Expert Engineer/Security Operation Centre
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
Subject Matter Expert – Security Operations Center (SOC) is the technical authority responsible for 24x7 security monitoring, advanced incident investigation, detection engineering, and threat hunting. The role leads and guides SOC analysts, ensures high-quality incident response, and continuously improves detection capabilities across on-premises, cloud, and telco cloud environments.
Key Skills for This Role
Full Job Posting
Responsibilities
- Serve as the primary contact for advanced security monitoring, threat detection, and investigation methodologies.
- Lead and supervise team members to ensure effective incident detection and response.
- Provide technical guidance and escalation support to SOC analysts for complex or high-severity incidents.
- Act as the final technical validation authority before escalating to Incident Response (IR) teams.
- Utilize the MITRE ATT&CK and DEFEND frameworks to map detected threats and enhance threat-hunting capabilities.
- Lead in-depth analysis of security events from multiple sources, such as SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data.
- Conduct deep-dive technical investigations for high-impact or ambiguous alerts.
- Identify gaps in detection coverage and recommend improvements.
- Continuously support the content development team by recommending detection rule tuning to reduce false positives and by proposing new advanced correlation rules, behavioral detections, and anomaly-based use cases.
- Develop and maintain SOC playbooks and runbooks to ensure consistent investigation standards.
- Ensure effective detection and monitoring across hybrid environments, including on-premises, cloud, and telco cloud.
- Support SOC shift staff in maintaining SLA compliance.
- Review and quality-check investigation reports before closure.
- Participate in major incident calls as the SOC technical lead.
- Conduct post-incident detection gap analysis.
- Mentor analysts and organize trainings to maintain team expertise.
- Develop knowledge articles, technical documentation, and use-case libraries.
- Lead internal technical workshops and purple-team collaboration exercises.
- Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities.
- Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders.
- Participate in the RFP process to provide technical recommendations and propose best-fit solutions.
- - Serve as the primary contact for advanced security monitoring, threat detection, and investigation methodologies. - Lead and supervise team members to ensure effective incident detection and response. - Provide technical guidance and escalation support to SOC analysts for complex or high-severity incidents. - Act as the final technical validation authority before escalating to Incident Response (IR) teams. - Utilize the MITRE ATT&CK and DEFEND frameworks to map detected threats and enhance threat-hunting capabilities. - Lead in-depth analysis of security events from multiple sources, such as SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data. - Conduct deep-dive technical investigations for high-impact or ambiguous alerts. - Identify gaps in detection coverage and recommend improvements. - Continuously support the content development team by recommending detection rule tuning to reduce false positives and by proposing new advanced correlation rules, behavioral detections, and anomaly-based use cases. - Develop and maintain SOC playbooks and runbooks to ensure consistent investigation standards. - Ensure effective detection and monitoring across hybrid environments, including on-premises, cloud, and telco cloud. - Support SOC shift staff in maintaining SLA compliance. - Review and quality-check investigation reports before closure. - Participate in major incident calls as the SOC technical lead. - Conduct post-incident detection gap analysis. - Mentor analysts and organize trainings to maintain team expertise. - Develop knowledge articles, technical documentation, and use-case libraries. - Lead internal technical workshops and purple-team collaboration exercises. - Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities. - Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders. - Participate in the RFP process to provide technical recommendations and propose best-fit solutions.
Qualifications
- Formal Education Required:
- Bachelor’s degree in Cybersecurity, Computer Science, or a related field (or equivalent work experience).
- Related Professional Training, Certification or Membership:
- Cybersecurity-related certification(s).
- Preferred:
- CISM
- CISSP
- Microsoft Sentinel training
- Splunk training
- Years & Field of Experience Required:
- 8–10 years
- Job-Specific Competencies:
- Mandatory: Team Lead experience
- Deep experience in monitoring and interpreting SIEM outputs, including log correlation, alert triage, and threat prioritization.
- Ability to design, validate, and tune detection rules and alerts for multiple platforms (SIEM, EDR, NDR, IDS/IPS, firewalls).
- Advanced log analysis skills across endpoints, network, identity systems, and cloud environments.
- Experience with SIEM technologies such as Splunk, Microsoft Sentinel, etc., EDR, and Threat Intelligence Platforms.
- Proficiency in building and executing complex queries (KQL, SPL, or vendor-specific languages) for detection and investigation.
- Expertise in identifying automation potential in SOC manual processes/workflows and designing their transformation into automated SOC/IR playbooks and modules within SOAR, such as FortiSOAR and Splunk SOAR.
- Strong knowledge of network protocols (TCP/IP, HTTP/S, DNS, FTP, SMTP) and the ability to identify malicious activity patterns.
- Ability to analyze threat intelligence feeds and apply IOC/TTP indicators to operational detection logic.
- Expertise in monitoring Anti-DDoS solutions and understanding mitigation at an operational level.
- Strong capability to validate alerts and investigation outputs from SOC engineers to ensure quality and accuracy.
- Experience in documenting investigations, creating runbooks, and maintaining operational knowledge repositories.
- Understanding of the global threat landscape through analysis of cyber threat intelligence.
- Ability to mentor and coach SOC engineers on technical best practices, complex investigations, and use-case development.
- Awareness of the current threat landscape, malware trends, and attack vectors, with the ability to translate this into operational detection priorities.
- Formal Education Required: - Bachelor’s degree in Cybersecurity, Computer Science, or a related field (or equivalent work experience). Related Professional Training, Certification or Membership: - Cybersecurity-related certification(s). Preferred: - CISM - CISSP - Microsoft Sentinel training - Splunk training Years & Field of Experience Required: - 8–10 years Job-Specific Competencies: - Mandatory: Team Lead experience - Deep experience in monitoring and interpreting SIEM outputs, including log correlation, alert triage, and threat prioritization. - Ability to design, validate, and tune detection rules and alerts for multiple platforms (SIEM, EDR, NDR, IDS/IPS, firewalls). - Advanced log analysis skills across endpoints, network, identity systems, and cloud environments. - Experience with SIEM technologies such as Splunk, Microsoft Sentinel, etc., EDR, and Threat Intelligence Platforms. - Proficiency in building and executing complex queries (KQL, SPL, or vendor-specific languages) for detection and investigation. - Expertise in identifying automation potential in SOC manual processes/workflows and designing their transformation into automated SOC/IR playbooks and modules within SOAR, such as FortiSOAR and Splunk SOAR. - Strong knowledge of network protocols (TCP/IP, HTTP/S, DNS, FTP, SMTP) and the ability to identify malicious activity patterns. - Ability to analyze threat intelligence feeds and apply IOC/TTP indicators to operational detection logic. - Expertise in monitoring Anti-DDoS solutions and understanding mitigation at an operational level. - Strong capability to validate alerts and investigation outputs from SOC engineers to ensure quality and accuracy. - Experience in documenting investigations, creating runbooks, and maintaining operational knowledge repositories. - Understanding of the global threat landscape through analysis of cyber threat intelligence. - Ability to mentor and coach SOC engineers on technical best practices, complex investigations, and use-case development. - Awareness of the current threat landscape, malware trends, and attack vectors, with the ability to translate this into operational detection priorities.
About Etisalat
Etisalat by e& is a UAE-based telecommunications company and one of the largest telecom operators in the Middle East and Africa, providing mobile, fixed-line, broadband, and digital services across multiple countries.
Visit company websiteApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Etisalat
Sr. Sales Manager/Government Sales-AUH (Emiratized role)
Abu Dhabi, UAE
Manage sales and drive improvement in share of wallet for 5-10 large accounts Maintains strong professional relationships with key decision makers/influencers. Creates detailed account plan to accommodate revenue growth
Nafis - Sales Executive (DXB)
Dubai, UAE
Sales Executive is accountable for receiving and reviewing customer applications and requirements, ensuring all necessary information and documentation are available, and processing applications promptly and efficiently.
Manager/Customer Registration
Dubai, UAE
Oversees customer and POS registration TDRA policies implementation and other projects assigned by management and ensure all policies, procedures, processes are in place to meet the TDRA mandate. Monitors operational eff
Sr. Sales Manager/Government Sales-AUH (Emiratized role)
Abu Dhabi, UAE
Nafis - Sales Executive (DXB)
Dubai, UAE
Manager/Customer Registration
Dubai, UAE
e& NAFIS Programme
, UAE
AI Graduate Programme
, UAE
Join our Talent Pipeline
Abu Dhabi, UAE
Bidayati – Internship Programme
, UAE
