SOC L2 Engineer
PureCS · Dubai, United Arab Emirates
Apply & track with Apply EdgeSOC L2 Engineer | PureCS / PurenetDubai, UAE (Soon to be moved toAbu Dhabi)Department: Cybersecurity / SOCReporting to: SOC Manager / Cyber Defense Lead
This role is responsible for advanced alert investigation, incident response, threat hunting, and tuning detection logic across SIEM, EDR/XDR, SOAR, and cloud environments. You will act as the technical escalation point for L1 analysts and play a key role in improving monitoring coverage, detection maturity, and SOC automation.
Key Responsibilities
Investigate and respond to alerts across SIEM, EDR/XDR, SOAR, firewall, WAF, email security, DLP, and cloud platforms.Perform incident triage, containment, escalation, and root‑cause analysis within defined SLAs.Conduct threat hunting for malware, phishing, credential compromise, privilege escalation, lateral movement, persistence, and data exfiltration.Develop and tune SIEM correlation rules, detection use cases, and hunting queries.Analyze suspicious emails, files, URLs, processes, and network activity using EDR and sandboxing tools.Support SOAR automation and identify opportunities to improve SOC efficiency.Provide technical guidance to L1 analysts and handle complex escalations.Maintain accurate incident documentation, evidence, timelines, and handovers.Collaborate with IT, Network, IAM, Cloud, and Infrastructure teams during security incidents.Continuously improve SOC processes, monitoring coverage, and detection capabilities.Required Skills & TechnologiesSIEM: IBM QRadar / SplunkEDR/XDR: CrowdStrike Falcon / Microsoft DefenderIncident Response & Threat HuntingStrong knowledge of Windows, Active Directory, networking, cloud, and security technologiesSOAR & Security AutomationScripting in PowerShell/Python (preferred)Experience & Qualifications:3–6 years of SOC/security operations experience with L2‑level responsibilities.Bachelor’s degree in Cybersecurity, Information Security, Computer Science, IT, or related field.Relevant security certifications (preferred).Willingness to work rotational 24x7 shifts.Why Join PureCS?You will be part of a mission‑critical cybersecurity function protecting national digital health infrastructure. This role offers exposure to advanced detection technologies, complex incident response scenarios, and a collaborative environment focused on continuous improvement and modern security operations.