About the Role
The Security Operations Centre team is a cross-functional Operations/Engineering team involved at all phases of application and service release lifecycle, embracing the SecOps communication, collaboration, and integration method. The Senior Security Analyst is responsible for leading security monitoring efforts, analyzing various log sources, responding to security incidents, and enhancing the overall security operations program within elements of technology.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
Key Responsibilities include:
- Validate the incidents escalated by Tier 1 SOC Security Analysts.
- Perform secondary evaluation of threat conditions and determine which security issues may impact organizational services and information.
- Conduct research, analysis, and correlation across a wide variety of data sets (e.g., indications and warnings).
- Provide recommendations for incident handling, security monitoring and validation of physical security.
- Identify weaknesses in software, hardware, and networks.
- Analyze and communicate with stakeholders about the threats associated with every incident.
- Coordinate with relevant stakeholders to validate network alerts.
- Conduct analysis of log files, evidence, and other information to determine best methods for identifying attackers.
- Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
- Monitor external data sources (e.g., Threat Intelligence sources, Dubai AE-CERT Teams, etc.) to maintain current SIEM content development, tuning, reports, and dashboards.
Characteristics
- Excellent communication skills: written, verbal, and interpersonal.
- Strong team player with a customer service orientation, able to forge relationships at all levels of the organization and across diverse cultures.
- Ethical, honest, fair, and with high integrity.
- Excellent organizational and time management skills.
- Exhibits ownership of projects and assigned tasks.
- In-depth understanding of the incident response process, analysis, alerts, and rules.
- Highly analytical with strong problem-solving skills, thriving in an energetic, fast-paced, high-growth security team environment.
- Must be able to pass all security clearances.
- Highly dependable, self-motivated, and capable of accurately handling tasks.
- Responsible for configuring, implementing, and maintaining Data Loss Prevention (DLP) technologies.
Qualifications
Certifications (Technical & Non-Technical):
- Related security certifications (i.e., CCNA, Network+, Security+, CISSP, CISM, GICSP, GCIH, GCIA, GRID).
Minimum Work Experience:
- 3-5 years of experience in one or more of the following:
- Skilled in identifying trends and patterns from analyzing host-based and network-based security logs.
- Experience with network investigation tools such as Wireshark, and other open-source tools like ELK, Rekall, Ghidra, FlareVM, to analyze log sources, memory, and malware to understand intrusion vectors and attacker tactics, techniques, and procedures.
- Provide support and guidance to improve security requirements for security operations.
- Experience with Windows/Linux/Unix, along with an understanding of NIDS/HIDS.
- Monitoring SIEM alerts with tools such as Splunk and EDR solutions.
Education:
- BS or MS in Information Security, Computer Science, Electrical Engineering, or related field.