Analyst - Security Operations

Core42

United Arab Emirates

On-site

AED 100,000 - 140,000

Full time

4 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Core42 is seeking an Incident Analyst to anchor the technical depth of our 24×7 Security Operations Center. You will own incidents end-to-end—from first alert in Splunk through containment, eradication, and recovery—while improving detections and mentoring junior analysts.

The role requires hands-on expertise across Splunk, Cribl, Elastic Security and Corelight, with a focus on threat detection, triage, and rapid response within a private-cloud/OpenShift/OpenStack environment.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity or related field; equivalent professional experience considered
  • 4–8 years in security operations, incident response or SOC monitoring
  • Hands‑on experience with Splunk — advanced SPL, dashboard development, alert creation, correlation and administration
  • Experience with Cribl Stream/Edge — data routing, filtering, pipelines and log enrichment
  • Strong incident analysis, escalation management and full‑lifecyle response aligned with industry standards
  • Familiarity with private-cloud and platform log sources — Red Hat OpenShift, OpenStack, etc.

Responsibilities

  • Monitor security alerts in Splunk to identify threats and anomalies across the private-cloud platform and enterprise services
  • Own security incidents end-to-end: identification, containment, eradication, recovery and post-incident review
  • Develop and maintain incident response playbooks and SOPs; drive improvements after major incidents
  • Create and tune Splunk correlation searches, alerts, dashboards and reports to improve detection quality
  • Lead threat hunts linked to MITRE ATT&CK and other frameworks; map coverage and report gaps
  • Document RCA and incident details; support audit and compliance requirements

Skills

Security operations
Incident response
Threat hunting
SOP development
Communication

Education

Bachelor's degree in CS/InfoSec

Tools

Splunk
Cribl
Elastic Security
Corelight

Job description

Analyst - Security Operations 8/24/26

We are looking for Incident Analyst to anchor the technical depth of our 24×7 Security Operations Center. This role detects, triages, investigates and responds to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate is a hands‑on practitioner who can own an incident end to end - from the first alert in Splunk through containment, eradication and recovery - while also raising the quality of our detections and acting as a senior escalation point and mentor for less experienced analysts. The environment is a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR) and Corelight (NDR); comfort working across virtualized and containerized infrastructure log sources is expected.

Your Key Responsibilities
Security Monitoring, Triage & Detection
  • Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
  • Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
  • Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise
Incident Response (full lifecycle)
  • Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post-incident review
  • Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
  • Lead the response on assigned incidents and coordinate cross-team activity to ensure timely investigation, escalation and resolution
  • Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident
SIEM, Detection Engineering & Log Pipeline
  • Create, tune and optimize Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
  • Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
  • Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic, weighing false‑positive cost against miss cost when making tuning decisions
  • Support onboarding of new log sources and validate log quality, parsing, field extraction and normalization
  • Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalization, optimizing data flow and Splunk license consumption
Threat Hunting & Intelligence
  • Conduct hypothesis‑driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
  • Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
  • Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response
  • Identify patterns, trends and indicators of compromise (IOCs) to proactively detect and prevent recurrence
Documentation, Reporting & Governance
  • Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
  • Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned in the case-management platform
  • Contribute to the continuous improvement of security monitoring use cases and detection rules
  • Support audit and compliance requirements by providing evidence of incident-management activities
Working arrangement
  • Full‑time role reporting to the SOC Manager, operating within a 24×7 Security Operations Center
  • Participation in rotational shifts — day, evening and night — including weekends and public holidays on a rotational basis
  • Defined acknowledgement, triage and escalation SLAs apply to each shift, with structured shift handovers to maintain continuity of in-flight incidents
What We’re Looking For
  • Required skills / qualifications
Education
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
Experience
  • 4–8 years in security operations, incident response or SOC monitoring
  • Proven hands‑on experience with Splunk — advanced SPL, dashboard development, alert creation, correlation and administration
  • Demonstrated experience with Cribl Stream/Edge — data routing, filtering, pipelines and log enrichment
  • Strong background in incident analysis, investigation, evidence handling, escalation management and full‑lifecycle response aligned with industry standards
Technical Skills
  • SIEM: Splunk Enterprise / Splunk Cloud — advanced SPL, dashboard development, correlation searches, alert tuning, administration
  • Data Pipeline: Cribl Stream / Cribl Edge — log routing, parsing, filtering, enrichment and pipeline management
  • EDR / NDR: Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation and response
  • Incident Response: end-to-end IR lifecycle, playbook and SOP development, RCA, evidence collection and handling
  • Threat Frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain, Diamond Model
  • Networking: strong understanding of TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS
  • Operating Systems: proficiency in Windows and Linux environments
  • Scripting: proficiency in Python, Bash or PowerShell for automation and analysis
  • Platform Technologies: familiarity with private-cloud and platform log sources — Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
  • Ticketing / Case Mgmt: ServiceNow, Jira or equivalent for incident tracking, evidence attachment, escalation notes and closure documentation
  • Preferred skills / qualifications
Industry Certifications, Such As
  • Splunk Core Certified Power User or Splunk Certified Admin
  • Cribl Certified Admin
  • GIAC certifications relevant to detection and response — GCIA, GCIH, GCDA or GCFA
  • Blue Team Level 2 (BTL2) or equivalent hands‑on defensive certification
  • Experience monitoring OpenStack and Kubernetes/OpenShift environments
  • Familiarity with detection‑as‑code practices (version control and peer review of detection content)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Splunk Sentinel and Cribl
Senior Security Engineer - Splunk Sentinel and Cribl

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C • Dubai

On-site
AED 300,000 - 550,000
Senior IT Security Operations Engineer (Russian & Sri Lankan Nationals)
Senior IT Security Operations Engineer (Russian & Sri Lankan Nationals)

VaporVM • Dubai

On-site
AED 350,000 - 480,000
Services Delivery Manager
Services Delivery Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 280,000 - 520,000
SOC Manager
SOC Manager

Noventiq Seven Seas Technology • Dubai Emirate

On-site
AED 500,000 - 700,000
Senior SOC Incident Response Analyst
Senior SOC Incident Response Analyst

Core42 • United Arab Emirates

On-site
AED 100,000 - 140,000
Senior Engineer – SOC (SIEM)
Senior Engineer – SOC (SIEM)

CPX • Abu Dhabi

On-site
AED 223,000 - 234,000
SOC Manager
SOC Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 380,000 - 660,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

VaporVM • Dubai

On-site
AED 250,000 - 390,000
Senior SOC Analyst
Senior SOC Analyst

Deriv.com • Dubai

On-site
AED 350,000 - 550,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Client of ITHR 360° CONSULTING FZE • Dubai

On-site
AED 240,000 - 360,000