Cloud Security & SIEM Engineer (SOC)

Client of ITHR 360° CONSULTING FZE

Dubai

On-site

AED 240,000 - 360,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Client of ITHR 360° CONSULTING FZE in Dubai seeks a Cloud Security & SIEM Engineer to secure cloud environments (AWS, Azure, GCP) and to integrate telemetry with SIEM platforms. You will monitor cloud activity, investigate security events, and automate security operations.

The role requires hands-on cloud security, logging, IAM, network security, and incident response skills. Immediate joiners preferred; onsite in Dubai for a permanent position.

Qualifications

  • Bachelor's degree in cybersecurity or related field.
  • 3–8 years of cybersecurity/cloud security/SOC experience.
  • Hands-on with AWS, Azure, or GCP and cloud security basics.
  • Knowledge of IAM, RBAC, MFA, and least-privilege access.
  • Experience configuring cloud logs and SIEM integrations.
  • Strong analytical, troubleshooting, and documentation skills.

Responsibilities

  • Monitor and protect workloads across AWS, Azure and GCP.
  • Integrate cloud telemetry with SIEM platforms and maintain connectors.
  • Identify misconfigurations, excessive permissions, and network risks.
  • Develop detection rules, dashboards, and automated SOC playbooks.
  • Investigate incidents and support response; coordinate with SOC.
  • Automate security tasks using Python/PowerShell/Bash and IaC.

Skills

Cloud Security
SIEM
IAM
Python
PowerShell
Bash
Incident Response
SOC Operations
Cloud Networking
Automation

Education

Bachelor's degree in Cybersecurity / IT / CS / Engineering

Tools

Securonix
Microsoft Sentinel
Splunk
IBM QRadar
Elastic SIEM
AWS
Azure
Google Cloud Platform

Job description

Job Description: Cloud Security amp SIEM Engineer

Job Title: Cloud Security amp SIEM Engineer

Department: Security Operations Centre SOC

Location: Dubai UAE

Employment Type: Permanent

Work Arrangement: Onsite

Experience Required: 3 8 years

Mid-Level

Joining Date: Immediate joiners preferred

Role Summary

We are seeking a skilled Cloud Security amp SIEM Engineer to join our client s Security Operations Centre in Dubai The successful candidate will be responsible for securing cloud environments integrating cloud security telemetry with SIEM platforms monitoring cloud activity investigating security events and automating security operations The role requires hands-on experience across AWS Microsoft Azure or Google Cloud Platform along with strong knowledge of SIEM integration cloud-native logging identity and access management network security and security automation The ideal candidate should be able to translate cloud activity into actionable security monitoring detection investigation and response capabilities

Key Responsibilities
  • Cloud Security Operations Monitor and protect workloads and services hosted across AWS Microsoft Azure and Google Cloud Platform
  • Apply cloud security principles across IaaS PaaS and SaaS environments
  • Understand and implement security controls based on the shared responsibility model of each cloud provider
  • Identify cloud security misconfigurations excessive permissions insecure network exposure and other security risks
  • Support the implementation and continuous improvement of cloud security standards controls and operational procedures
  • Assist with cloud security assessments risk reviews and remediation activities
  • Identity and Access Management Implement and review role-based access control and least-privilege access models
  • Monitor privileged accounts service accounts authentication activities and permission changes
  • Support the enforcement of multi-factor authentication and conditional access controls
  • Investigate suspicious authentication attempts privilege escalation compromised identities and unauthorised access
  • Conduct periodic reviews of cloud roles permissions and access policies
  • Cloud Network Security Monitor and secure cloud networks including VPCs virtual networks subnets security groups firewalls routing rules and network access controls
  • Review VPC and virtual network flow logs to identify suspicious or unauthorised network activity
  • Support cloud network segmentation and Zero Trust security initiatives
  • Assist in securing connectivity between cloud on-premises and hybrid environments
  • Investigate network-based threats anomalous traffic unauthorised connections and exposed cloud resources
  • SIEM Integration and Monitoring Integrate cloud services and security telemetry with SIEM platforms such as Securonix Microsoft Sentinel Splunk IBM QRadar Elastic SIEM Configure and maintain cloud-native connectors API-based integrations and agent-based log ingestion Onboard validate normalise and troubleshoot cloud log sources Develop and optimise detection rules correlation rules dashboards alerts reports and investigation queries Ensure that cloud security logs are accurately collected parsed classified enriched and retained Monitor ingestion failures data gaps parsing issues and abnormal log-volume changes
  • Cloud Logging and Analysis Configure and monitor AWS CloudWatch AWS CloudTrail Azure Monitor Azure Activity Logs and related cloud-native logging services Collect and analyse security-relevant logs including API and administrative activity Authentication and access logs VPC and network flow logs DNS logs Firewall and security-group logs Audit and configuration-change logs Container and orchestration logs AKS EKS and ECS logs Conduct log parsing field extraction event classification filtering masking and enrichment Identify unusual activity and behavioural anomalies using SIEM analytics and cloud-native monitoring tools Maintain adequate logging coverage to support security monitoring investigations and audit requirements
  • Security Incident Detection and Response Monitor and triage cloud security alerts generated by SIEM and cloud-native security platforms Investigate suspicious activity compromised identities unauthorised access cloud configuration changes and potential data exposure Determine the severity scope business impact and root cause of cloud security incidents Escalate confirmed incidents in accordance with SOC procedures and response timelines Support containment remediation recovery and post-incident review activities Document investigation findings evidence response actions and recommendations Contribute to the development of cloud-specific incident-response playbooks and use cases
  • Automation and Secure Cloud Deployment Develop scripts using Python PowerShell or Bash for security automation log parsing enrichment validation and investigation Automate repetitive SOC and cloud security processes where appropriate Use Infrastructure as Code tools such as Terraform AWS CloudFormation and Azure Bicep to support secure cloud deployments Review Infrastructure as Code templates for security risks and configuration weaknesses Develop security workflows using services such as AWS Lambda Amazon EventBridge Azure Logic Apps Cloud-native automation and orchestration services Support automated alert enrichment notification containment and remediation workflows
  • Compliance and Governance Support log-retention policies and ensure that security logs are protected against unauthorised alteration or deletion Maintain audit-ready evidence relating to cloud access administrative activity security events and incident investigations Support compliance requirements aligned with applicable frameworks and standards including PCI DSS and HIPAA where relevant Maintain technical documentation cloud security procedures integration records and operational runbooks Participate in periodic audits security assessments and control-testing activities
Required Qualifications and Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
  • 3 – 8 years of relevant experience in cybersecurity, cloud security, SIEM engineering, or Security Operations Centre environments.
  • Practical experience with at least one major cloud provider: AWS, Microsoft Azure, or Google Cloud Platform.
  • Strong understanding of IaaS, PaaS, and SaaS security responsibilities.
  • Working knowledge of cloud shared-responsibility models.
  • Hands-on knowledge of identity and access management, RBAC, least privilege, MFA, and privileged-access monitoring.
  • Experience with cloud network security concepts, including VPCs, virtual networks, security groups, firewalls, segmentation, and Zero Trust.
  • Experience with at least one enterprise SIEM platform, preferably Securonix, Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
  • Experience integrating cloud logs into a SIEM through native connectors, APIs, or agents.
  • Knowledge of cloud audit, authentication, network, DNS, and activity logs.
  • Experience investigating cloud security alerts and supporting incident-response activities.
  • Working knowledge of Python, PowerShell, or Bash.
  • Strong analytical, troubleshooting, and documentation skills.
  • Ability to work independently in a fast-paced, onsite SOC environment.
Preferred Skills
  • Multi-cloud security experience across AWS, Azure, and GCP.
  • Experience monitoring Kubernetes and container environments, including AKS, EKS, and ECS.
  • Knowledge of Terraform, CloudFormation, or Bicep.
  • Experience with AWS Lambda, Amazon EventBridge, or Azure Logic Apps.
  • Familiarity with cloud security posture management and cloud workload protection platforms.
  • Experience creating SIEM detection rules, use cases, dashboards, and automated response playbooks.
  • Understanding of MITRE ATT&CK techniques relevant to cloud environments.
  • Knowledge of PCI DSS, HIPAA, ISO 27001, NIST, CIS Benchmarks, or other recognised security frameworks.
  • Experience supporting compliance audits and log-retention requirements.
  • Exposure to threat hunting and behavioural anomaly detection in cloud environments.
Preferred Certifications
  • Any of the following certifications would be advantageous: Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, Microsoft Security Operations Analyst (SC-200), Relevant SIEM Administrator or SIEM Engineer certification, Other recognised cloud security or SOC certifications.
Key Competencies
  • Strong cloud security and SOC fundamentals
  • Analytical and investigative thinking
  • Security-event correlation and log analysis
  • Incident prioritisation and response
  • Automation-oriented approach
  • Attention to detail
  • Clear technical documentation
  • Effective communication and stakeholder coordination
  • Ability to manage security incidents under time-sensitive conditions
Candidate Profile

The preferred candidate is a hands-on cloud security professional with practical SIEM and SOC experience. The individual should be capable of onboarding cloud log sources, developing monitoring use cases, investigating cloud security events, and automating operational security activities. Candidates who are currently available in the UAE or able to join immediately will be given preference.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Olik Global • Dubai

On-site
AED 240,000 - 420,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR 360° CONSULTING FZE • Dubai

On-site
AED 180,000 - 300,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Qode • Dubai

On-site
AED 312,000 - 502,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC • Dubai

On-site
AED 250,000 - 420,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Qode • United Arab Emirates

On-site
AED 240,000 - 360,000
SOC Cloud Security & SIEM Engineer
SOC Cloud Security & SIEM Engineer

Qode • United Arab Emirates

On-site
AED 240,000 - 360,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR 360° CONSULTING FZE • Dubai

On-site
AED 180,000 - 300,000
Dubai Onsite Cloud Security & SIEM Engineer (SOC)
Dubai Onsite Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC • Dubai

On-site
AED 250,000 - 420,000
Cloud Security & SIEM Engineer — SOC (Onsite, Dubai)
Cloud Security & SIEM Engineer — SOC (Onsite, Dubai)

Qode • Dubai

On-site
AED 312,000 - 502,000
Cloud Security & SIEM Engineer (SOC) - Dubai Onsite
Cloud Security & SIEM Engineer (SOC) - Dubai Onsite

Olik Global • Dubai

On-site
AED 240,000 - 420,000