Python, PowerShell, Jinja, Cyber Kill Chain, pervasive threats attack
Preferred Jobseekers
Jobseekers from any GCC country
Job Responsibilities:
- Lead the development, deployment, and optimization of Security Operations Centres (SOC), including SOAR implementation projects.
- Design and execute custom automation scripts and playbooks to streamline security workflows (detection, containment, response).
- Reduce MTTD/MTTR, improve recovery times, and automate security event handling in multi-tenant environments.
- Collaborate with cross-functional teams to integrate SOAR with existing security tools and processes.
- Develop and maintain SOC documentation, SOPs, SLAs, and reporting templates.
- Investigate, analyze, coordinate, and report on security events, incidents, and intrusions.
- Analyze and integrate threat intelligence data in SIEM and SOAR to enhance detection and response.
- Leverage threat intelligence to build and tune use cases for security monitoring and develop security hunting tasks.
- Stay current with emerging threats and vulnerabilities, incorporating relevant intelligence into security practices.
- Create and maintain documentation for SIEM and SOAR configurations, procedures, and playbooks.
- Generate reports on security incidents, trends, and metrics for management.
- Provide training and guidance on SIEM and SOAR best practices.
- Document incidents, investigations, and analysis activities thoroughly.
- Work with IT teams to troubleshoot and resolve security issues and configure log forwarding.
- Assist in project activities, creating/reviewing use cases, and coordinating with vendors.
- Study vulnerabilities, identify threats, and recommend corrective actions.
- Conduct SOC Maturity Model assessments.
- Stay updated on tools, techniques, and vulnerabilities.
- Promote positive behaviors aligned with DP World's principles and ensure safety.
- Perform other related duties as assigned.
Qualifications, Experience, and Skills:
- Bachelor’s Degree in Computer Science or equivalent.
- 8-10 years of experience in IT Security, with at least 6 years in log data analysis supporting intrusion or security operations.
- Deep technical knowledge across Cyber Security domains.
- Knowledge of current cyber threats, attack lifecycle, TTPs, and the Cyber Kill Chain.
- Hands-on experience with SIEM and SOAR solutions.
- Understanding of security frameworks and compliance regulations.
- Proficiency in scripting languages like Python, PowerShell, Jinja.
- Excellent analytical and communication skills.
- Industry certifications such as CISSP, GIAC, NSE, or Microsoft Azure.
- Understanding of e-commerce, logistics, supply chain, and port operations is a plus.
- Knowledge of the MITRE framework and attack vectors.
- Experience in multi-tenant environments preferred.
You will be redirected to the company website to apply for this position.