Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC

Dubai

On-site

AED 220,000 - 380,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ITHR Technologies Consulting LLC is hiring a Cloud Security & SIEM Engineer to join its Dubai Security Operations Centre. The role requires securing cloud environments, integrating telemetry with SIEM platforms, monitoring activity, and investigating events across multiple cloud providers.

The candidate should have hands-on experience with AWS, Azure, or GCP, plus strong knowledge of IAM, network security, logging, and automation. SIEM proficiency and incident response skills are essential.

Qualifications

  • 3–8 years of cybersecurity, cloud security, SIEM engineering, or SOC experience.
  • Hands-on experience with at least one major cloud provider (AWS/Azure/GCP).
  • Working knowledge of IAM, RBAC, least privilege, MFA, and privileged-access monitoring.
  • Experience with cloud network security concepts, including VPCs, subnets, security groups, and firewalls.

Responsibilities

  • Monitor workloads across AWS, Azure, and Google Cloud Platform.
  • Implement security controls across IaaS, PaaS, and SaaS and follow shared-responsibility models.
  • Integrate cloud telemetry with SIEM platforms and maintain cloud-native connectors and dashboards.
  • Develop and optimize detection rules, correlation rules, dashboards, alerts, and investigation queries.
  • Support incident detection, triage, containment, and post-incident activities.

Skills

Cloud security
SIEM engineering
RBAC
MFA
Zero Trust
VPCs

Education

Bachelor's degree in Cybersecurity/IT/CS/Engineering

Tools

Securonix
Microsoft Sentinel
Splunk
IBM QRadar
Elastic SIEM

Job description

Job Description – Cloud Security & SIEM Engineer (SOC)

Job Title: Cloud Security & SIEM Engineer

Department: Security Operations Centre (SOC)

Location: Dubai, UAE

Employment Type: Permanent, Full-Time

Work Arrangement: Onsite

Experience Required: 3–8 years (Mid-Level)

Joining Date: Immediate joiners preferred

Role Summary

We are seeking a skilled Cloud Security & SIEM Engineer to join our client's Security Operations Centre in Dubai. The successful candidate will be responsible for securing cloud environments, integrating cloud security telemetry with SIEM platforms, monitoring cloud activity, investigating security events, and automating security operations.

The role requires hands‑on experience across AWS, Microsoft Azure, or Google Cloud Platform, along with strong knowledge of SIEM integration, cloud‑native logging, identity and access management, network security, and security automation.

The ideal candidate should be able to translate cloud activity into actionable security monitoring, detection, investigation, and response capabilities.

Key Responsibilities
Cloud Security Operations

Monitor and protect workloads and services hosted across AWS, Microsoft Azure and Google Cloud Platform.

Apply cloud security principles across IaaS, PaaS, and SaaS environments.

Understand and implement security controls based on the shared responsibility model of each cloud provider.

Identify cloud security misconfigurations, excessive permissions, insecure network exposure, and other security risks.

Support the implementation and continuous improvement of cloud security standards, controls, and operational procedures.

Assist with cloud security assessments, risk reviews, and remediation activities.

Identity and Access Management

Implement and review role‑based access control and least‑privilege access models.

Monitor privileged accounts, service accounts, authentication activities, and permission changes.

Support the enforcement of multi‑factor authentication and conditional access controls.

Investigate suspicious authentication attempts, privilege escalation, compromised identities, and unauthorised access.

Conduct periodic reviews of cloud roles, permissions, and access policies.

Cloud Network Security

Monitor and secure cloud networks, including VPCs, virtual networks, subnets, security groups, firewalls, routing rules, and network access controls.

Review VPC and virtual network flow logs to identify suspicious or unauthorised network activity.

Support cloud network segmentation and Zero Trust security initiatives.

Assist in securing connectivity between cloud, on‑premises, and hybrid environments.

Investigate network‑based threats, anomalous traffic, unauthorised connections, and exposed cloud resources.

SIEM Integration and Monitoring

Integrate cloud services and security telemetry with SIEM platforms such as:

  • Securonix
  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic SIEM

Configure and maintain cloud‑native connectors, API‑based integrations, and agent‑based log ingestion.

Onboard, validate, normalise, and troubleshoot cloud log sources.

Develop and optimise detection rules, correlation rules, dashboards, alerts, reports, and investigation queries.

Ensure that cloud security logs are accurately collected, parsed, classified, enriched, and retained.

Monitor ingestion failures, data gaps, parsing issues, and abnormal log‑volume changes.

Cloud Logging and Analysis

Configure and monitor AWS CloudWatch, AWS CloudTrail, Azure Monitor, Azure Activity Logs, and related cloud‑native logging services.

Collect and analyse security‑relevant logs, including:

  • API and administrative activity
  • Authentication and access logs
  • VPC and network flow logs
  • DNS logs
  • Firewall and security‑group logs
  • Audit and configuration‑change logs
  • Container and orchestration logs
  • AKS, EKS, and ECS logs

Conduct log parsing, field extraction, event classification, filtering, masking, and enrichment.

Identify unusual activity and behavioural anomalies using SIEM analytics and cloud‑native monitoring tools.

Maintain adequate logging coverage to support security monitoring, investigations, and audit requirements.

Security Incident Detection and Response

Monitor and triage cloud security alerts generated by SIEM and cloud‑native security platforms.

Investigate suspicious activity, compromised identities, unauthorised access, cloud configuration changes, and potential data exposure.

Determine the severity, scope, business impact, and root cause of cloud security incidents.

Escalate confirmed incidents in accordance with SOC procedures and response timelines.

Support containment, remediation, recovery, and post‑incident review activities.

Document investigation findings, evidence, response actions, and recommendations.

Contribute to the development of cloud‑specific incident‑response playbooks and use cases.

Automation and Secure Cloud Deployment

Develop scripts using Python, PowerShell, or Bash for security automation, log parsing, enrichment, validation, and investigation.

Automate repetitive SOC and cloud security processes where appropriate.

Use Infrastructure as Code tools such as Terraform, AWS CloudFormation, and Azure Bicep to support secure cloud deployments.

Review Infrastructure as Code templates for security risks and configuration weaknesses.

Develop security workflows using services such as:

  • AWS Lambda
  • Amazon EventBridge
  • Azure Logic Apps
  • Cloud‑native automation and orchestration services

Support automated alert enrichment, notification, containment, and remediation workflows.

Compliance and Governance

Support log‑retention policies and ensure that security logs are protected against unauthorised alteration or deletion.

Maintain audit‑ready evidence relating to cloud access, administrative activity, security events, and incident investigations.

Support compliance requirements aligned with applicable frameworks and standards, including PCI DSS and HIPAA where relevant.

Maintain technical documentation, cloud security procedures, integration records, and operational runbooks.

Participate in periodic audits, security assessments, and control‑testing activities.

Required Qualifications And Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
  • 3–8 years of relevant experience in cybersecurity, cloud security, SIEM engineering, or Security Operations Centre environments.
  • Practical experience with at least one major cloud provider: AWS, Microsoft Azure, or Google Cloud Platform.
  • Strong understanding of IaaS, PaaS, and SaaS security responsibilities.
  • Working knowledge of cloud shared‑responsibility models.
  • Hands‑on knowledge of identity and access management, RBAC, least privilege, MFA, and privileged‑access monitoring.
  • Experience with cloud network security concepts, including VPCs, virtual networks, security groups, firewalls, segmentation, and Zero Trust.
  • Experience with at least one enterprise SIEM platform, preferably Securonix, Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
  • Experience integrating cloud logs into a SIEM through native connectors, APIs, or agents.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR 360° CONSULTING FZE • Dubai

On-site
AED 180,000 - 300,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Client of ITHR 360° CONSULTING FZE • Dubai

On-site
AED 240,000 - 360,000
Cloud Security & SIEM Engineer — SOC Operations
Cloud Security & SIEM Engineer — SOC Operations

ITHR Technologies Consulting LLC • Dubai

On-site
AED 220,000 - 380,000
Cloud Security Engineer
Cloud Security Engineer

Theme Blog Studio • Dubai

On-site
AED 250,000 - 450,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR 360° CONSULTING FZE • Dubai

On-site
AED 180,000 - 300,000
Cloud Security Engineer
Cloud Security Engineer

DAG • Dubai

On-site
AED 300,000 - 540,000
Cloud Security Engineer - Hybrid Platforms
Cloud Security Engineer - Hybrid Platforms

AlFuttaim • Dubai

Hybrid
Cloud Security Engineer
Cloud Security Engineer

Confidential • Dubai

Hybrid
AED 350,000 - 550,000
Cloud Security Engineer
Cloud Security Engineer

DiceTek UAE • Dubai

On-site
Opportunity for career growth in cloud security
Work on enterprise-level security projects
Dubai Onsite Cloud Security & SIEM Engineer
Dubai Onsite Cloud Security & SIEM Engineer

Client of ITHR 360° CONSULTING FZE • Dubai

On-site
AED 240,000 - 360,000