About the Role
Join the company Security and help organizations strengthen their ability to detect, investigate, and respond to sophisticated cyber threats. As a Security Delivery Specialist, you will serve as a senior cybersecurity practitioner responsible for delivering and enhancing Security Operations Center capabilities across Incident Response, SIEM, Endpoint Detection and Response (EDR), and Network Detection and Response (NDR). You will combine hands-on technical expertise with leadership and stakeholder management, guiding security teams through complex investigations, improving detection capabilities, and helping mature cyber defense processes and technologies.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
What You’ll Do
Incident Response & SOC Operations
- Develop, maintain, and continuously improve Incident Response plans, SOC policies, processes, procedures, and operational playbooks.
- Lead and support the detection, investigation, containment, and response to cybersecurity events and incidents.
- Perform detailed analysis of security events and provide technical guidance to analysts and other security team members.
- Support the development and continuous maturity of Cybersecurity Operations Center processes and procedures.
- Provide technical leadership during complex incidents, investigations, and escalations.
- Participate in on-call and after-hours security support when required.
SIEM & Detection Engineering
- Work closely with SIEM engineers and other cybersecurity teams to develop, refine, and optimize security correlation rules.
- Analyze security telemetry and events to identify suspicious activity, attack patterns, and potential threats.
- Develop and tune custom correlation and detection rules leveraging SIEM, EDR, and NDR telemetry.
- Identify opportunities to enhance security detection coverage and monitoring effectiveness.
- Support the integration of endpoint, network, and other security technologies with enterprise SIEM platforms.
EDR Administration
- Administer and optimize enterprise Endpoint Detection and Response (EDR) technologies.
- Deploy, upgrade, and maintain EDR agents across Windows, macOS, and Linux environments.
- Monitor endpoint agent health and troubleshoot systems that are not reporting as expected.
- Develop, maintain, and optimize EDR security policies and configurations.
- Integrate EDR technologies with SIEM and other cybersecurity platforms.
- Periodically review EDR configurations and recommend enhancements to strengthen endpoint detection and response capabilities.
- Coordinate and manage technical support cases with EDR technology vendors as required.
NDR Administration
- Administer and optimize Network Detection and Response (NDR) technologies.
- Develop, maintain, and enhance NDR policies and configurations.
- Integrate NDR technologies with SIEM and the broader security technology ecosystem.
- Develop custom correlation rules utilizing EDR and NDR security telemetry.
- Review existing NDR configurations and identify potential improvements and enhancements.
- Troubleshoot platform issues and coordinate vendor support through resolution.
Cyber Intelligence, Leadership & Reporting
- Produce clear, actionable cyber intelligence and security reports communicating technical findings, risks, and recommendations.
- Translate complex security issues for audiences ranging from security practitioners to non-technical business stakeholders and senior management.
- Provide technical leadership, coaching, and guidance to cybersecurity team members.
- Collaborate effectively across SOC, infrastructure, network, application, and broader security teams.
- Communicate technical and strategic cybersecurity matters clearly to stakeholders at different organizational levels.
What You’ll Need
- Strong experience in Security Operations and Incident Response.
- Experience developing or maintaining Incident Response plans and SOC policies, procedures, and processes.
- Strong hands-on experience with Security Information and Event Management (SIEM) technologies.
- Experience developing, tuning, or refining security correlation and detection rules.
- Hands-on expertise administering EDR and NDR technologies.
- Experience deploying and maintaining endpoint security agents across Windows, macOS, and Linux.
- Experience integrating EDR/NDR platforms with SIEM and other security technologies.
- Strong knowledge of security-event analysis, investigation, detection, and response.
- Strong analytical, troubleshooting, and organizational capabilities.
- Ability to technically lead teams and provide guidance during complex cybersecurity investigations.
- Excellent verbal and written communication skills, with the ability to engage both technical and non-technical stakeholders.
- Strong documentation and security-reporting capabilities.
- Ability to participate in on-call or after-hours support when required.
Bonus Points If You Have
- GIAC Certified Incident Handler (GCIH)
- GIAC Continuous Monitoring Certification (GMON)
- GIAC Certified Forensic Analyst (GCFA)
- Equivalent industry-recognized cybersecurity, SOC, digital forensics, or Incident Response certifications.
- Experience within large-scale enterprise Security Operations Centers.
- Exposure to threat hunting, cyber threat intelligence, and detection engineering.
- Experience supporting complex or managed cybersecurity environments.