Senior Security Operations Engineer (Security Operations & AI-Driven Defense)

Deriv

Dubai

On-site

AED 420,000 - 660,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Deriv is building an autonomous security operations platform that hunts proactively, responds automatically, and learns continuously. In production, we already deploy automated security reviews on every PR and fraud models running in real time.

Join a security team protecting a distributed system processing transactions 24/7, enforcing Zero Trust, and maturing cloud configurations across AWS, GCP, and Azure. You’ll lead detection, response, and hardening at scale.

Qualifications

  • 8+ years in security operations or blue team work.
  • You can write custom detection rules and tune thresholds to reduce false positives.
  • You automate repetitive tasks with Python, Bash, or Terraform.
  • You have experience with ML-based anomaly detection or UEBA.
  • You have secured cloud environments at scale (AWS, GCP, or Azure).

Responsibilities

  • Develop early-detection logic by extending SIEM rules and AI baselines.
  • Run threat hunts using behavior analytics, log forensics, and threat intel.
  • Tune EDR/XDR configurations to reduce noise and improve attack visibility.
  • Lead automation of incident response with runbooks and workflows.
  • Collaborate with engineering to integrate security controls into CI/CD pipelines.

Skills

Security operations
Threat hunting
Incident response
Automation scripting (Python/Bash/Ter​
Cloud security (AWS/GCP/Azure)

Tools

SIEM
EDR/XDR
Okta
Azure AD
Terraform

Job description

We’re not hiring a security engineer to keep up with threats. We’re hiring someone to make threats irrelevant before they become incidents.

Most security teams react. They tune SIEM rules after the alert fires. They write playbooks after the incident closes. They patch after the scan flags. At Deriv, we’re building an autonomous security operations platform that hunts proactively, responds automatically, and learns continuously. Real money, real regulations, real consequences — and a security function built to match.

Why This Matters

Deriv’s mission is Trading for Anyone, Anywhere, Anytime. Millions of traders across the globe, around the clock, across regulatory environments. At this scale, a misconfigured WAF rule or undetected lateral movement isn’t a technical inconvenience — it’s a trader’s funds at risk and a regulator on the phone.

Our Security Operations team isn’t defending a perimeter. We’re protecting a living, distributed system that processes transactions 24/7. When the threat surface never sleeps, your detection and response capabilities can’t either — which is exactly why we’re embedding AI and automation at every layer of the security stack.

Why Deriv

We’re already in production, not planning:

  • Automated security review on every pull request — continuous code-level scanning, not quarterly audits
  • Dozens of fraud detection models running continuously in production, protecting real transactions at scale
  • AI-driven anomaly detection across identity, endpoint, and network telemetry
  • 400+ internal users on our workflow orchestration platform — including security response workflows
Scope of Work

You’ll own outcomes across Security Operations with focus on four areas:

  • Threat Detection & Response — SIEM optimisation, EDR/XDR tuning, incident investigation, threat hunting
  • AI-Driven Defence — Anomaly detection models, UEBA, automated triage, phishing detection pipelines
  • Security Hardening — Cloud security posture (AWS, GCP, Azure), WAF/CDN configuration, SSO and IAM policy enforcement
  • Cross-functional Security — Integrating controls into engineering workflows, CI/CD pipelines, and DevOps processes
What You’ll Do
Detect and Hunt
  • Build detection logic that fires early: Extend SIEM custom rules, AI-powered anomaly baselines, and automated alert enrichment that reduce noise and surface what matters.
  • Run threat hunts with hypotheses, not hunches: Use behavioural analytics, log forensics, and threat intelligence to surface adversarial activity hiding below the alert threshold.
  • Tune signal, not noise: Optimise EDR/XDR configurations to cut false positives and make attack visibility actionable — not overwhelming.
Automate the Response
  • Replace manual triage with intelligent playbooks: Build incident response automation that contains threats in minutes, not hours.
  • Encode institutional knowledge into systems: When a senior analyst’s six-step response becomes a runbook, you turn it into a workflow that runs at 3am without them.
  • Ship real-time visibility: Build automated dashboards tracking detection coverage, active incidents, misconfiguration trends, and policy compliance — for the team and for leadership.
Harden the Perimeter
  • Review configurations before attackers do: Run security assessments across cloud, endpoint, network, and application layers — mapping gaps against MITRE ATT&CK, CIS, and NIST benchmarks.
  • Enforce Zero Trust in practice, not just policy: Work with IT and Engineering to close IAM gaps, apply least privilege across cloud workloads, and strengthen MFA and conditional access controls.
  • Protect the build pipeline: Ensure container security, CI/CD guardrails, and automated compliance scanning prevent vulnerabilities from reaching production.
Who You Are
  • 8+ years in security operations — incident response, threat detection, or blue team work. You know what attacks actually look like in logs, not just textbooks.
  • Your SIEM is a weapon, not a logging system: You write custom detection rules, tune thresholds, and build correlation logic. You’ve reduced false positives by an order of magnitude at least once.
  • You automate before you elevate: Python, Bash, or Terraform is how you respond to repetitive problems. When a manual step happens twice, you script it the third time.
  • You understand AI’s role in security — and its limits: You’ve worked with ML-based anomaly detection, UEBA, or AI-driven phishing models. You know where they catch things humans miss, and where they need guardrails.
  • You secure cloud environments at scale: AWS, GCP, or Azure — you’ve reviewed posture, implemented compliance scanning, and closed misconfigurations before they became incidents.
  • You communicate risk, not just findings: You translate technical exposure into decisions that reach engineering leads and executives without losing accuracy.
  • Certifications are a signal, not a requirement: CISSP, GSEC, AWS Security Specialty, or equivalent. What matters is what you’ve actually built and stopped.
Tech Stack
  • Languages & Automation: Python, Bash, Terraform
  • SIEM / Detection: Custom rule logic, AI-driven anomaly baselines, automated alert triage
  • Endpoint: EDR/XDR platforms, UEBA, behavioural analytics
  • Identity & Access: Okta, Google Workspace, Azure AD — SSO, MFA, conditional access
  • Cloud: AWS, GCP, Azure — security posture management, automated compliance scanning
  • Perimeter: WAF/CDN hardening, API abuse prevention, bot mitigation
The Honest Reality

This is demanding work. You’ll build systems that catch threats your colleagues haven’t seen yet — and raise findings that aren’t always welcome. You’ll tune detections where a 1% miss rate means real exposure in a regulated environment. You’ll balance moving fast in engineering culture with the security controls that make speed sustainable.

But you’ll build security operations that actually catch things — continuously, automatically, at scale. Automated security review already ships on every PR. Fraud models run in production. The investment in AI-driven defence is real, not a slide deck.

If you want to maintain existing tools and respond to tickets, this isn’t it. If you want to build security systems that render entire threat categories obsolete, it might be.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Deriv • Dubai

On-site
AED 260,000 - 420,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Deriv • Dubai

On-site
AED 180,000 - 270,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Deriv.com • Dubai

Hybrid
AED 400,000 - 720,000
Senior SOC Analyst
Senior SOC Analyst

Deriv.com • Dubai

On-site
AED 350,000 - 550,000
Senior Security Engineer – Vulnerability Management
Senior Security Engineer – Vulnerability Management

Deriv • Dubai

On-site
AED 164,000 - 328,000
Autonomous Security Operations Engineer: AI-Driven Defense
Autonomous Security Operations Engineer: AI-Driven Defense

Deriv • Dubai

On-site
AED 420,000 - 660,000
Compliance Technology Specialist
Compliance Technology Specialist

Deriv • Dubai

On-site
AED 180,000 - 300,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site
Compliance Technology Specialist at Deriv.com
Compliance Technology Specialist at Deriv.com

Deriv.com • Dubai

On-site
AED 180,000 - 240,000
Anti Fraud Manager
Anti Fraud Manager

Deriv • Dubai

On-site
AED 100,000 - 130,000