Expert Engineer/Security Operation Centre

e& UAE

Abu Dhabi

On-site

AED 400,000 - 660,000

Full time

44 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

e& UAE is seeking a senior security professional to lead incident response, host-level investigations, and comprehensive digital forensics across on-premises and cloud environments. You will proactively hunt threats, develop playbooks, and produce actionable reports for security teams and management.

Required are 6+ years in DFIR/IR/Threat Hunting, strong skills with Windows/Linux logs, and certifications (SANS/GCFA/GCFE/GCIH). Experience with Microsoft Sentinel and Splunk preferred.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field (or equivalent work experience)
  • Investigation background must include host-level investigations, not just EDR/SIEM
  • Hands-on experience with Windows and Linux environments and log analysis
  • Strong hands-on experience with Incident Response and Digital Forensics
  • Practical end-to-end investigation/case handling exposure
  • Docker OR Kubernetes
  • DFIR related certifications
  • SANS certifications (GCFA/GCFE/GCIH preferred)
  • 6+ years in digital forensics, incident response, or threat hunting
  • Expertise in Digital Forensics, Incident Response, and Threat Hunting

Responsibilities

  • Monitor and analyze threat intelligence to stay informed on threats and vulnerabilities
  • Conduct forensic investigations for cybersecurity incidents including data breaches and APTs
  • Use forensic tools to collect and analyze evidence with chain-of-custody
  • Analyze security events from SIEM, IDS/IPS, firewalls, EDR, and network data
  • Develop advanced threat-hunting queries and custom searches to detect evasion
  • Perform host-based forensics on Windows, Linux, macOS, and mobile devices
  • Perform network forensics using NDR and Security Onion
  • Initial malware analysis to assess risk
  • Hunt for IOCs and TTPs to identify adversaries
  • Build and refine threat-hunting playbooks and runbooks
  • Communicate findings via reports and presentations to security teams and stakeholders
  • Experience with FTK, EnCase, Oxygen, Cellebrite, etc.
  • Develop remediation strategies for compromised environments
  • Develop scripts to automate security log analysis
  • Conduct cloud incident response across Azure & AWS
  • Map threats using MITRE ATT&CK framework
  • Ensure incidents close per SLA requirements

Skills

Incident Response
Digital Forensics
Threat Hunting
KQL
Windows & Linux logs analysis
DFIR certifications
SANS certifications

Education

Bachelor’s degree in Cybersecurity, Computer Science, or related field

Tools

Docker
Kubernetes
Microsoft Sentinel
Splunk

Job description

Job Description

Responsible for incident response efforts, host-level investigations, conducting comprehensive forensic investigations and proactively hunting for threats within the network and systems and remediate security incidents.

Job Description

Responsible for incident response efforts, host-level investigations, conducting comprehensive forensic investigations and proactively hunting for threats within the network and systems and remediate security incidents.

Responsibilities
  • Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities.
  • Conduct forensic investigations for cybersecurity incidents, including data breaches, advanced persistent threats (APT), ransomware, and insider threats.
  • Utilize forensic tools and techniques to collect and analyze evidence, ensuring secure evidence handling and chain of custody for compliance with legal and regulatory standards.
  • Conduct in-depth analysis of security events from multiple sources, such as SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data.
  • Develop and execute advanced threat-hunting queries and custom searches to detect malicious activities that may evade standard detection systems and improve detection rules.
  • Conduct host-based forensic analyses across various platforms, including Windows, Linux, macOS, and mobile devices.
  • Conduct network-based forensics using platforms such as NDR, Security Onion.
  • Conduct initial malware analysis to assess potential risks.
  • Proactively hunt for threats in the organization’s network by identifying Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) used by adversaries.
  • Build and refine threat-hunting playbooks and runbooks to standardize and enhance threat-hunting operations.
  • Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders.
  • Experience with Forensic Tools such as FTK, Encase, Oxygen, Cellebrite, etc.
  • Develop the remediation strategies for compromised environments.
  • Develop custom scripts to automate the security log analysis.
  • Conduct cloud incident response across Azure & AWS.
  • Utilize the MITRE ATT&CK framework to map detected threats and enhance threat-hunting capabilities.
  • Ensure timely closure of incidents in compliance with SLA requirements.
Qualifications
Mandatory
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field (or equivalent work experience)
  • Investigation background can't just be focused on EDR and SIEM tools. NEED exposure to Host-Level Investigations.
  • Hands-on experience with Windows and Linux environments, can read and explain Windows or Linux logs effectively.
  • Strong hands-on experience with Incident Response and Digital Forensics.
  • Practical Investigation experience (end-to-end case handling or evidence processing exposure).
  • Docker OR Kubernetes.
  • DFIR related certifications.
  • Possess relevant SANS certifications, and preferably have experience working with SIEM platforms such as Microsoft Sentinel and Splunk.
  • Ability to write and execute complex queries using KQL (Kusto Query Language) .
  • SANS GCFA, GCFE & GCIH.
  • Minimum 6 years of experience in in digital forensics, incident response, or threat hunting.
  • Expertise in Digital Forensics, Incident Response, and Threat Hunting.
Preferred
  • Strong knowledge of forensic tools such as EnCase, FTK, Oxygen, Cellebrite, Volatility, and other forensics analysis tools.
  • Experience with cloud forensics for platforms such as AWS & Microsoft Azure.
  • Skilled in scripting (e.g., Python, PowerShell) for automation of forensics and incident response tasks
  • Knowledge of the MITRE ATT&CK framework for categorizing and responding to adversarial techniques
  • Ability to communicate complex technical findings effectively to both technical and non-technical audiences
  • Strong analytical and problem-solving skills, with attention to detail and accuracy
  • Self-driven and able to work effectively in high-stress situations, handling multiple incidents simultaneously
  • Demonstrated ability to work both independently and collaboratively within a team
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Consultant - Incident Response CPX
Lead Consultant - Incident Response CPX

CPX • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior Consultant - Incident Response (CPX)
Senior Consultant - Incident Response (CPX)

CPX Piceance • Abu Dhabi

On-site
AED 300,000 - 520,000
Lead Consultant - Incident Response (CPX)
Lead Consultant - Incident Response (CPX)

CPX Piceance • Abu Dhabi

On-site
AED 250,000 - 450,000
Senior Consultant - Incident Response CPX
Senior Consultant - Incident Response CPX

CPX • Abu Dhabi

On-site
AED 300,000 - 480,000
Senior Consultant - Incident Response (CPX)
Senior Consultant - Incident Response (CPX)

CPX • Abu Dhabi

On-site
AED 250,000 - 350,000
Security Engineer DFIR Lab
Security Engineer DFIR Lab

CPX • Abu Dhabi

On-site
AED 300,000 - 540,000
DFIR Analyst
DFIR Analyst

CyberGate Defense • Abu Dhabi

On-site
AED 150,000 - 200,000
Engineer/Incident Management
Engineer/Incident Management

e& UAE • Abu Dhabi

On-site
AED 240,000 - 360,000
Senior Manager - Incident Response (CPX)
Senior Manager - Incident Response (CPX)

CPX Piceance • Abu Dhabi

On-site
AED 350,000 - 700,000
Expert Engineer/Security Operation Centre
Expert Engineer/Security Operation Centre

Forensic Focus • Abu Dhabi

On-site
AED 350,000 - 550,000