{bc}
linkedin

Analyst - Security Operations

Core42
Abu Dhabi, UAE
Full-time
Mid-Senior
Onsite
Discovered 3 weeks ago
Security operationsIncident responseSplunk Enterprise / Splunk CloudSPLCribl Stream / Cribl EdgeElastic Security
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Security operationsIncident responseSplunk Enterprise / Splunk Cloud
Smart Apply

Full Job Posting

The Opportunity

Serve as an Incident Analyst supporting a 24×7 Security Operations Center.

Detect, triage, investigate, and respond to incidents across a private-cloud platform and enterprise services.

Work across OpenStack, Red Hat OpenShift, Splunk, Cribl, Elastic Security, and Corelight environments.

Act as a senior technical escalation point and mentor for less-experienced analysts.

Security Monitoring and Incident Response

  • Monitor Splunk alerts and events to identify threats, anomalies, and malicious activity.
  • Triage and investigate events and determine whether alerts represent genuine incidents.
  • Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware, and compromise.
  • Own incidents through identification, containment, eradication, recovery, and post-incident review.
  • Coordinate remediation with platform, infrastructure, network, and application teams.
  • Develop and improve incident-response playbooks and standard operating procedures.

Detection Engineering and Log Pipelines

  • Create and optimize Splunk searches, alerts, dashboards, reports, and correlation logic.
  • Write and maintain SPL queries for investigation, hunting, reporting, and detection engineering.
  • Tune noisy detections to reduce false positives and alert fatigue.
  • Support log-source onboarding and validate parsing, extraction, normalization, and log quality.
  • Manage Cribl pipelines for routing, filtering, enrichment, normalization, and Splunk license optimization.

Threat Hunting and Intelligence

  • Conduct hypothesis-driven threat hunts for advanced persistent threats and evasive techniques.
  • Map detection coverage to MITRE ATT&CK, identify gaps, and convert successful hunts into detections.
  • Apply MITRE ATT&CK, Cyber Kill Chain, and Diamond Model frameworks to investigations.
  • Identify indicators of compromise, patterns, and trends to prevent recurrence.

Documentation and Governance

  • Conduct root cause analysis and produce incident reports for management and stakeholders.
  • Maintain records of incidents, actions, evidence, and lessons learned in the case-management platform.
  • Improve security monitoring use cases and detection rules.
  • Provide incident-management evidence for audit and compliance requirements.

Working Arrangement

  • This is a full-time role reporting to the SOC Manager.
  • The role operates within a 24×7 Security Operations Center.
  • Participate in rotating day, evening, and night shifts, including weekends and public holidays.
  • Follow acknowledgement, triage, escalation, and shift-handover procedures governed by defined SLAs.

Required Skills and Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field; equivalent experience and certifications may substitute.
  • 4–8 years of experience in security operations, incident response, or SOC monitoring.
  • Advanced hands-on Splunk experience, including SPL, dashboards, alerts, correlation, and administration.
  • Experience with Cribl Stream or Cribl Edge data routing, filtering, pipelines, and enrichment.
  • Strong incident analysis, investigation, evidence handling, escalation, and full-lifecycle response experience.
  • Knowledge of Elastic Security, Corelight, MITRE ATT&CK, Cyber Kill Chain, Diamond Model, networking, Windows, Linux, scripting, and case-management tools.

Preferred Qualifications

  • Splunk Core Certified Power User or Splunk Certified Admin certification.
  • Cribl Certified Admin certification.
  • Relevant GIAC certification such as GCIA, GCIH, GCDA, or GCFA.
  • Blue Team Level 2 or equivalent hands-on defensive certification.
  • Experience monitoring OpenStack and Kubernetes or OpenShift environments.
  • Familiarity with detection-as-code practices using version control and peer review.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Core42