Apply Edge Start your job search

SOC Team Lead (Fortinet-centric)

RedSnap Defense · Abu Dhabi Emirate, United Arab Emirates

Apply & track with Apply Edge
About the RoleYou'll be the operational leader of a government SOC. You own the day-to-day running, governance, incident management, and team performance. You're responsible for SLAs, escalation procedures, stakeholder reporting, and making sure the team is always improving. Key ResponsibilitiesLead major incident investigations — take ownership of critical security events, coordinate response across network/endpoint/cloud teams, ensure containment and eradication within SLAPerform hands-on technical analysis — investigate advanced network, endpoint, and cloud security events; validate complex alerts; extract IOCs and TTPsAct as senior escalation point — be the on-call escalation for analysts when incidents exceed defined thresholds; make go/no-go decisions on incident severity and response intensityDesign and implement SOC detection rules — work with SIEM/SOAR engineers to build detection logic for emerging threats; review rule effectiveness and drive tuning cycles Architect SOC platform integration — design data flows from endpoints, firewalls, cloud platforms, email systems into FortiSIEM; ensure log sources are correctly mapped andLead detection engineering roadmap — identify coverage gaps using MITRE ATT&CK framework; prioritize new detections based on threat landscape and client risk profile Mentor SOC analysts in real-time — provide live guidance during investigations; conduct post-incident reviews and give feedback to improve technical capability Coach analysts on threat hunting methodology — teach hypothesis-driven hunting (not just IOC chasing); help analysts develop custom queries and hunting playbooks.Manage incident response procedures and governance — define escalation paths, severity levels, SLA response times; maintain and test incident runbooks monthly Conduct root cause analysis — lead post-incident reviews to understand attack paths, control failures, and systemic improvements needed Oversee SOC maturity enhancement — track SOC maturity using established frameworks; identify process gaps and implement improvements quarterly Manage government stakeholder relationships — present security posture to senior government officials; address compliance concerns (security policies, audit trails, data handling) Drive SOC automation improvements — work with SOAR engineer to automate repetitive triage and response tasks; measure automation ROI Evaluate and integrate AI/ML for SOC — assess ML-based anomaly detection; test user/entity behavior analytics (UEBA); implement where appropriate to reduce analyst workloadTrack and report SOC performance — maintain dashboards for MTTD, MTTR, false positive rate, SLA compliance; report monthly to leadership with trend analysis Approve FortiSIEM/FortiSOAR architectural changes — review platform upgrades, new connectors, playbook designs before deployment Conduct SOC readiness assessments — evaluate analyst skills, tool readiness, and process maturity; identify training needs Build knowledge base and playbooks — document all major incident types, response procedures, tool configurations; ensure knowledge transfers to client internal teamRequired QualificationsBachelor's or Master's in Computer Science, IT, Engineering, or related fieldMinimum 5–7 years hands-on SOC operations, incident response, or security engineering in large enterprise environmentsMinimum 2 years supporting government, public sector, or judicial clientsExpert-level understanding of TCP/IP, routing (OSPF, BGP), VLANs, VPNs, network segmentationHands-on FortiSIEM and FortiSOAR experience (or equivalent: Splunk, Elastic SIEM, Demisto SOAR)Advanced incident response and forensics knowledge (memory analysis, disk forensics, log analysis, network traffic analysis)MITRE ATT&CK framework knowledge and threat modelingExperience designing detection rules and tuning SIEM alertsMalware triage and reverse engineering fundamentalsCloud security (AWS, Azure, GCP log analysis and threat detection)EDR, firewall, and IDS/IPS integration knowledgeExperience leading teams and presenting to senior stakeholdersAble to work full-time onsite in Abu Dhabi for 12 monthsMust sign NDA and pass government background checks  Preferred CertificationsCISSPGCIH, GSOC, GMON, GCFA or any related SANS GIAC Certifications.Nice to HaveArabic language skillsFortinet NSE 4+ certificationsUEBA and ML-based detection experienceGovernment security policy and compliance frameworks📩 Interested?Please share your updated CV/resume via email to contact@redsnapdefense.com along with the following information:Full Name:Email:Phone (WhatsApp):Current Location:Passport Nationality:Current Salary: AED / INR / USD / GBPExpected Salary (Abu Dhabi): AED Notice Period: ___ weeks/daysCurrent Status: UAE Resident / Other GCC / Need SponsorshipCan Relocate By: _______ (date)Know someone who could be a great fit? share this opportunity.