Apply Edge Start your job search

Expert Engineer/Security Operation Centre

e& UAE · Dubai, Dubai, United Arab Emirates

Apply & track with Apply Edge

Job DescriptionThe Subject Matter Expert – Security Operations Center (SOC) oversees advanced security monitoring and incident management activities within the Cyber Security function. This role serves as the primary escalation point for complex or high-severity security incidents, providing technical leadership and validation before handover to Incident Response teams.The SME leads deep-dive investigations using SIEM, IDS/IPS, firewalls, endpoint detection, and network telemetry, and applies frameworks such as MITRE ATT&CK and DEFEND to strengthen threat-hunting and detection coverage. The role is responsible for designing, tuning, and validating detection rules, developing and maintaining SOC playbooks and runbooks, and ensuring effective monitoring across hybrid infrastructures (on-prem, cloud, and telco cloud).In addition, the SME mentors SOC engineers, conducts trainings and technical workshops, drives automation opportunities (SOAR playbooks and workflows), and contributes to continuous improvement of SOC processes and content. The role also monitors threat intelligence, tracks emerging threats and vulnerabilities, and communicates findings through clear reports and presentations to security leadership and stakeholders. The SME may participate in RFP processes, providing technical input to help select best-fit security solutions.Responsibilities Serve as the primary contact for advanced security monitoring, threat detection, and investigation methodologies. Lead and supervise team members to ensure effective incident detection and response. Provide technical guidance and escalation support to SOC analysts for complex or high-severity incidents. Act as the final technical validation authority before escalating to Incident Response (IR) teams. Utilize the MITRE ATT&CK and DEFEND frameworks to map detected threats and enhance threat-hunting capabilities. Lead in-depth analysis of security events from multiple sources, such as SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data. Conduct deep-dive technical investigations for high-impact or ambiguous alerts. Identify gaps in detection coverage and recommend improvements. Continuously support the content development team by recommending detection rule tuning to reduce false positives and by proposing new advanced correlation rules, behavioral detections, and anomaly-based use cases. Develop and maintain SOC playbooks and runbooks to ensure consistent investigation standards. Ensure effective detection and monitoring across hybrid environments, including on-premises, cloud, and telco cloud. Support SOC shift staff in maintaining SLA compliance. Review and quality-check investigation reports before closure. Participate in major incident calls as the SOC technical lead. Conduct post-incident detection gap analysis. Mentor analysts and organize trainings to maintain team expertise. Develop knowledge articles, technical documentation, and use-case libraries. Lead internal technical workshops and purple-team collaboration exercises. Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities. Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders. Participate in the RFP process to provide technical recommendations and propose best-fit solutions. QualificationsFormal Education Required: Bachelor’s degree in Cybersecurity, Computer Science, or a related field (or equivalent work experience). Related Professional Training, Certification Or Membership Cybersecurity-related certification(s). Preferred CISM CISSP Microsoft Sentinel training Splunk training Years & Field Of Experience Required 8–10 years Job-Specific Competencies Mandatory: Team Lead experience Deep experience in monitoring and interpreting SIEM outputs, including log correlation, alert triage, and threat prioritization. Ability to design, validate, and tune detection rules and alerts for multiple platforms (SIEM, EDR, NDR, IDS/IPS, firewalls). Advanced log analysis skills across endpoints, network, identity systems, and cloud environments. Experience with SIEM technologies such as Splunk, Microsoft Sentinel, etc., EDR, and Threat Intelligence Platforms. Proficiency in building and executing complex queries (KQL, SPL, or vendor-specific languages) for detection and investigation. Expertise in identifying automation potential in SOC manual processes/workflows and designing their transformation into automated SOC/IR playbooks and modules within SOAR, such as FortiSOAR and Splunk SOAR. Strong knowledge of network protocols (TCP/IP, HTTP/S, DNS, FTP, SMTP) and the ability to identify malicious activity patterns. Ability to analyze threat intelligence feeds and apply IOC/TTP indicators to operational detection logic. Expertise in monitoring Anti-DDoS solutions and understanding mitigation at an operational level. Strong capability to validate alerts and investigation outputs from SOC engineers to ensure quality and accuracy. Experience in documenting investigations, creating runbooks, and maintaining operational knowledge repositories. Understanding of the global threat landscape through analysis of cyber threat intelligence. Ability to mentor and coach SOC engineers on technical best practices, complex investigations, and use-case development. Awareness of the current threat landscape, malware trends, and attack vectors, with the ability to translate this into operational detection priorities.