Apply Edge Start your job search

IT Security Operations Engineer

BigData Technology Solutions · Dubai, United Arab Emirates

Apply & track with Apply Edge
Job SummaryThe IT Security Operations Engineer is responsible for monitoring, detecting, analyzing, investigating, and responding to cybersecurity threats and incidents. The role operates within the Security Operations Center (SOC) and focuses on protecting the confidentiality, integrity, and availability of the organization's information systems.The IT Security Operations Engineer will leverage security technologies, threat intelligence, log analysis, and incident response processes to identify and mitigate security risks while continuously improving SOC detection and response capabilities.Core ResponsibilitiesSecurity Monitoring & Incident ResponseMonitor and analyze alerts from SIEM, EDR/XDR, IDS/IPS, DLP, and other security monitoring platforms.Perform triage, investigation, and analysis of security events to identify potential threats and determine their severity and impact.Investigate and respond to cybersecurity incidents in accordance with established incident response procedures and SLAs.Escalate critical or complex incidents to appropriate teams when required.Support containment, eradication, recovery, and root cause analysis (RCA) activities.Coordinate with infrastructure, network, application, and other cybersecurity teams during incident investigations.Threat Detection & AnalysisConduct proactive threat hunting using threat intelligence, security telemetry, and log analysis.Investigate phishing, malware, ransomware, suspicious activity, and intrusion attempts.Analyze security logs and network activity to identify indicators of compromise and abnormal behavior.Develop, maintain, and tune detection rules, correlation logic, use cases, and security playbooks.Continuously improve detection coverage and reduce false-positive alerts.Vulnerability & Risk ManagementSupport vulnerability scanning, assessment, tracking, and remediation activities.Coordinate with IT and infrastructure teams to patch or mitigate identified vulnerabilities and security risks.Monitor remediation activities and support closure within agreed timelines.Maintain awareness of critical vulnerabilities and emerging cybersecurity threats.Support asset inventory management and identify unauthorized or suspicious changes.Security Tools & AutomationManage, monitor, and optimize security technologies such as SIEM, SOAR, EDR/XDR, IDS/IPS, DLP, firewalls, and other SOC tools.Support integration of security platforms and log sources into the SOC monitoring environment.Develop and maintain automated workflows and SOAR playbooks to improve incident handling and response efficiency.Use scripting and automation to support repetitive security operations activities.Monitor tool effectiveness and recommend improvements to SOC technologies and processes.Security Investigation & AnalysisPerform detailed analysis of security alerts and incidents using log analysis, packet captures, endpoint telemetry, and forensic information.Identify attack patterns, indicators of compromise, and potential attack vectors.Support investigations involving compromised endpoints, accounts, network activity, and cloud environments.Document investigation findings and recommend appropriate remediation actions.Reporting & DocumentationMaintain accurate documentation of security incidents, investigations, response actions, RCA findings, and lessons learned.Prepare periodic reports covering threat trends, vulnerabilities, incidents, and SOC performance.Maintain security operational procedures, incident response playbooks, and technical documentation.Support internal and external compliance audits by providing required security logs, reports, and evidence.Provide knowledge transfer and technical guidance to junior SOC/security team members.Technical ExpertiseThe candidate should have strong hands-on knowledge of:SIEM: Splunk, IBM QRadar, Microsoft Sentinel, or equivalent platformsEndpoint Security: EDR/XDR and endpoint protection technologiesSecurity Monitoring: IDS/IPS, DLP, firewalls, and network security monitoringIncident Response: Incident triage, investigation, containment, eradication, recovery, and RCAThreat Detection: Threat hunting, detection engineering, correlation rules, and security use casesThreat Intelligence: Indicators of compromise, threat feeds, and emerging attack techniquesSecurity Automation: SOAR platforms, automated workflows, and security playbooksVulnerability Management: Vulnerability scanning, risk assessment, remediation, and patch coordinationOperating Systems: Windows and LinuxCloud Security: AWS, Microsoft Azure, and GCP environmentsSecurity Analysis: Log analysis, packet capture, endpoint telemetry, and forensic toolsScripting: Python, PowerShell, or Bash for security automation is an advantageCyber Threats: Malware, phishing, ransomware, intrusion techniques, and common attack vectorsExperience & SeniorityMinimum 5–8 years of relevant experience in SOC operations, cybersecurity, incident response, or IT security operations.Strong hands-on experience with SIEM platforms, endpoint security, firewalls, and security monitoring technologies.Demonstrated experience investigating and responding to cybersecurity incidents.Experience with log analysis, threat hunting, detection tuning, and security incident management.Experience working within an SLA-driven SOC environment.Ability to work in a 24/7 SOC environment or rotational shifts, where required.