{bc}
linkedin

IT Security Operations Engineer

BigData Technology Solutions
Dubai, UAE
Full-time
Mid-Senior
Onsite
Discovered 2 weeks ago
Security Operations Center operationsSIEMEDR/XDRIDS/IPSDLPIncident response
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Security Operations Center operationsSIEMEDR/XDR
Smart Apply

Full Job Posting

Job Summary

The IT Security Operations Engineer monitors, detects, analyzes, investigates, and responds to cybersecurity threats and incidents.

The role operates within a Security Operations Center and protects the confidentiality, integrity, and availability of information systems.

The position uses security technologies, threat intelligence, log analysis, and incident response processes to mitigate risk and improve SOC capabilities.

Security Monitoring and Incident Response

  • Monitor alerts from SIEM, EDR/XDR, IDS/IPS, DLP, and other security platforms.
  • Triage and investigate events, determine severity and impact, and respond under established procedures and SLAs.
  • Escalate critical incidents and support containment, eradication, recovery, and root cause analysis.
  • Coordinate with infrastructure, network, application, and cybersecurity teams.

Threat Detection and Analysis

  • Conduct proactive threat hunting using threat intelligence, telemetry, and log analysis.
  • Investigate phishing, malware, ransomware, suspicious activity, and intrusion attempts.
  • Analyze logs and network activity for indicators of compromise and abnormal behavior.
  • Develop and tune detection rules, correlation logic, use cases, and security playbooks.
  • Improve detection coverage and reduce false-positive alerts.

Vulnerability and Risk Management

  • Support vulnerability scanning, assessment, tracking, and remediation activities.
  • Coordinate patching and mitigation with IT and infrastructure teams.
  • Monitor remediation timelines and maintain awareness of critical vulnerabilities and emerging threats.
  • Support asset inventory management and identify unauthorized or suspicious changes.

Tools and Automation

  • Manage and optimize SIEM, SOAR, EDR/XDR, IDS/IPS, DLP, firewalls, and other SOC tools.
  • Integrate security platforms and log sources into the SOC monitoring environment.
  • Develop automated workflows and SOAR playbooks for incident handling.
  • Use scripting and automation for repetitive security operations and recommend tool improvements.

Investigation and Reporting

  • Analyze alerts and incidents using logs, packet captures, endpoint telemetry, and forensic information.
  • Identify attack patterns, indicators of compromise, and potential attack vectors.
  • Document findings, response actions, root cause analysis, lessons learned, and remediation recommendations.
  • Prepare reports on threats, vulnerabilities, incidents, and SOC performance.
  • Maintain procedures, playbooks, technical documentation, and audit evidence.
  • Provide knowledge transfer and technical guidance to junior SOC or security team members.

Technical Expertise

  • Strong hands-on knowledge of SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, or equivalent platforms.
  • Knowledge of EDR/XDR, endpoint protection, IDS/IPS, DLP, firewalls, and network security monitoring.
  • Knowledge of incident response, threat hunting, detection engineering, threat intelligence, and SOAR automation.
  • Knowledge of vulnerability management, Windows, Linux, cloud security, log analysis, packet capture, endpoint telemetry, and forensic tools.
  • Python, PowerShell, or Bash for security automation is an advantage.

Experience and Seniority

  • Five to eight years of relevant experience in SOC operations, cybersecurity, incident response, or IT security operations.
  • Strong hands-on experience with SIEM, endpoint security, firewalls, and security monitoring technologies.
  • Experience investigating incidents, analyzing logs, hunting threats, tuning detections, and managing security incidents.
  • Experience in an SLA-driven SOC environment.
  • Ability to work in a 24/7 SOC environment or rotational shifts where required.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at BigData Technology Solutions