Analyst - Security Operations
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
Serve as an Incident Analyst supporting a 24×7 Security Operations Center.
Detect, triage, investigate, and respond to incidents across a private-cloud platform and enterprise services.
Work across OpenStack, Red Hat OpenShift, Splunk, Cribl, Elastic Security, and Corelight environments.
Act as a senior technical escalation point and mentor for less-experienced analysts.
Key Skills for This Role
Full Job Posting
The Opportunity
Serve as an Incident Analyst supporting a 24×7 Security Operations Center.
Detect, triage, investigate, and respond to incidents across a private-cloud platform and enterprise services.
Work across OpenStack, Red Hat OpenShift, Splunk, Cribl, Elastic Security, and Corelight environments.
Act as a senior technical escalation point and mentor for less-experienced analysts.
Security Monitoring and Incident Response
- Monitor Splunk alerts and events to identify threats, anomalies, and malicious activity.
- Triage and investigate events and determine whether alerts represent genuine incidents.
- Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware, and compromise.
- Own incidents through identification, containment, eradication, recovery, and post-incident review.
- Coordinate remediation with platform, infrastructure, network, and application teams.
- Develop and improve incident-response playbooks and standard operating procedures.
Detection Engineering and Log Pipelines
- Create and optimize Splunk searches, alerts, dashboards, reports, and correlation logic.
- Write and maintain SPL queries for investigation, hunting, reporting, and detection engineering.
- Tune noisy detections to reduce false positives and alert fatigue.
- Support log-source onboarding and validate parsing, extraction, normalization, and log quality.
- Manage Cribl pipelines for routing, filtering, enrichment, normalization, and Splunk license optimization.
Threat Hunting and Intelligence
- Conduct hypothesis-driven threat hunts for advanced persistent threats and evasive techniques.
- Map detection coverage to MITRE ATT&CK, identify gaps, and convert successful hunts into detections.
- Apply MITRE ATT&CK, Cyber Kill Chain, and Diamond Model frameworks to investigations.
- Identify indicators of compromise, patterns, and trends to prevent recurrence.
Documentation and Governance
- Conduct root cause analysis and produce incident reports for management and stakeholders.
- Maintain records of incidents, actions, evidence, and lessons learned in the case-management platform.
- Improve security monitoring use cases and detection rules.
- Provide incident-management evidence for audit and compliance requirements.
Working Arrangement
- This is a full-time role reporting to the SOC Manager.
- The role operates within a 24×7 Security Operations Center.
- Participate in rotating day, evening, and night shifts, including weekends and public holidays.
- Follow acknowledgement, triage, escalation, and shift-handover procedures governed by defined SLAs.
Required Skills and Qualifications
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field; equivalent experience and certifications may substitute.
- 4–8 years of experience in security operations, incident response, or SOC monitoring.
- Advanced hands-on Splunk experience, including SPL, dashboards, alerts, correlation, and administration.
- Experience with Cribl Stream or Cribl Edge data routing, filtering, pipelines, and enrichment.
- Strong incident analysis, investigation, evidence handling, escalation, and full-lifecycle response experience.
- Knowledge of Elastic Security, Corelight, MITRE ATT&CK, Cyber Kill Chain, Diamond Model, networking, Windows, Linux, scripting, and case-management tools.
Preferred Qualifications
- Splunk Core Certified Power User or Splunk Certified Admin certification.
- Cribl Certified Admin certification.
- Relevant GIAC certification such as GCIA, GCIH, GCDA, or GCFA.
- Blue Team Level 2 or equivalent hands-on defensive certification.
- Experience monitoring OpenStack and Kubernetes or OpenShift environments.
- Familiarity with detection-as-code practices using version control and peer review.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Core42
Senior Director - Financial Reporting & Taxation
, UAE
Core42 is seeking a Senior Director to own group financial reporting, consolidation, statutory reporting and the full UAE tax compliance agenda. The role leads external audit, technical accounting, finance operations, pr
Vendor Manager
, UAE
Core42 is seeking a Vendor Manager to own strategic supplier relationships, governance, onboarding, performance management, and supplier development. The role leads the Vendor Management team and requires substantial ven
Tax Specialist
Abu Dhabi, UAE
Core42 is seeking a Tax Specialist to support UAE and international tax matters, including corporate tax, VAT, transfer pricing, compliance, and reporting. The role requires a qualified CA, ACCA, or CPA, 6–8 years of pos
Tax Specialist
Abu Dhabi, UAE
Core42 is seeking a Tax Specialist to manage UAE corporate tax, VAT, tax accounting, transfer pricing, compliance, and tax advisory activities. The role requires 5+ years of tax experience, a professional tax or accounti
Treasury Specialist
Abu Dhabi, UAE
Core42 is seeking a Treasury Specialist to manage daily liquidity, banking operations, cash forecasting, payment controls, and treasury reporting across multiple entities. Candidates need 5+ years of corporate treasury,
Accounts Payable Manager
, UAE
The employer is seeking an Accounts Payable Manager to own the end-to-end payables cycle, lead a payables team, strengthen controls, and improve automation. The role covers supplier invoices, payment runs, reconciliation
Legal Director
, UAE
Core42 is seeking a Legal Director to lead government and public-sector legal engagement in Abu Dhabi while advising on regulatory, governance, risk and commercial matters. The role represents the company with senior sta
Senior Engineer - Infrastructure and Cloud Engineering
Abu Dhabi, UAE
Core42 is seeking a Senior Engineer to design, operate, automate, and improve private cloud, virtualization, observability, and infrastructure platforms. The hands-on role includes production support, AI-assisted operati
Senior Director - Financial Reporting & Taxation
, UAE
Vendor Manager
, UAE
Tax Specialist
Abu Dhabi, UAE
Tax Specialist
Abu Dhabi, UAE
Treasury Specialist
Abu Dhabi, UAE
Accounts Payable Manager
, UAE
Legal Director
, UAE
Senior Engineer - Infrastructure and Cloud Engineering
Abu Dhabi, UAE