Analyst - Security Operations

Core42

Dubai

On-site

AED 200,000 - 320,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Core42 in Dubai is seeking an Incident Analyst to anchor the 24x7 Security Operations Center. You will own end-to-end incident response from alert through containment, eradication and recovery, while elevating detection quality and mentoring junior analysts.

The role requires hands-on expertise with Splunk, Cribl and EDR/NDR tools in a private-cloud OpenStack/OpenShift environment, and collaboration across platform, network and application teams.

Qualifications

  • Bachelor’s degree or equivalent in a related field.
  • Hands-on experience with security incident handling and IR lifecycle.
  • Strong experience with Splunk SPL, dashboards and correlation.

Responsibilities

  • Monitor and triage security alerts in Splunk across private-cloud and enterprise services.
  • Own incidents end-to-end from detection to recovery and post-incident review.
  • Develop and maintain incident response playbooks and SOPs.

Skills

Incident analysis
Threat hunting
Security monitoring
SOP development
Cross-team collaboration
MITRE ATT&CK mapping

Education

Bachelor’s degree in Computer Science or related field

Tools

Splunk
Cribl
Elastic Security
Red Hat OpenShift
OpenStack

Job description

Job Description:

Analyst - Security Operations 7/31/26

The opportunity

We are looking for Incident Analyst to anchor the technical depth of our 24×7 Security Operations Center. This role detects, triages, investigates and responds to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate is a hands‑on practitioner who can own an incident end to end — from the first alert in Splunk through containment, eradication and recovery — while also raising the quality of our detections and acting as a senior escalation point and mentor for less‑experienced analysts. The environment is a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR) and Corelight (NDR); comfort working across virtualized and containerized infrastructure log sources is expected.

Your Key Responsibilities
Security Monitoring, Triage & Detection
  • Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
  • Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
  • Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise
Incident Response (full lifecycle)
  • Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post-incident review
  • Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
  • Lead the response on assigned incidents and coordinate cross‑team activity to ensure timely investigation, escalation and resolution
  • Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident
SIEM, Detection Engineering & Log Pipeline
  • Create, tune and optimize Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
  • Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
  • Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic, weighing false‑positive cost against miss cost when making tuning decisions
  • Support onboarding of new log sources and validate log quality, parsing, field extraction and normalization
  • Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalisation, optimizing data flow and Splunk license consumption
Threat Hunting & Intelligence
  • Conduct hypothesis-driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
  • Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
  • Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response
  • Identify patterns, trends and indicators of compromise (IOCs) to proactively detect and prevent recurrence
Documentation, Reporting & Governance
  • Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
  • Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned in the case-management platform
  • Contribute to the continuous improvement of security monitoring use cases and detection rules
  • Support audit and compliance requirements by providing evidence of incident‑management activities
Working arrangement
  • Full‑time role reporting to the SOC Manager, operating within a 24×7 Security Operations Center
  • Participation in rotational shifts — day, evening and night — including weekends and public holidays on a rotational basis
  • Defined acknowledgement, triage and escalation SLAs apply to each shift, with structured shift handovers to maintain continuity of in‑flight incidents
What We’re Looking For
  • Required skills / qualifications
Education
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
Experience
  • 4–8 years in security operations, incident response or SOC monitoring
  • Proven hands‑on experience with Splunk — advanced SPL, dashboard development, alert creation, correlation and administration
  • Demonstrated experience with Cribl Stream/Edge — data routing, filtering, pipelines and log enrichment
  • Strong background in incident analysis, investigation, evidence handling, escalation management and full‑lifecycle response aligned with industry standards
Technical Skills
  • SIEM: Splunk Enterprise / Splunk Cloud — advanced SPL, dashboard development, correlation searches, alert tuning, administration
  • Data Pipeline: Cribl Stream / Cribl Edge — log routing, parsing, filtering, enrichment and pipeline management
  • EDR / NDR: Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation and response
  • Incident Response: end‑to‑end IR lifecycle, playbook and SOP development, RCA, evidence collection and handling
  • Threat Frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain, Diamond Model
  • Networking: strong understanding of TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS
  • Operating Systems: proficiency in Windows and Linux environments
  • Scripting: proficiency in Python, Bash or PowerShell for automation and analysis
  • Platform Technologies: familiarity with private‑cloud and platform log sources — Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
  • Ticketing / Case Mgmt: ServiceNow, Jira or equivalent for incident tracking, evidence attachment, escalation notes and closure documentation
Preferred skills / qualifications
  • Preferred skills / qualifications
Industry Certifications, Such As
  • Splunk Core Certified Power User or Splunk Certified Admin
  • Cribl Certified Admin
  • GIAC certifications relevant to detection and response — GCIA, GCIH, GCDA or GCFA
  • Blue Team Level 2 (BTL2) or equivalent hands‑on defensive certification
  • Experience monitoring OpenStack and Kubernetes/OpenShift environments
  • Familiarity with detection-as-code practices (version control and peer review of detection content)

Requirements:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Good co India • United Arab Emirates

On-site
AED 350,000 - 750,000
Senior SOC Analyst
Senior SOC Analyst

Good co India • United Arab Emirates

On-site
AED 180,000 - 300,000
Senior Engineer – SOC (SIEM)
Senior Engineer – SOC (SIEM)

CPX • Abu Dhabi

On-site
AED 240,000 - 480,000
Engineer/Incident Management
Engineer/Incident Management

e& UAE • Abu Dhabi

On-site
AED 180,000 - 260,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Intertec Systems • Dubai

On-site
AED 134,000 - 223,000
Senior SOC Analyst
Senior SOC Analyst

CPX • Abu Dhabi

On-site
AED 120,000 - 180,000
Senior SIEM Admin
Senior SIEM Admin

Moro Hub • Dubai

On-site
AED 420,000 - 720,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC • Dubai

On-site
AED 250,000 - 420,000
SOC Lead
SOC Lead

Intertec Softwares • Dubai

On-site
AED 300,000 - 600,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Qode • Dubai

On-site
AED 312,000 - 502,000