About the Role / About the Job
The Security Operations Centre team at the company is a cross-functional Operations/Engineering team involved in all phases of our application and service release lifecycle, embracing the SecOps communication, collaboration, and integration method. The Senior Security Analyst is responsible for leading security monitoring efforts, analyzing various log sources, responding to security incidents, and enhancing the overall security operations program within elements of the company/Client technology.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
Key Responsibilities:
- Validate the incidents escalated by Tier 1 SOC Security Analysts.
- Perform second-level analysis of threat conditions and determine which security issues may impact the organization's services and information.
- Conduct research, analysis, and correlation across a wide variety of data sets (e.g., indications and warnings).
- Provide recommendations for incident handling and security monitoring, and validation of physical security.
- Identify weaknesses in software, hardware, and networks.
- Analyze and communicate with stakeholders the threats associated with every incident.
- Coordinate with relevant stakeholders to validate network alerts.
- Conduct analysis of log files, evidence, and other information to determine the best methods for identifying attackers.
- Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
- Monitor external data sources (e.g., Threat Intelligent sources, Dubai AE-CERT Teams, etc.) to maintain and enhance SIEM content development, tuning, reports, and dashboards.
Characteristics
- Excellent communication skills: written, verbal, and interpersonal.
- Strong team player with a customer service orientation, and the ability to forge relationships at all levels of the company and across diverse cultures.
- Ethical, honest, fair, and with high integrity.
- Excellent organizational and time management skills.
- Exhibits ownership of projects and assigned tasks.
- In-depth understanding of the incident response process, analysis, alerts, rules, etc.
- Highly analytical with strong problem-solving skills, thriving in an energetic, fast-paced, high-growth security team environment.
- Must be able to pass all security clearances.
- Quickly owns and handles tasks accurately, showing high dependability and self-motivation.
- Takes proper care and administration to configure, implement, and maintain DLP technologies.
Qualifications
Certifications (Technical & Non-Technical)
- Related security certifications (i.e., CCNA, Network+, Security+, CISSP, CISM, GICSP, GCIH, GCIA, GRID).
Minimum Work Experience
- Minimum 3-5 years of experience in one or more of the following areas:
- Skilled in identifying trends and patterns from analyzing host-based and network-based security logs.
- Experience with network investigation tools such as Wireshark and other open-source tools like ELK, Rekall, Ghidra, FlareVM to analyze log sources/memory/malware and understand intrusion vectors as well as attacker tactics, techniques, and procedures.
- Provide support and guidance to improve security requirements for the security operations.
- Experience with Windows/Linux/Unix, with a strong understanding of NIDS/HIDS.
- Monitoring of SIEM alerts using tools such as Splunk and EDR solutions.
Education
- BS or MS in Information Security, Computer Science, Electrical Engineering, or a related field.