Company logo hidden

Senior SOC Analyst

Unlock employer Dubai, United Arab Emirates Direct to Company 1 hour ago · 09 Oct 2026

Financial

  • Estimate: $80k - $120k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

About the Job
We're not hiring a security engineer to keep up with threats. We're hiring someone to make threats irrelevant before they become incidents.
Most security teams react. They tune SIEM rules after the alert fires, write playbooks after incidents close, and patch after scans flag vulnerabilities. Our goal is to build an autonomous security operations platform that hunts proactively, responds automatically, and learns continuously in real time. This mission is crucial as we handle real money, adhere to strict regulations, and face significant consequences if security measures fail.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Why This Matters
Our mission is trading for anyone, anywhere, anytime, which means millions of traders rely on our platform globally. At this scale, a misconfigured WAF rule or undetected lateral movement isn't just a technical inconvenience—it risks traders' funds and can draw regulatory scrutiny. Our Security Operations team is not just defending a perimeter; we protect a living, distributed system that processes transactions 24/7. Our detection and response capabilities must always be awake, which is why we embed AI and automation at every layer of our security stack.

The Challenge
Most of the job is quiet. Alerts fire, and while most are noise, you clear them and move on. Then there are days when something feels off—a login from an unusual location, a process initiating something abnormal—and the entire shift pivots in minutes. That's the essence of the job: long stretches of discipline followed by rapid responses to potential threats.
With $600 billion moving through our platform every month, we attract significant attention from state-sponsored crews, financially motivated groups, and insiders. We do not wait for a vendor's threat intel feed to signal problems; we actively hunt for threats ourselves. If your concept of SOC work involves merely clearing a queue, this role is not for you. However, if you want to develop detections that uncover blind spots before they escalate into incidents, keep reading.

Why Us

  • Autonomous security operations platform processing real alerts in real-time, not just conceptual plans.
  • An automated security review is conducted on every pull request across engineering.
  • Security detection coverage is actively extending into our AI agent stack, addressing prompt injection, tool misuse, and credential exposure—areas many SOCs have yet to evaluate thoroughly.
  • A dedicated Security & AI Engineering organization where detection and response are treated as distinct, essential disciplines rather than mere compliance tasks.
  • Opportunities to share insights and learnings about our projects, mistakes, and successes.

What You’ll Do

  • Hunt proactively across infrastructure, cloud, identity, and endpoint, operating from hypotheses and not just waiting for alerts.
  • Build, tune, and maintain detections aligned with real attacker tactics, techniques, and procedures (TTPs) as outlined in MITRE ATT&CK, rather than relying on vendor defaults.
  • Own incident handling end-to-end: from triage to containment, root cause analysis, and actionable reporting leading to fixes.
  • Challenge any tuning decisions, exclusions, or assumptions that potentially obscure visibility in favor of noise reduction, catching them before they are implemented.
  • Collaborate with the Red Team on purple team exercises, ensuring every finding contributes to improved detection.
  • Extend detection and monitoring coverage into our AI agent stack, addressing issues like prompt injection and credential exposure during agent workflows.
  • Perform malware analysis and reverse engineering to enhance understanding beyond what standard reports provide.
  • Mentor junior analysts and elevate the standards of what "triaged" truly means.

Who You Are

  • You have 6+ years of experience in a SOC, threat hunting, or DFIR role with substantial incident ownership, not just routine alert handling.
  • GCFA, GCIH, GCIA, or similar DFIR/detection engineering credentials are strongly preferred.
  • You possess deep expertise in at least three of the following areas: EDR internals and endpoint telemetry, cloud security monitoring (AWS/GCP), network forensics, malware analysis, SIEM, and detection-as-code, identity threat hunting.
  • You are comfortable writing your own detection logic and tooling in Python or an appropriate query language, avoiding mere copy-pasting from vendor examples.
  • You approach detection creation with an attacker’s mindset to ensure effectiveness.
  • You recognize the difference between merely reducing noise and inadvertently creating blind spots, and you've successfully caught such mistakes before they lead to incidents.
  • You can craft reports that prompt actionable fixes instead of just getting filed away.

The Honest Reality
You will be part of a Security & AI Engineering organization that regards detection and response as a legitimate discipline rather than a box to tick off for compliance. You will engage collaboratively across Dubai and Malaysia with a team focused on real incident responses rather than theoretical exercises. You will enjoy a direct connection between identifying threats and resolving them effectively, and have the freedom to shape strategies for detection and protection against evolving AI agent threats.

Apply Direct

Jobs you might like   View all jobs

About Financial Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct