Incident Response Security Engineer

RecruitMe Plus

Dubai

On-site

AED 250,000 - 450,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RecruitMe Plus in Dubai seeks an Incident Response Security Engineer to lead host-based investigations and compromise assessments across Unix/Linux and Windows environments. You will analyze telecom protocols (SS7, SIP, Diameter, VoIP) and triage artifacts at scale, guiding containment and remediation of advanced threats within production telecom infrastructure.

Collaborating with operations teams, you will refine investigation playbooks, produce technical reports, and train SOC staff to

Qualifications

  • Experience in telecom incident response and protocols.
  • Hands-on host-based investigations on Unix/Linux and Windows.
  • Familiar with telecom signaling systems and related artifacts.
  • Experience with creating or using UAC scripts for data collection.

Responsibilities

  • Investigate security incidents in telecom environments across core network and signaling platforms.
  • Analyze incidents involving telecom protocols and systems (e.g., SS7, SIP, Diameter, VoIP, signaling infrastructure).
  • Lead deep host-based investigations on compromised systems.
  • Conduct advanced investigations on Unix/Linux-based systems and supporting services.
  • Lead and support compromise assessments to determine attacker presence, persistence, and lateral movement.
  • Execute large-scale artifact triage across enterprise Windows and Linux fleets.
  • Identify indicators of compromise (IOCs), attacker techniques, and affected assets.
  • Collect and analyze host artifacts such as logs, processes, memory, persistence mechanisms, and network connections.
  • Use and customize UAC (Unix-like Artifacts Collector) scripts for scalable evidence collection.
  • Ensure forensic soundness and proper evidence handling.
  • Recommend and execute containment strategies tailored to telecom infrastructure and production systems.
  • Support eradication of malicious artifacts and validate system integrity post-remediation.
  • Work closely with operations teams to minimize service disruption.
  • Threat Hunting & Proactive Detection: conduct proactive threat hunting across Unix/Linux and Windows systems using known TTPs and telecom-specific threat models.
  • Correlate host-based findings with network and signaling activity.
  • Incident Response Process & Playbooks: contribute to the development and refinement of incident response playbooks for telecom environments.
  • Improve investigation workflows for host-based and large-scale incident scenarios.
  • Reporting, Collaboration & Knowledge Transfer: produce clear technical reports detailing findings, impact, and remediation actions.
  • Brief stakeholders, SOC teams, and leadership on incident scope and risk.
  • Share investigation techniques and lessons learned to strengthen detection capabilities.

Skills

Telecommunications incident response
Unix-based investigations
Windows investigations
Artifact triage
Threat hunting

Tools

UAC scripts

Job description

About the job Incident Response Security Engineer

Position Overview:

Our client is seeking a highly skilled and detail-oriented Incident Response Security Engineer to join their team in Dubai. The ideal candidate will lead host-based investigations and compromise assessments across Unix/Linux and Windows environments, leveraging UAC and large-scale artifact triage to identify, contain, and remediate advanced threats within telecommunications infrastructures.

Key Responsibilities & Role:

  • Investigate security incidents within telecommunications environments, including core network, signaling, and service platforms.
  • Analyze incidents involving telecom protocols and systems (e.g., SS7, SIP, Diameter, VoIP, signaling infrastructure).
  • Perform deep host-based investigations on compromised systems.
  • Conduct advanced investigations on Unix/Linux-based systems and supporting services.
  • Lead and support compromise assessments to determine attacker presence, persistence, and lateral movement.
  • Execute large-scale artifact triage across enterprise Windows and Linux fleets.
  • Identify indicators of compromise (IOCs), attacker techniques, and affected assets.
  • Collect and analyze host artifacts such as logs, processes, memory, persistence mechanisms, and network connections.
  • Use and customize UAC (Unix-like Artifacts Collector) scripts for scalable evidence collection.
  • Ensure forensic soundness and proper evidence handling.
  • Recommend and execute containment strategies tailored to telecom infrastructure and production systems.
  • Support eradication of malicious artifacts and validate system integrity post-remediation.
  • Work closely with operations teams to minimize service disruption.

5. Threat Hunting & Proactive Detection:

  • Conduct proactive threat hunting across Unix/Linux and Windows systems using known TTPs and telecom-specific threat models.
  • Correlate host-based findings with network and signaling activity.

6. Incident Response Process & Playbooks:

  • Contribute to the development and refinement of incident response playbooks for telecom environments.
  • Improve investigation workflows for host-based and large-scale incident scenarios.

7. Reporting, Collaboration & Knowledge Transfer:

  • Produce clear technical reports detailing findings, impact, and remediation actions.
  • Brief stakeholders, SOC teams, and leadership on incident scope and risk.
  • Share investigation techniques and lessons learned to strengthen detection capabilities.

Qualifications & Skills:

  • Background in telecommunications incident response and is familiar with telecom concepts and protocols.
  • Prior investigation experience on Unix-based systems.
  • Investigation background with direct experience in host-based investigations.
  • Practical experience in using or customizing UAC script.
  • Prior experience in conducting compromise assessments and large-scale artifact triage across both Windows and Linux environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Telecom Incident Response Engineer: Unix/Linux Forensics
Telecom Incident Response Engineer: Unix/Linux Forensics

RecruitMe Plus • Dubai

On-site
AED 250,000 - 450,000
Incident Response Lead (DFIR) -Dubai, UAE
Incident Response Lead (DFIR) -Dubai, UAE

DeepSource Technologies • United Arab Emirates

On-site
AED 335,000 - 670,000
Incident Response Lead (DFIR) -Dubai, UAE
Incident Response Lead (DFIR) -Dubai, UAE

DeepSource • United Arab Emirates

On-site
AED 260,000 - 520,000
Compromise Management Analyst
Compromise Management Analyst

RecruitMe Plus • Dubai

On-site
AED 180,000 - 320,000
Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Lead Consultant - Incident Response
Lead Consultant - Incident Response

CPX • Abu Dhabi

On-site
AED 300,000 - 540,000
Telecom DFIR Analyst - Incident Response & Forensics
Telecom DFIR Analyst - Incident Response & Forensics

RecruitMe Plus • Dubai

On-site
AED 180,000 - 320,000
SIEM Integration Specialist
SIEM Integration Specialist

RecruitMe Plus • Dubai

On-site
Network & Information Security Engineer | Reach Group | UAE
Network & Information Security Engineer | Reach Group | UAE

Reach Group • United Arab Emirates

On-site
AED 120,000 - 180,000
Senior IT Security Analyst (Banking /Financial services exp)
Senior IT Security Analyst (Banking /Financial services exp)

Confidential Company • Dubai

On-site
AED 350,000 - 500,000