C

Analyst - Security Operations

Core42

United Arab Emirates · Full Time

Be the first to apply

Experience
4–8 yrs
Salary
Openings
1
Posted
2 ঘন্টা আগে
Work mode
In office
Education
Bachelor's degree in Computer Science, Cybersecurity or related field
Resume
Required to apply

Job description

Opportunity Overview

We seek an Incident Analyst to provide technical expertise within our 24/7 Security Operations Center (SOC). The role involves detection, triage, investigation, and response to security incidents affecting our private cloud platform and enterprise services. The ideal candidate will manage incident lifecycles from initial alert through containment, eradication, recovery, and post-incident analysis, while mentoring junior analysts and enhancing detection quality. Our infrastructure leverages OpenStack and Red Hat OpenShift, with SIEM and security tools including Splunk, Cribl, Elastic Security, and Corelight. Familiarity with virtualized and containerized platforms is essential.

Primary Responsibilities

  • Monitor security alerts in Splunk to identify threats and malicious activities across cloud and enterprise environments.
  • Conduct investigations and triage, making senior-level technical decisions on incident validity.
  • Analyze EDR and NDR alerts related to malware, credential theft, ransomware, lateral movement, and other compromises.
  • Lead complete incident response processes including identification, containment, eradication, recovery, and post-incident review.
  • Coordinate remediation efforts across platform, network, infrastructure, and application teams.
  • Develop and update incident response playbooks and SOPs, refining them after major incidents.
  • Create and fine-tune Splunk correlation searches, alerts, dashboards, and reports to improve detection accuracy.
  • Craft efficient SPL queries to support investigative and detection activities.
  • Minimize false positives by tuning alert thresholds and correlation logic to balance detection accuracy and alert fatigue.
  • Assist with onboarding and validation of new log sources, ensuring data quality and normalization.
  • Manage Cribl Stream/Edge pipelines to optimize log routing, filtering, enrichment, and data flow efficiency.
  • Conduct hypothesis-driven threat hunting to discover advanced threats and detection gaps, mapping coverage to MITRE ATT&CK framework.
  • Apply threat intelligence models such as MITRE ATT&CK, Cyber Kill Chain, and Diamond Model to enhance investigations and detection capabilities.
  • Perform root cause analyses and prepare detailed incident reports for stakeholders.
  • Maintain accurate incident documentation, evidence, and lessons learned within the case management system.
  • Support audit and compliance efforts by documenting incident management activities and outcomes.
  • Work full-time within a 24/7 SOC environment, participating in rotational shifts including nights, weekends, and holidays with defined SLAs and structured handovers.

Required Qualifications and Experience

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related fields; equivalent professional experience and certifications considered.
  • Between 4 and 8 years of hands-on experience in security operations, incident response, or SOC monitoring roles.
  • Advanced proficiency with Splunk (including SPL scripting, dashboard development, correlation, and administration).
  • Experience managing Cribl Stream/Edge pipelines for log data routing and enrichment.
  • Strong background in incident analysis, evidence handling, escalation, and comprehensive incident response lifecycle aligned with industry standards.
  • Technical familiarity with Elastic Security (EDR) and Corelight (NDR) tools.
  • Solid networking knowledge including TCP/IP, DNS, HTTP/S, firewall and proxy configurations, and IDS/IPS systems.
  • Comfortable working with Windows and Linux operating systems.
  • Scripting skills in Python, Bash, or PowerShell to automate tasks and aid investigations.
  • Experience with private cloud platforms such as Red Hat OpenShift, OpenStack, Commvault, and Scality.
  • Competence using ticketing and case management tools like ServiceNow or Jira for incident tracking and documentation.

Preferred Certifications and Skills

  • Splunk Core Certified Power User or Splunk Certified Admin certifications.
  • Cribl Certified Admin credential.
  • GIAC certifications relevant to detection and incident response (e.g., GCIA, GCIH, GCDA, GCFA).
  • Blue Team Level 2 (BTL2) or equivalent certifications in defensive security.
  • Experience monitoring OpenStack and Kubernetes/OpenShift environments.
  • Knowledge of detection-as-code practices including version control and peer review.

Working Conditions

  • Full-time employment with reporting to SOC Manager.
  • Shift work on a rotational basis covering day, evening, night shifts including weekends and public holidays.
  • Structured shift handover processes to maintain incident continuity.

Work styles they’re looking for

Analytical Thinking Problem Solving Attention to Detail Team Collaboration Shift work adaptability

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help