Senior SOC Engineer- SIEM (UAEN)

CPX

Abu Dhabi

On-site

AED 260,000 - 420,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CPX is seeking a Senior SOC Engineer to lead Splunk SIEM management within a fast‑paced SOC environment in Abu Dhabi. You will onboard log sources, optimize telemetry, and maintain CIM compliance while developing detection use cases with threat intel teams.

The role requires hands‑on Splunk experience, strong scripting capabilities, and cloud accreditation to support across IT and security functions. A keen eye for process improvements and customer interfacing is essential.

Qualifications

  • 3–5 years of experience in SOC operations, with significant experience in Splunk SIEM management.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.

Responsibilities

  • Manage Splunk SIEM services within SOC environment.
  • Implement scalable Splunk-based SIEM solutions following best practices.
  • Define data ingestion strategies, parsing logic, and correlation rules.
  • Onboard new log sources and ensure proper integration with Splunk SIEM.
  • Monitor and maintain critical log sources; troubleshoot issues promptly.
  • Collaborate with SOC and threat intel teams to develop detection use cases.
  • Create dashboards, alerts, and reports for proactive threat monitoring.
  • Perform system updates, version upgrades, and feature rollouts.
  • Ensure CIM compliance, field extractions, and data normalization.
  • Maintain SIEM performance and troubleshoot Splunk-related issues.
  • Evaluate and deploy Splunk apps/add-ons as needed.
  • Document SIEM workflows, configurations, and procedures.
  • Support continuous process improvements to enhance SOC efficiency.

Skills

Splunk
UEBA
CRIBL
SPL
Python
Bash
PowerShell
Cloud Certifications (AWS/GCP/Azure)
CISSP

Education

Bachelor's degree in Computer Science/IT/Cybersecurity

Tools

Splunk SIEM
Splunk UEBA

Job description

Overview

The Senior SOC Engineer is responsible for managing SIEM services within the Security Operations Center, with a primary focus on Splunk SIEM and Splunk UEBA. This role involves onboarding new log sources, optimizing telemetry, ensuring system updates, troubleshooting issues, and maintaining SIEM performance. Additionally, the engineer will support SIEM architecture improvements and deployments aligned with business requirements.

Responsibilities
  • Manage Splunk SIEM services within the SOC environment.
  • Implement scalable Splunk-based SIEM solutions following best practices.
  • Define data ingestion strategies, parsing logic, and correlation rules.
  • Onboard new log sources and ensure proper integration with Splunk SIEM.
  • Monitor and maintain critical log sources; troubleshoot and resolve issues promptly.
  • Optimize telemetry for improved data collection, correlation, and reporting.
  • Collaborate with SOC and threat intelligence teams to develop detection use cases.
  • Create dashboards, alerts, and reports for proactive threat monitoring.
  • Perform system updates, version upgrades, and feature rollouts.
  • Ensure CIM compliance, field extractions, and data normalization.
  • Maintain SIEM performance and troubleshoot Splunk-related issues.
  • Evaluate and deploy Splunk apps and add-ons as needed.
  • Document SIEM workflows, configurations, and operational procedures.
  • Support continuous process improvements to enhance SOC efficiency. Work cross-functionally with IT, DevOps, and security teams.
Characteristics
  • Profound knowledge and hands‑on experience with Splunk SIEM, UEBA and other related technologies like CRIBL.
  • Understanding of SOC workflows, MITRE ATT&CK framework, and threat detection methodologies.
  • Ability to correlate data across multiple sources to identify patterns and anomalies.
  • Strong understanding of cloud and network technologies, essential for efficient log source onboarding.
  • Proven technical capabilities in a complex, fast‑paced SOC environment.
  • Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.
  • Strong understanding of SOC operations, cybersecurity principles, and best practices.
  • Excellent problem‑solving skills and the ability to make decisions under pressure.
  • Ability to collaborate effectively with a variety of team members, including interfacing with customers to resolve issues.
  • High proficiency in written and verbal communication
Qualifications
Skills/Certifications (Technical & Non-Technical)
  • Splunk Certified Administrator.
  • Mastery of SPL (Search Processing Language) for complex queries, dashboards, and reports.
  • Scripting skills (Python, Bash, PowerShell)
  • Cloud‑related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.
  • Certified Information Systems Security Professional (CISSP), GIAC is preferred.
  • Excellent communication and documentation skills
  • Ability to lead technical initiatives and work independently
Minimum Work Experience
  • A minimum of 3-5 years of experience in SOC operations, with significant experience in Splunk SIEM management.
  • Prior experience in a technical role within a SOC or similar cybersecurity environment.
Education
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Engineer SIEM CPX
SOC Engineer SIEM CPX

CPX • Abu Dhabi

On-site
AED 180,000 - 320,000
SOC Engineer (SIEM) (CPX)
SOC Engineer (SIEM) (CPX)

Showcify, Inc. • Abu Dhabi

On-site
AED 180,000 - 240,000
SOC Engineer (SIEM)
SOC Engineer (SIEM)

CPX • Abu Dhabi

On-site
AED 120,000 - 180,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

Cpx Affiliate • Abu Dhabi

On-site
AED 260,000 - 520,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

CPX • Abu Dhabi

On-site
AED 300,000 - 420,000
Senior Security Engineer - Splunk Sentinel and Cribl
Senior Security Engineer - Splunk Sentinel and Cribl

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C • Dubai

On-site
AED 300,000 - 550,000
Senior Analyst - SOC Monitoring UAEN
Senior Analyst - SOC Monitoring UAEN

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Soc Analyst - L2
Soc Analyst - L2

Keka Technologies Private Limited • Abu Dhabi

On-site
AED 200,000 - 320,000
SOC SIEM Engineer - Splunk & Cribl Health & Onboarding
SOC SIEM Engineer - Splunk & Cribl Health & Onboarding

CPX • Abu Dhabi

On-site
AED 120,000 - 180,000
Senior Splunk SIEM Engineer | Threat Detection & SOC
Senior Splunk SIEM Engineer | Threat Detection & SOC

CPX • Abu Dhabi

On-site
AED 260,000 - 420,000