Senior Security Analyst - 24x7 SOC (Abu Dhabi)

Core42

United Arab Emirates

On-site

AED 300,000 - 540,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive Salary
Yearly Bonus
Exclusive Discounts (Esaad/Fazaa)
Premium Health Insurance
Learning & Development

Job summary

Core42 is seeking a Senior Security Analyst to anchor the 24x7 SOC in Abu Dhabi. You will own incidents end-to-end from detection to recovery, triage threats detected in Splunk, tune detections and mentor junior analysts across private-cloud and enterprise services.

The role requires 5–8 years in security operations and strong scripting capabilities. You will work with Splunk, Cribl, Elastic Security, Corelight, and a private-cloud stack (OpenStack/OpenShift).

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
  • 5-8 years in security operations, incident response or SOC monitoring, with at least 2 years at a senior level
  • Proven hands-on experience with Splunk Enterprise / Splunk Cloud - advanced SPL, dashboard development, correlation searches, alert creation and tuning, and administration
  • Demonstrated experience with Cribl Stream / Cribl Edge - log routing, parsing, filtering, enrichment and pipeline management
  • Strong background in incident analysis, investigation, evidence handling, escalation management and full-lifecycle response aligned with industry standards, including playbook and SOP development and RCA
  • Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation and response
  • Threat frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain and Diamond Model
  • Familiarity with private-cloud and platform log sources: Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
  • ServiceNow, Jira or equivalent ticketing/case management for incident tracking, evidence attachment, escalation notes and closure documentation
  • Preferred certifications: Splunk Core Certified/ Admin, Cribl Certified Admin, GIAC GCIA/GCIH/GCDA/GCFA, BT Level 2; OpenStack and Kubernetes/OpenShift familiarity
  • Familiarity with detection-as-code practices (version control and peer review of detection content)

Responsibilities

  • Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
  • Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
  • Serve as the senior escalation point for front‑line analysts, providing investigative guidance and validating findings before escalation
  • Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise
  • Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post‑incident review
  • Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
  • Lead the response on assigned incidents and coordinate cross‑team activity to ensure timely investigation, escalation and resolution
  • Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident
  • Create, tune and optimise Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
  • Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
  • Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic
  • Support onboarding of new log sources and validate log quality, parsing, field extraction and normalisation
  • Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalisation, optimising data flow and Splunk licence consumption
  • Conduct hypothesis‑driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
  • Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
  • Apply threat intelligence and frameworks to enrich investigations and improve detection and response
  • Identify patterns, trends and indicators of compromise to proactively detect and prevent recurrence
  • Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
  • Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned
  • Contribute to the continuous improvement of security monitoring use cases and detection rules
  • Support audit and compliance requirements by providing evidence of incident-management activities
  • Operate within a 24x7 SOC, participating in rotational day, evening and night shifts, including weekends and public holidays on a rotational basis
  • Meet defined acknowledgement, triage and escalation SLAs on each shift and complete structured shift handovers to maintain continuity of in‑flight incidents

Skills

Security operations
Incident response
Splunk
Cribl
EDR/NDR
MITRE ATT&CK
Networking basics
Windows
Linux
Python
Automation
OpenStack
OpenShift
ServiceNow/Jira
Detection engineering

Education

Bachelor's degree in Computer Science, Information Security, Cybersecurity or related field

Tools

Splunk
Cribl
Elastic Security
Corelight
OpenStack
OpenShift

Job description

Core42 is seeking a Senior Security Analyst to anchor the 24x7 SOC in Abu Dhabi. You will own incidents end-to-end from detection to recovery, triage threats detected in Splunk, tune detections and mentor junior analysts across private-cloud and enterprise services.

The role requires 5–8 years in security operations and strong scripting capabilities. You will work with Splunk, Cribl, Elastic Security, Corelight, and a private-cloud stack (OpenStack/OpenShift).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Core42 • United Arab Emirates

On-site
AED 300,000 - 540,000
Competitive Salary
Yearly Bonus
Exclusive Discounts (Esaad/Fazaa)
+2
SOC L2 Analyst: Advanced Threat Hunter & Incident Lead
SOC L2 Analyst: Advanced Threat Hunter & Incident Lead

Keka Technologies Private Limited • Abu Dhabi

On-site
AED 200,000 - 320,000
Advanced SOC Analyst: Incident Response & Threat Hunting
Advanced SOC Analyst: Incident Response & Threat Hunting

Innovative Solutions SA • Abu Dhabi

On-site
AED 180,000 - 300,000
Senior SOC Engineer: Splunk SIEM & Threat Detection Lead
Senior SOC Engineer: Splunk SIEM & Threat Detection Lead

CPX • Abu Dhabi

On-site
AED 223,000 - 234,000
Senior SOC Analyst: Threat Monitoring & Incident Response Lead
Senior SOC Analyst: Threat Monitoring & Incident Response Lead

CPX • Abu Dhabi

On-site
AED 201,000 - 212,000
SOC Threat Monitoring & Incident Response Specialist
SOC Threat Monitoring & Incident Response Specialist

Dicetekuae • United Arab Emirates

On-site
AED 201,000 - 335,000
Senior SOC Analyst
Senior SOC Analyst

CPX • Abu Dhabi

On-site
AED 201,000 - 212,000
Security Operations Center Analyst (SOC Analyst)
Security Operations Center Analyst (SOC Analyst)

CPX • Abu Dhabi

On-site
AED 167,000 - 179,000
SOC Team Lead (Tier 1)
SOC Team Lead (Tier 1)

Recenso • Abu Dhabi

On-site
AED 200,000 - 250,000
Professional development opportunities
Leadership roles
Collaborative environment
L2 SOC Engineer (UAE National)
L2 SOC Engineer (UAE National)

Talents of Endearment • Abu Dhabi

On-site
AED 201,000 - 234,000
Competitive salary (AED)
Career growth opportunities
Collaborative environment