Senior Engineer – SOC (SIEM)

CPX

Abu Dhabi

On-site

AED 223,000 - 234,000

Full time

22 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CPX in Abu Dhabi is seeking a Senior SOC Engineer to manage Splunk SIEM and UEBA within the Security Operations Center. You will onboard new log sources, optimize telemetry, apply CIM-compliant data normalization, and drive SIEM performance improvements.

The ideal candidate has at least 5 years in SOC, Splunk SIEM experience, SPL proficiency, and relevant cloud certifications; excellent communication, and the ability to lead initiatives and work independently in a fast-paced environment.

Qualifications

  • Bachelor's degree in computer science, information technology, cybersecurity, or a related field.
  • Splunk Certified Administrator.
  • Mastery of SPL (Search Processing Language) for complex queries, dashboards, and reports.
  • Cloud-related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.
  • Certified Information Systems Security Professional (CISSP), GIAC is preferred.
  • Excellent communication and documentation skills.
  • Ability to lead technical initiatives and work independently.
  • A minimum of 5 years of experience in SOC operations, with significant experience in Splunk SIEM management.
  • Prior experience in a technical role within a SOC or similar cybersecurity environment.

Responsibilities

  • Manage Splunk SIEM services within the SOC environment.
  • Implement scalable Splunk-based SIEM solutions following best practices.
  • Define data ingestion strategies, parsing logic, and correlation rules.
  • Onboard new log sources and ensure proper integration with Splunk SIEM.
  • Monitor and maintain critical log sources; troubleshoot and resolve issues promptly.
  • Optimize telemetry for improved data collection, correlation, and reporting.
  • Collaborate with SOC and threat intelligence teams to develop detection use cases.
  • Create dashboards, alerts, and reports for proactive threat monitoring.
  • Perform system updates, version upgrades, and feature rollouts.
  • Ensure CIM compliance, field extractions, and data normalization.
  • Maintain SIEM performance and troubleshoot Splunk-related issues.
  • Evaluate and deploy Splunk apps and add-ons as needed.
  • Document SIEM workflows, configurations, and operational procedures.
  • Support continuous process improvements to enhance SOC efficiency. Work cross-functionally with IT, DevOps, and security teams.

Skills

Splunk SIEM
SPL mastery
Threat detection
Communication skills
Independent work

Education

Bachelor's degree in CS/IT/Cybersecurity or related field

Tools

Splunk
AWS Cloud Certification
GCP Cloud Certification
Azure Cloud Certification
CISSP
GIAC

Job description

Important Note: -Given the urgency of this position, the recruitment process has been accelerated. Interviews are progressing actively, with all candidate assessments expected to be completed over the next two weeks.

Salary - AED 20,000 - AED 21,0000 per month

Duration - 1 year (can be extendable)

Required Notice Period -Immediate or max 1 month

Education - Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.

Mandate Requirement:-

Skills/Certifications (Technical & Non-Technical)

  • Splunk Certified Administrator.
  • Mastery of SPL (Search Processing Language) for complex queries, dashboards, and reports.
  • Cloud-related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.
  • Certified Information Systems Security Professional (CISSP), GIAC is preferred.
  • Excellent communication and documentation skills
  • Ability to lead technical initiatives and work independently
  • A minimum of 5 years of experience in SOC operations, with significant experience in Splunk SIEM management.
  • Prior experience in a technical role within a SOC or similar cybersecurity environment.

The Senior SOC Engineer is responsible for managing SIEM services within the Security Operations Center, with a primary focus on Splunk SIEM and Splunk UEBA. This role involves onboarding new log sources, optimizing telemetry, ensuring system updates, troubleshooting issues, and maintaining SIEM performance. Additionally, the engineer will support SIEM architecture improvements and deployments aligned with business requirements.

Key Responsibilities:
  • Manage Splunk SIEM services within the SOC environment.
  • Implement scalable Splunk-based SIEM solutions following best practices.
  • Define data ingestion strategies, parsing logic, and correlation rules.
  • Onboard new log sources and ensure proper integration with Splunk SIEM.
  • Monitor and maintain critical log sources; troubleshoot and resolve issues promptly.
  • Optimize telemetry for improved data collection, correlation, and reporting.
  • Collaborate with SOC and threat intelligence teams to develop detection use cases.
  • Create dashboards, alerts, and reports for proactive threat monitoring.
  • Perform system updates, version upgrades, and feature rollouts.
  • Ensure CIM compliance, field extractions, and data normalization.
  • Maintain SIEM performance and troubleshoot Splunk-related issues.
  • Evaluate and deploy Splunk apps and add-ons as needed.
  • Document SIEM workflows, configurations, and operational procedures.
  • Support continuous process improvements to enhance SOC efficiency. Work cross-functionally with IT, DevOps, and security teams.
Characteristics:
  • Profound knowledge and hands-on experience with Splunk SIEM, UEBA and other related technologies like CRIBL.
  • Understanding of SOC workflows, MITRE ATT&CK framework, and threat detection methodologies.
  • Ability to correlate data across multiple sources to identify patterns and anomalies.
  • Strong understanding of cloud and network technologies, essential for efficient log source onboarding.
  • Proven technical capabilities in a complex, fast-paced SOC environment.
  • Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.
  • Strong understanding of SOC operations, cybersecurity principles, and best practices.
  • Excellent problem-solving skills and the ability to make decisions under pressure.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead SOC Engineer SIEM CPX
Lead SOC Engineer SIEM CPX

TALENTMATE • Abu Dhabi

On-site
AED 350,000 - 600,000
Senior SOC Engineer: Splunk SIEM & Threat Detection Lead
Senior SOC Engineer: Splunk SIEM & Threat Detection Lead

CPX • Abu Dhabi

On-site
AED 223,000 - 234,000
Security Operations Center Analyst (SOC Analyst)
Security Operations Center Analyst (SOC Analyst)

CPX • Abu Dhabi

On-site
AED 167,000 - 179,000
SOC L1 Analyst – SIEM Integration (Emirati National Only)
SOC L1 Analyst – SIEM Integration (Emirati National Only)

Talents Of Endearment Careers • Dubai

Remote
AED 180,000 - 300,000
Remote work support
Career development for Emirati talent
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Client of ITHR 360° CONSULTING FZE • Dubai

On-site
AED 240,000 - 360,000
SIEM Security Analyst SOC L3 Analyst
SIEM Security Analyst SOC L3 Analyst

Epergne Solutions • Dubai

On-site
AED 180,000 - 300,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

CPX • Abu Dhabi

On-site
AED 550,000 - 750,000
SOC L1 Analyst – SIEM Integration (Emirati National Only)
SOC L1 Analyst – SIEM Integration (Emirati National Only)

Talents of Endearment • Dubai

On-site
AED 100,000 - 167,000
Career growth potential
Emirati talent development program
Hands-on SIEM exposure
SOC Specialist - Cyber Threats
SOC Specialist - Cyber Threats

DiceTek UAE • Al Ruways Industrial City

On-site
SIEM Security Analyst
SIEM Security Analyst

Epergne Solutions • Dubai

On-site
AED 240,000 - 360,000