About Us
We offer dynamic solutions that create recruitment opportunities.
Role Overview
The SOC L1 Analyst (SIEM Integration Focus) supports real‑time security monitoring, log ingestion validation, and first‑level incident triage. The role blends SOC operations with SIEM onboarding and data quality assurance to strengthen enterprise threat visibility.
This position is exclusively open to Emirati Nationals, supporting national workforce development and compliance requirements.
Key Responsibilities
- Monitor SIEM dashboards, alerts, and correlation rules for potential security incidents.
- Validate log ingestion from firewalls, IDS/IPS, EDR/XDR, servers, cloud platforms, IAM, and network devices.
- Support onboarding of new log sources using Syslog, API, agents, connectors, and event hubs.
- Assist in maintaining parsers, field extractions, normalization rules, and basic detection use cases.
- Perform first‑level triage: classify alerts, elevate incidents, and document findings.
- Troubleshoot ingestion issues such as missing fields, timestamp errors, duplicate logs, and parsing failures.
- Coordinate with SOC L2/L3, security architects, and infrastructure teams for issue resolution.
- Ensure critical telemetry is available for investigations and threat monitoring.
- Maintain documentation for integration procedures, onboarding checklists, and runbooks.
Requirements
Required Skills & Knowledge
- Understanding of SIEM architecture, log flow, and event correlation.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, Elastic Security .
- Familiarity with security log types: Windows Event Logs, Linux syslog, firewall/proxy logs, AD logs, cloud audit logs, EDR telemetry.
- Basic hands‑on experience with log parsing, regex, JSON/XML formats, syslog protocols, and REST APIs.
- Foundational knowledge of MITRE ATT&CK, incident response, detection engineering, and threat monitoring.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, authentication protocols, and IAM concepts.
- Ability to analyze ingestion issues and support correlation troubleshooting.
Preferred Skills
- Exposure to cloud SIEM integrations (AWS, Azure, GCP).
- Familiarity with SOAR workflows.
- Understanding of compliance logging requirements (ISO 27001, PCI‑DSS, HIPAA, GDPR).
- Experience creating basic detections or use cases.
- Exposure to threat intelligence feed integration.
- Awareness of SIEM retention, storage, and licensing considerations.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, IT, or related field.
- 1–4 years of experience in SOC, SIEM operations, or log management.
- Relevant certifications (advantage):
- Microsoft Sentinel
- Splunk Core
- QRadar
- Security+ / CySA+
Benefits
- Opportunity to grow from SOC L1 to L2/L3 roles.
- Hands‑on exposure to enterprise SIEM integrations and detection engineering.
- Supportive environment for Emirati talent development in cybersecurity.