{bc}
linkedin

Expert Engineer/Security Operation Centre

e& UAE
Dubai, UAE
Full-time
Mid-Senior
Onsite
Discovered 1 weeks ago
Security operations center (SOC) operationsSIEMThreat huntingIncident investigationDetection rule design and tuningMITRE ATT&CK
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Security operations center (SOC) operationsSIEMThreat hunting
Smart Apply

Full Job Posting

Role Overview

The Subject Matter Expert oversees advanced security monitoring and incident management within the Cyber Security function.

The role is the primary escalation point for complex or high-severity incidents and provides technical validation before Incident Response handover.

Core Responsibilities

  • Lead security monitoring, threat detection, incident investigation, and escalation support for complex incidents.
  • Analyze SIEM, IDS/IPS, firewall, endpoint, and network telemetry using deep-dive investigation methods.
  • Apply MITRE ATT&CK and DEFEND frameworks to improve threat hunting and detection coverage.
  • Design, tune, validate, and improve detection rules, correlation rules, behavioral detections, and anomaly use cases.
  • Develop and maintain SOC playbooks, runbooks, knowledge articles, and use-case libraries.
  • Support monitoring across on-premises, cloud, and telco cloud environments.
  • Lead major incident technical calls, quality-check reports, and perform post-incident detection gap analysis.
  • Mentor SOC engineers, conduct training and workshops, and support purple-team collaboration.
  • Monitor threat intelligence, emerging vulnerabilities, malware trends, and attack vectors.
  • Present findings to security teams, management, stakeholders, and RFP participants.

Qualifications and Experience

  • A bachelor’s degree in Cybersecurity, Computer Science, or a related field, or equivalent work experience, is required.
  • A cybersecurity-related certification is required; CISM and CISSP are preferred.
  • 8–10 years of relevant experience and mandatory team lead experience are required.
  • Deep SIEM monitoring, alert triage, detection engineering, and advanced log analysis experience are required.
  • Experience with SIEM, EDR, NDR, IDS/IPS, firewalls, threat intelligence platforms, and complex queries is required.
  • Experience designing SOAR automation, playbooks, runbooks, and operational documentation is required.
  • Strong knowledge of TCP/IP, HTTP/S, DNS, FTP, SMTP, Anti-DDoS monitoring, and cyber threat intelligence is required.
  • Microsoft Sentinel or Splunk training is preferred.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at e& UAE