أبلاي إيدج ابدأ البحث عن عمل

Security Operations Center Analyst L1

SecurityHQ · Dubai, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
About the RoleAs a SOC Analyst Level 1, you will be the first line of defence within our 24/7 Security Operations Centre, monitoring security events, investigating alerts, and helping to protect customer environments from cyber threats.Working closely with SOC Level 2 Analysts and Security Engineers, you will perform initial investigation and triage of security alerts across a range of technologies, including SIEM, EDR, firewalls, IDS/IPS, and endpoint security platforms. You will determine whether activity is benign or malicious, document findings, and escalate validated security incidents for further investigation and response.This role is ideal for early-career cybersecurity professionals who have a strong foundation in security operations and are looking to build hands-on experience within a fast-paced MSSP environment while developing their technical and analytical skills.You will work on a rotating shift schedule (7 AM to 3 PM, 3 PM to 11 PM, 11 PM to 7 AM), including weekends and holidays, with two days off per week.You will be based onsite in Dubai and assigned to one of three customer locations. All sites are located within approximately 20km of SecurityHQ's Dubai office, providing variety in your day-to-day environment while remaining within a local area.About SecurityHQSecurityHQ is a global cybersecurity company. Our specialist teams design, engineer and manage solutions that do three things: Promote clarity and trust in a complex world. Build momentum around improving security posture. And increase the value of cybersecurity investment within organizations. Free from limitations, and inclusive of all requirements, we focus on defending today, while mitigating the risks of tomorrow. And into the future. Our solutions are tailored to our customers and their unique context. Around the clock, 365 days per year, our customers are never alone.SecurityHQ – We're focused on engineering cybersecurity, by design.ResponsibilitiesMonitor security alerts across SIEM, EDR, IDS/IPS, firewalls, and other security platforms.Perform initial triage to determine false positives versus actionable incidents.Analyse logs, events, and indicators of compromise (IOCs).Follow SOC runbooks and standard operating procedures (SOPs) for alert handling and escalation.Create and update incident tickets with accurate details and timelines.Escalate suspicious activity or confirmed incidents to SOC Level 2 Analysts.Conduct basic threat intelligence lookups, including IP, URL, and hash reputation checks.Support shift handovers and ensure smooth operational continuity.Achieve SOC KPIs, including TTT, TTQ, and SLA adherence.What We Are Looking ForBasic understanding of cybersecurity concepts, including malware, phishing, DDoS, brute force attacks, and other common threats.Working knowledge of Windows and Linux operating systems.Familiarity with networking fundamentals, including TCP/IP, DNS, HTTP/S, and basic troubleshooting.Exposure to SIEM technologies such as Microsoft Sentinel, QRadar, Splunk, or similar platforms.Understanding of EDR and endpoint security tools such as Microsoft Defender, Trend Micro, SentinelOne, or equivalent solutions.Ability to follow defined procedures and work effectively within a 24/7 operational environment.Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or equivalent practical experience.0 to 2 years of experience within a SOC, MSSP, or IT security operations environment.Relevant certifications such as Security+, CEH (Foundation), SC-200, or similar certifications are beneficial.