Apply Edge Start your job search

Senior SOC Analyst / Cybersecurity Engineer

Malcrove · Dubai, Dubai, United Arab Emirates

Apply & track with Apply Edge
Job PurposeThe role is responsible for day-to-day security monitoring, incident investigation, threat hunting, vulnerability management, and administration of the organization’s security platforms. The person will also act as an escalation point for SOC analysts and coordinate security activities with internal teams and external vendors.Key ResponsibilitiesMonitor and investigate alerts in Microsoft Defender XDR, Microsoft Sentinel, LogRhythm, Entra ID, Exchange, firewalls, and other security platforms.Investigate phishing, compromised accounts, malware, suspicious sign-ins, unauthorized applications, and endpoint or network threats.Perform threat hunting using KQL, indicators of compromise, and MITRE ATT&CK techniques.Contain incidents by isolating endpoints, blocking indicators, disabling accounts, revoking sessions, and coordinating phishing-email removal.Administer and troubleshoot LogRhythm, including alarms, AIE rules, reports, log sources, queues, indexing, integrations, storage, and system health.Manage Microsoft Defender policies, device onboarding, endpoint health, antivirus updates, ASR rules, indicators, exclusions, and application controls.Review Tenable/Nessus vulnerability findings, identify affected assets, coordinate remediation, and verify closure.Investigate newly published CVEs and security advisories to determine organizational exposure.Develop and tune SIEM detection rules to improve coverage and reduce false positives.Coordinate with infrastructure, network, application, database, cloud, GRC, and vendor teams to resolve security issues.Prepare incident reports, technical findings, operational updates, and remediation recommendations.Provide technical guidance and escalation support to SOC analysts.Required Experience and SkillsMinimum five years of experience in SOC operations, incident response, or cybersecurity engineering.Hands-on experience with Microsoft Defender XDR, Microsoft Sentinel, LogRhythm, Entra ID, and Tenable/Nessus.Strong knowledge of KQL, SIEM monitoring, threat hunting, and detection engineering.Experience investigating phishing, account compromise, malware, authentication attacks, and endpoint threats.Understanding of Windows, Linux, Active Directory, Exchange, networking, firewalls, WAF, and cloud security.Strong analytical, troubleshooting, documentation, and communication skills.Ability to independently manage security incidents from investigation through containment and remediation.