls, and other monitoring tools, incorporating automation and scripting to streamline operations.
  • Perform in-depth analysis of security incidents using diverse forensic and telemetry tools, identifying attack vectors and indicators of compromise, and documenting findings for remediation.
  • Prepare comprehensive reports on threat trends, vulnerabilities, incident responses, and SOC metrics while ensuring all security documentation and audit requirements are met.
  • Provide mentorship and knowledge sharing for junior SOC team members and contribute towards improving SOC processes and toolsets.

Required Skills and Competencies

  • Proficiency with SIEM solutions such as Splunk, IBM QRadar, or Microsoft Sentinel.
  • Experience with endpoint detection and response platforms and network security systems including IDS/IPS and DLP.
  • Strong incident response expertise covering event triage, containment, eradication, recovery, and root cause analysis.
  • Capabilities in threat hunting, detection engineering, and development of correlation rules and use cases.
  • Familiarity with threat intelligence indicators, feeds, and analysis of emerging attack vectors.
  • Experience with security automation tools such as SOAR and scripting languages like Python, PowerShell, or Bash.
  • Knowledge of vulnerability assessment processes and patch management coordination.
  • Operating system proficiency in both Windows and Linux environments.
  • Competence in cloud security across AWS, Azure, and GCP platforms.
  • Strong skills in security analysis including log examination, packet capture interpretation, and forensic investigations.

Experience and Eligibility

  • Minimum of 5 to 8 years in SOC operations, cybersecurity incident response, or related IT security fields.
  • Hands-on experience working within SLA-driven SOC environments and ability to operate in 24/7 or rotating shifts as required.

How they work

Stress Management required
🤖
Online · instant AI help
Broxer