Engineer/Incident Management

e& UAE

Abu Dhabi

On-site

AED 180,000 - 260,000

Full time

1 hour ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

e& UAE is seeking a technical SOC Specialist with 3-5 years of experience to lead incident response and threat detection within its 24/7 Security Operations Center. The role covers the full incident lifecycle from triage to remediation, requiring strong Windows and Linux knowledge and the ability to design automated FortiSOAR playbooks.

The ideal candidate will tackle real-time monitoring, SIEM alert prioritization, and detailed threat analysis while documenting all actions in the ticketing

Qualifications

  • BSc in Computer Science, Electrical/Computer/Software Engineering.
  • Mandatory: SIEM Based Trainings, FortiSOAR Training.
  • Preferred: GCIH Certified, Incident Handler Training, Linux+, Security+, CCNA, CCNA Security, FortiSOAR Certification.

Responsibilities

  • Real-Time Monitoring: Provide continuous 24/7 oversight of security events and alerts.
  • Triage & Prioritization: Manage and categorize alerts from SIEM, Anti-DDoS, and other security solutions based on urgency and risk.
  • Incident Response Operations: Lead technical response activities, including host triage, containment, and recovery.
  • Remediation & Analysis: Conduct remote system analysis and implement remediation efforts using strong correlation skills.
  • Lifecycle Management: Maintain the full incident response lifecycle and ensure all actions adhere to established SLAs (Service Level Agreements).
  • SOAR Optimization: Identify opportunities for automation in manual workflows and design automated playbooks and modules in the SOAR platform.
  • Threat Analysis: Apply a detailed understanding of the MITRE ATT&CK Framework to identify and map attacker techniques.
  • Threat Intelligence: Analyze global threat landscapes, including cyber threat intelligence, new vulnerabilities, and exploit code to stay ahead of adversaries.
  • Vulnerability Assessment: Study vulnerabilities and provide technical recommendations for corrective actions and reporting.
  • Platform Mastery: Maintain deep knowledge of Security Technologies, Operating Systems (Windows & Linux), and deep-packet analysis tools like Wireshark.
  • Log Analysis: Utilize extensive experience in log correlation and analysis to detect and investigate suspicious patterns.
  • Incident Documentation: Ensure all findings, communication, and mitigation steps are thoroughly recorded in the ticketing system.

Skills

Real-Time Monitoring
Triage & Prioritization
Incident Response
Remediation & Analysis
Threat Analysis
Threat Intelligence
Vulnerability Assessment
Log Analysis
KQL Queries
Windows & Linux
FortiSOAR

Education

BSc in Computer Science, Electrical/Computer/Software Engineering

Tools

FortiSOAR
ArcSight
Microsoft Sentinel
Wireshark

Job description

Job Description

We are seeking a technical SOC Specialist with 3-5 years' experience to drive high-level

Job Description

We are seeking a technical SOC Specialist with 3-5 years' experience to drive high-level incident response and threat detection within our 24/7 Security Operations Center. This role is responsible for the full incident lifecycle—from initial triage and traffic analysis to host recovery and remediation. The ideal candidate combines deep knowledge of Windows/Linux environments with the ability to design automated SOAR playbooks that enhance our defensive posture.

Responsibilities
Incident Management & Response
  • Real-Time Monitoring: Provide continuous 24/7 oversight of security events and alerts.
  • Triage & Prioritization: Manage and categorize alerts from SIEM, Anti-DDoS, and other security solutions based on urgency and risk.
  • Incident Response Operations: Lead technical response activities, including host triage, containment, and recovery.
  • Remediation & Analysis: Conduct remote system analysis and implement remediation efforts using strong correlation skills.
  • Lifecycle Management: Maintain the full incident response lifecycle and ensure all actions adhere to established SLAs (Service Level Agreements).
Security Automation & Intelligence
  • SOAR Optimization: Identify opportunities for automation in manual workflows and design automated playbooks and modules in the SOAR platform.
  • Threat Analysis: Apply a detailed understanding of the MITRE ATT&CK Framework to identify and map attacker techniques.
  • Threat Intelligence: Analyze global threat landscapes, including cyber threat intelligence, new vulnerabilities, and exploit code to stay ahead of adversaries.
  • Vulnerability Assessment: Study vulnerabilities and provide technical recommendations for corrective actions and reporting.
Technical Expertise & Maintenance
  • Platform Mastery: Maintain deep knowledge of Security Technologies, Operating Systems (Windows & Linux), and deep-packet analysis tools like Wireshark.
  • Log Analysis: Utilize extensive experience in log correlation and analysis to detect and investigate suspicious patterns.
  • Incident Documentation: Ensure all findings, communication, and mitigation steps are thoroughly recorded in the ticketing system.
Qualifications

BSc in Computer Science, Electrical/Computer/Software Engineering.

Mandatory

SIEM Based Trainings, FortiSOAR Training

Preferred

GCIH Certified, Incident Handler Training, Linux+, Security+, CCNA, CCNA Security, FortiSOAR Certification

  • Thorough experience in Security Operations Center environment.
  • Experience in handling Cyber Security Incidents.
  • Experience with SIEM technologies such as ArcSight, Microsoft Sentinel, etc. and Threat Intelligence Platform.
  • Expertise in gauging automation potential in SOC manual processes/workflows and designing their transformation into automated SOC/IR playbooks and Modules within FortiSOAR.
  • Understanding the global threat landscape by analyzing cyber threat intelligence.
  • Extensive experience in Incident Response activities and skilled in Log Analysis.
  • Ability to write and execute complex queries using KQL (Kusto Query Language)
  • Experience with Anti-DDoS solutions, preferably at a Service Provider level.
  • Monitoring experience of security tools like SIEM, Anti-DDoS, IPS, EDR, firewalls, and MFA systems.
  • Flexible to work in shifts and willing to assist team overtime if needed.
  • Sound understanding of common network services (Web, Mail, FTP, DNS etc.), network vulnerabilities and network attack patterns.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Good co India • United Arab Emirates

On-site
AED 180,000 - 300,000
Security Operations Lead
Security Operations Lead

Good co India • United Arab Emirates

On-site
AED 350,000 - 750,000
Senior Engineer – SOC (SOAR)
Senior Engineer – SOC (SOAR)

CPX • Abu Dhabi

On-site
AED 350,000 - 550,000
Analyst - Security Operations
Analyst - Security Operations

Core42 • Dubai

On-site
AED 200,000 - 320,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site
SOC Incident Response & Automation Engineer
SOC Incident Response & Automation Engineer

e& UAE • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior SOC Analyst
Senior SOC Analyst

CPX • Abu Dhabi

On-site
AED 120,000 - 180,000
Lead Consultant - Incident Response
Lead Consultant - Incident Response

CPX • Abu Dhabi

On-site
AED 300,000 - 540,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Intertec Systems • Dubai

On-site
AED 134,000 - 223,000
Lead SOC Engineer (Devops)
Lead SOC Engineer (Devops)

CPX • Abu Dhabi

On-site
AED 330,517 - 440,690