Apply Edge Start your job search

SOC / Security Platform Analyst

Command Post QFZ LLC · Doha, Qatar

Apply & track with Apply Edge
Location: Qatar or Dubai, UAE Working Arrangement: Full-time, on-site at client locations Company: Command PostAbout Command PostCommand Post is a cybersecurity and AI technology company delivering advanced security operations, threat intelligence, application security, AI assurance, governance, risk, compliance, and privacy solutions.We are expanding our regional delivery capability and are seeking a hands-on SOC & Security Platform Analyst to support customer security operations and security technology environments across Qatar and Dubai.This role is suitable for candidates from either of the following backgrounds:An experienced SOC analyst with strong operational, threat-hunting, and incident investigation capabilities.A technical security platform engineer with experience deploying, managing, and improving SIEM, SOAR, endpoint security, and security monitoring platforms.Role OverviewThe successful candidate will work on-site within customer environments, supporting day-to-day security operations and the implementation, administration, and optimisation of security monitoring platforms.The role requires a practical understanding of how security alerts, endpoint telemetry, logs, threat intelligence, detection rules, and automated response workflows come together to support an effective Security Operations Centre.Candidates do not need to be equally strong across every area. We are interested in experienced SOC practitioners, technical platform engineers, or candidates who combine elements of both disciplines.Key ResponsibilitiesSecurity Operations and Incident InvestigationMonitor, triage, investigate, and respond to security alerts and incidents.Analyse events from endpoints, networks, cloud services, identity platforms, applications, and security controls.Conduct structured investigations to determine incident scope, impact, root cause, and required containment actions.Perform proactive threat hunting using indicators, behavioural patterns, attack techniques, and threat intelligence.Document investigation findings, evidence, timelines, decisions, and recommended remediation actions.Support the development and maintenance of incident response procedures, investigation playbooks, and escalation processes.Identify recurring security issues and recommend improvements to controls, monitoring, and operational processes.Support customer reporting, operational reviews, and incident briefings.Security Platform EngineeringConfigure, administer, and optimise SIEM and security analytics platforms.Support log source onboarding, parsing, normalisation, enrichment, correlation, and data quality validation.Develop and maintain detection rules, use cases, alert logic, dashboards, reports, and monitoring workflows.Tune security use cases to reduce false positives while maintaining appropriate detection coverage.Integrate endpoint, network, cloud, identity, vulnerability, threat intelligence, and application security data sources.Support SOAR playbooks, workflow automation, case management, and response orchestration.Monitor platform health, ingestion performance, storage, integrations, connectors, and service availability.Assist with upgrades, troubleshooting, platform testing, documentation, and operational handover.Work with customer infrastructure, security, network, cloud, and application teams to resolve technical issues.Relevant Technology ExperienceExperience with one or more of the following platforms is highly desirable:Palo Alto Cortex XSIAM or XSIEMMicrosoft SentinelElastic Stack or ELKOpenSearchLogRhythmArcSightOther enterprise SIEM, SOAR, security analytics, or log-management platformsExperience in the following areas will also be valuable:Endpoint Detection and Response and Extended Detection and Response technologiesEndpoint protection platformsDevice and log-source onboardingDetection engineering and use-case managementSecurity orchestration and automated responseDashboard and security reporting developmentThreat intelligence integrationCloud security monitoringIdentity and access monitoringNetwork security monitoringVulnerability management integrationsRequired Experience and SkillsPractical experience working within a SOC, security operations team, managed security service, or security engineering function.Strong understanding of security monitoring, alert triage, incident investigation, and escalation processes.Working knowledge of common attacker techniques, indicators of compromise, and the MITRE ATT&CK framework.Ability to analyse security logs and telemetry from multiple sources.Experience with SIEM queries, dashboards, detection rules, correlation logic, or platform administration.Understanding of endpoint protection, EDR, XDR, firewalls, identity systems, cloud platforms, and common enterprise infrastructure.Ability to investigate technical issues methodically and communicate findings clearly.Strong written documentation and customer communication skills.Ability to work independently within a customer environment while collaborating with wider technical teams.Willingness and ability to work full-time on-site in Qatar or Dubai.Advantageous ExperienceThe following experience would be considered an advantage:Digital forensics or forensic investigation.Malware analysis.Incident response and containment.Threat-hunting programme development.Detection engineering.Offensive security, penetration testing, red teaming, or vulnerability assessment.Security automation using Python, PowerShell, APIs, or scripting.Cloud security experience across Microsoft Azure, AWS, or Google Cloud.Experience supporting regulated organisations or critical infrastructure.Experience working in consulting, professional services, or customer-facing technical roles.QualificationsRelevant technical qualifications, certifications, or equivalent practical experience are welcomed.Useful certifications may include:CompTIA Security+, CySA+, or equivalentMicrosoft Security Operations AnalystElastic, Palo Alto, LogRhythm, ArcSight, or SIEM-specific certificationsGIAC incident response, forensic, or security operations certificationsCEH, OSCP, or other offensive security certificationsCloud security certificationsCertifications are beneficial but will not replace strong practical experience.Candidate ProfileThe ideal candidate is:Technically curious and comfortable investigating complex security problems.Operationally focused and able to work effectively in live customer environments.Capable of balancing incident response priorities with longer-term platform improvement.Confident communicating with analysts, engineers, customer stakeholders, and management.Able to take ownership of assigned activities and deliver work to a professional standard.Interested in working with modern security analytics, automation, AI-assisted security operations, and integrated cyber defence platforms.Why Join Command PostWork directly with enterprise customers across Qatar and the UAE.Gain exposure to a broad range of security technologies and operating environments.Contribute to the development and delivery of AI-enabled cybersecurity platforms.Work across security operations, threat hunting, incident investigation, detection engineering, automation, and security platform transformation.Join a growing regional cybersecurity company with opportunities to develop into senior technical, consulting, platform engineering, or security operations leadership roles.ApplicationPlease apply with an up-to-date CV outlining your experience in security operations, incident investigation, threat hunting, SIEM or SOAR engineering, endpoint security, and security platform administration.Candidates should also confirm whether they are applying for the Qatar-based or Dubai-based position.The role title could also be advertised as SOC & SIEM Platform Analyst or Security Operations & Platform Engineer depending on whether you want to attract more operational analysts or engineering-focused candidates.