Information Security Specialist

NMC GROUP SERVICES.

Abu Dhabi

On-site

AED 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NMC GROUP SERVICES. is seeking a Cyber Security Operations Specialist responsible for managing intrusion detection systems and conducting vulnerability assessments. The ideal candidate will analyze network traffic for possible attacks and document incidents in line with our cybersecurity response plan.

The role demands a Bachelor's degree in IT or cyber security, alongside essential certifications like CompTIA Security+ and CISSP. A minimum of 3 years in cybersecurity operations is preferred, reinforcing the necessity for robust experience in the field.

Qualifications

  • 3 years of experience in cyber security operations.
  • Expertise in managing the Security Operations Center.
  • Understands security concepts like cyber-attacks, threats, and incident management.

Responsibilities

  • Manage network intrusion detection and prevention systems.
  • Conduct vulnerability assessments and suggest improvements.
  • Analyze network traffic for detection of intrusions.

Skills

SIEM/SOAR and Vulnerability Management tools
Sysadmin skills (Linux/Mac/Windows)
Programming skills (Python, Ruby, PHP, C, C#, Java, Perl)
Identifying trends in complex data sets
Detecting host and network-based intrusions
Conducting vulnerability scans
Applying analytical and problem-solving skills

Education

Bachelor’s degree in information technology or equivalent
CompTIA Security+
CISSP
GCFA
GCIH
GCIA
OSCP
CEH
CPT

Tools

Wireshark
Snort
tcpdump

Job description

Responsibilities
  • Manage network intrusion detection and prevention systems
  • Conduct periodic compromise assessments across selected networks and propose recommendations based on assessment results
  • Conduct physical security assessment of the organization s systems including servers and networks ensuring that any unauthorized external physical interference is not actually possible
  • Conduct ongoing network hunt activities
  • Conduct proactive vulnerability assessment across the network subnetworks and service traffic to identify potential points of intrusion
  • Research and develop methods of tracking and detecting malicious activity within a network
  • Develop tools, signatures and methods of detection for use in incident response activities
  • Develop SIEM integrations, dashboards and analytics to illuminate and visualize threat activity
  • Analyze network traffic to provide timely detection, identification and alerting of possible attacks, intrusions, anomalous activities and misuse activities and distinguish these incidents and events from benign activities
  • Use data collected from a variety of cyber defense tools (e.g., anti‑virus, IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments, perform cyber defense trend analysis and reporting and perform event correlation to mitigate threats and gain situational awareness and determine the effectiveness of an observed attack
  • Carry out triage to ensure that a genuine security incident is occurring
  • Coordinate with entity‑wide cyber defense staff to validate network alerts
  • Notify designated managers, cyber incident responders and cybersecurity service provider team members of suspected cyber incidents and articulate the event s history, status and potential impact for further action in accordance with the organization s cyber incident response plan
  • Document and elevate incidents including event s history, status and potential impact for further action that may cause ongoing and immediate impact to the environment
  • Provide daily summary reports of network events and activity relevant to cyber defense practices
  • Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools
  • Isolate and remove malware
  • Develop content for cyber defense tools, use them for continual monitoring and analysis of network activity to identify malicious activity
  • Assist in the construction of signatures which can be implemented on cyber defense tools in response to new or observed threats within the network environment
  • Analyze and report organizational security posture trends
  • Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus, Threat Intelligence Providers) to maintain updated of cyber defense threat condition and determine which security issues may have an impact on the enterprise
  • Provide cybersecurity recommendations based on significant threats and vulnerabilities
  • Provide advice and input for Disaster Recovery, Contingency and Continuity of Operational Plans
  • Collect and analyze intrusion artifacts (e.g., source code, malware, and system configuration) and use discovered data to enable mitigation of potential cyber incidents within the enterprise
  • Use specialized equipment and techniques to catalog, document, extract, collect, package and preserve digital evidence
  • Utilize deployable forensics toolkit to support operations as necessary
Knowledge
  • Security concepts such as cyber‑attacks and techniques, threat vectors, risk and threat management, incident management, etc.
  • Networking concepts and protocols, and network security attacks, vulnerabilities, processes, methodologies, access control mechanisms, traffic analysis methods.
  • Cyber threats and vulnerabilities and information dissemination sources (e.g., alerts and advisories).
  • Cyber defense and vulnerability assessment tools and their capabilities.
  • System and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross‑site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return‑oriented attacks, malicious code).
  • Scripting languages (e.g., Python, Perl, Bash) used in an incident response environment.
  • Incident response and handling methodologies.
  • Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) tools, applications, methodologies and techniques for detecting host and network‑based intrusions.
  • Threat investigations, reporting and investigative tools.
  • Cyber defense and information security policies, procedures, and regulations.
  • Common attack vectors, the different classes of attacks (e.g., passive, active, insider, close‑in, distribution attacks) and attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Cyber attackers (e.g., script kiddies, insider threat, non‑nation state‑sponsored, and nation‑sponsored), and attackers’ methodologies.
  • Signature implementation impact for viruses, malware, and attacks.
  • Windows/Unix ports and services.
  • Relevant laws, legal authorities, restrictions, and regulations pertaining to cyber defense activities.
  • Packet‑level analysis using appropriate tools (e.g., Wireshark, tcpdump).
  • Use of sub‑netting tools.
  • Penetration testing principles, tools, and techniques.
  • Investigation, auditing and forensics methods, processes, procedures and standards.
  • Different types of hardware, storage, imaging and file system analysis.
  • Data backup and recovery.
Skills
  • Using SIEM/SOAR and Vulnerability Management tools and services.
  • Sysadmin skills (Linux/Mac/Windows).
  • Programming skills (Python, Ruby, PHP, C, C#, Java, Perl, and more).
  • Identifying, analyzing and interpreting trends or patterns in complex data sets.
  • Developing and deploying signatures.
  • Detecting host and network‑based intrusions via intrusion detection technologies (e.g., Snort).
  • Using incident handling methodologies.
  • Collecting data from a variety of cyber defense resources.
  • Recognizing and categorizing types of vulnerabilities and associated attacks.
  • Performing packet‑level analysis.
  • Conducting trend analysis.
  • Using cyber defense reporting structure and processes.
  • Utilizing a combination of automated and manual testing methods.
  • Developing automated vulnerability testing scripts and using off‑the‑shelf vulnerability testing tools.
  • Conducting vulnerability scans and recognizing vulnerabilities in networks, systems and applications.
  • Using penetration testing tools and techniques.
  • Applying analytical and problem‑solving skills.
  • Ability to collaborate with other sections across the department to enhance detection capabilities.
  • Perform malware analysis.
  • Work closely with management to respond appropriately to the results of assessments and mitigation oversight of found vulnerabilities.
  • Perform data analysis, correlation, and analytics leveraging Security Information and Event Management (SIEM) tools.
  • Conduct vulnerability scans and recognize vulnerabilities in security systems & devices.
  • Accurately and completely source all data used in intelligence, assessment and/or planning products.
  • Apply techniques for detecting host and network‑based intrusions using intrusion detection technologies.
  • Interpret the information collected by network tools (e.g., Nslookup, Ping, and Traceroute).
  • Prepare and create regular reports to document any security breaches/ incidents.
  • Provide forensic support to Cyber Security Operations during the investigation of any detected threat or contained incident / event to determine root cause and propose response recommendations as required.
Education and Certification

Bachelor’s degree in an information technology, computer science, cyber security or equivalent work experience.

CompTIA Security+ / CISSP: Certified Information Systems Security Professional

GCFA: GIAC Certified Forensic Analyst

GCIH: GIAC Certified Incident Handler

GCIA: GIAC Certified Intrusion Analyst

OSCP: Offensive Security Certified Professional

CEH: Certified Ethical Hacker

CPT: Certified Penetration Tester

Experience

3 years of experience in cyber security operations with expertise in managing the Security Operations Center

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Security Operations Lead
Security Operations Lead

Good co India • United Arab Emirates

On-site
AED 350,000 - 750,000
Network Security Engineer
Network Security Engineer

Azizi Developments • Dubai

On-site
Senior SOC Analyst
Senior SOC Analyst

Good co India • United Arab Emirates

On-site
AED 180,000 - 300,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
Network & Information Security Officer
Network & Information Security Officer

GSSTech Group • Dubai

On-site
AED 201,000 - 335,000
ISO 27001 experience
Information Security Analyst
Information Security Analyst

Digital X - Owned By Digital Dewa Single Owner Com • Dubai

On-site
AED 80,000 - 120,000
Engineer/Incident Management
Engineer/Incident Management

e& UAE • Abu Dhabi

On-site
AED 180,000 - 260,000
Security Analyst
Security Analyst

Crescent Petroleum Company • Sharjah

On-site
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site