About the job
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
We are looking for a senior Security Analyst to anchor the technical depth of our 24x7 Security Operations Centre in Abu Dhabi, UAE. This role involves detecting, triaging, investigating, and responding to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate will take ownership of security incidents from the first alert in Splunk through containment, eradication, and recovery. Additionally, this role involves raising the quality of our detections and serving as a senior escalation point and mentor for less-experienced analysts. The environment includes a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR), and Corelight (NDR). Comfort working across virtualised and containerised infrastructure log sources is expected. This position operates on a full-time, 24x7 rotational shift basis and reports to the SOC Manager.
Your Key Responsibilities
Security monitoring, triage & detection
- Monitor security alerts and events in Splunk to identify threats, anomalies, and malicious activity across the private-cloud platform and enterprise services.
- Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident.
- Serve as the senior escalation point for front-line analysts, providing investigative guidance and validating findings before escalation.
- Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware, and endpoint or network compromise.
Incident response (full lifecycle)
- Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery, and post-incident review.
- Execute containment and remediation actions in coordination with platform, infrastructure, network, and application teams.
- Lead the response on assigned incidents and coordinate cross-team activity to ensure timely investigation, escalation, and resolution.
- Develop and maintain incident response playbooks and standard operating procedures (SOPs) and drive their improvement after each major incident.
SIEM, detection engineering & log pipeline
- Create, tune, and optimize Splunk correlation searches, alerts, dashboards, and reports to improve detection quality and coverage.
- Write and maintain efficient SPL queries supporting investigation, hunting, reporting, and detection engineering.
- Reduce alert fatigue by tuning noisy detections, lowering false positives, and strengthening correlation logic.
- Support onboarding of new log sources and validate log quality, parsing, field extraction, and normalization.
- Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment, and normalization, optimizing data flow and Splunk license consumption.
Threat hunting & intelligence
- Conduct hypothesis-driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections.
- Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections.
- Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response.
- Identify patterns, trends, and indicators of compromise (IOCs) to proactively detect and prevent recurrence.
Documentation, reporting & governance
- Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders.
- Maintain accurate, detailed records of incidents, actions taken, evidence collected, and lessons learned in the case-management platform.
- Contribute to the continuous improvement of security monitoring use cases and detection rules.
- Support audit and compliance requirements by providing evidence of incident-management activities.
Working arrangement
- Operate within a 24x7 SOC, participating in rotational day, evening, and night shifts, including weekends and public holidays on a rotational basis.
- Meet defined acknowledgment, triage, and escalation SLAs on each shift and complete structured shift handovers to maintain continuity of in-flight incidents.
What We’re Looking For
Required skills / qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree.
- 5-8 years in security operations, incident response or SOC monitoring, with at least 2 years at a senior level.
- Proven hands-on experience with Splunk Enterprise / Splunk Cloud - advanced SPL, dashboard development, correlation searches, alert creation and tuning, and administration.
- Demonstrated experience with Cribl Stream / Cribl Edge - log routing, parsing, filtering, enrichment and pipeline management.
- Strong background in incident analysis, investigation, evidence handling, escalation management and full-lifecycle response aligned with industry standards, including playbook and SOP development and RCA.
- Experience with Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation, and response.
- Familiarity with threat frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain and Diamond Model.
- Strong understanding of networking: TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS.
- Proficiency in Windows and Linux environments.
- Proficiency in Python, Bash or PowerShell for automation and analysis.
- Familiarity with private-cloud and platform log sources: Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure.
- Experience with ticketing/case management tools such as ServiceNow or Jira for incident tracking, evidence attachment, escalation notes and closure documentation.
Preferred skills / qualifications
- Splunk Core Certified Power User or Splunk Certified Admin.
- Cribl Certified Admin.
- GIAC certifications relevant to detection and response - GCIA, GCIH, GCDA or GCFA.
- Blue Team Level 2 (BTL2) or equivalent hands-on defensive certification.
- Experience monitoring OpenStack and Kubernetes/OpenShift environments.
- Familiarity with detection-as-code practices (version control and peer review of detection content).
What Working At the company Offers
With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At the company, we value trust, accountability, and high performance and aim to inspire progress and create meaningful change. Our team thrives in an environment where each person’s contributions propel us forward towards extraordinary results.
- Competitive Salary: We offer an attractive salary package based on your skills and experience.
- Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus.
- Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services.
- Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your family.
- Learning & Development: We offer access to top-tier learning platforms to help you grow in your career with unlimited access to premium courses.