SOC / Security Platform Analyst
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 10 hours ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
About Command Post
Command Post is a company specializing in cybersecurity and artificial intelligence technologies, offering advanced solutions in security operations, threat intelligence, application security, AI assurance, governance, risk, compliance, and privacy. Expanding its regional delivery capabilities, it seeks a hands-on SOC & Security Platform Analyst to join teams in Qatar or Dubai, UAE.
Role Overview
The selected candidate will work full-time onsite within client environments, supporting daily security operations and managing the setup, administration, and enhancement of security monitoring platforms. This position requires practical knowledge of how security alerts, telemetry, logs, threat intelligence, detection strategies, and automated workflows work collectively to maintain an effective Security Operations Centre. Suitable applicants may come from roles as experienced SOC analysts, technical security platform engineers, or a combination of both skill sets.
Key Responsibilities
- Monitor, triage, and investigate security alerts and incidents, responding appropriately.
- Analyze event data from endpoints, networks, cloud services, identity platforms, applications, and security controls.
- Carry out structured investigations to assess incident scope, impact, root causes, and containment measures.
- Perform proactive threat hunting by utilizing indicators, behaviors, techniques, and threat intelligence.
- Document findings, evidence, timelines, decisions, and suggest remediation actions.
- Develop and maintain incident response procedures, investigation playbooks, and escalation protocols.
- Identify recurring security issues and recommend enhancements to controls and operations.
- Support customer reporting, operational reviews, and incident briefings.
- Configure, manage, and improve SIEM and security analytics platforms.
- Assist in onboarding log sources, parsing data, normalization, enrichment, correlation, and validating data quality.
- Create and manage detection rules, use cases, alerts, dashboards, reports, and monitoring workflows.
- Optimize security use cases to minimize false positives while preserving adequate detection coverage.
- Integrate data sources including endpoint, network, cloud, identity, vulnerability, threat intelligence, and application security solutions.
- Support SOAR playbooks, automation workflows, case management, and response orchestration.
- Monitor platform health, ingestion performance, storage, integrations, and availability.
- Assist with system upgrades, troubleshooting, testing, documentation, and operational handover.
- Collaborate with customer infrastructure, security, network, cloud, and application teams to resolve technical problems.
Technology Experience
Experience with one or more of the following is highly preferred:
- Palo Alto Cortex XSIAM or XSIEM
- Microsoft Sentinel
- Elastic Stack / ELK
- OpenSearch
- LogRhythm
- ArcSight
- Other enterprise SIEM, SOAR, security analytics or log management systems
Additional valuable experience includes endpoint detection and response, device onboarding, detection engineering, orchestration and automation, threat intelligence integration, cloud and network security monitoring, identity access control, and vulnerability management integrations.
Required Experience and Skills
- Hands-on work experience within a SOC, security operations team, managed security service, or security engineering environment.
- Strong knowledge of security monitoring, alert triage, incident investigation, and escalation processes.
- Familiarity with attacker tactics, indicators of compromise, and the MITRE ATT&CK framework.
- Ability to analyze logs and telemetry from multiple security sources.
- Experience writing SIEM queries, creating dashboards, developing detection rules, correlation logic, and platform administration.
- Understanding of endpoint protection platforms, EDR/XDR, firewalls, identity systems, cloud environments, and enterprise infrastructure.
- Methodical investigation approach with clear communication of outcomes.
- Competent written documentation and customer interaction skills.
- Ability to work independently onsite while coordinating with wider technical teams.
- Availability and willingness to work onsite full-time in Qatar or Dubai.
Advantageous Expertise
- Digital forensics and investigative skills.
- Malware analysis proficiency.
- Incident response and containment experience.
- Threat hunting program creation.
- Detection engineering capabilities.
- Experience in offensive security, penetration testing, red teaming, or vulnerability assessment.
- Security automation using Python, PowerShell, APIs, or scripting tools.
- Cloud security exposure with Microsoft Azure, AWS, or Google Cloud.
- Work experience with regulated sectors or critical infrastructure.
- Consulting, professional services, or customer-facing technical roles experience.
Qualifications
Candidates with relevant technical qualifications, certifications, or practical experience are welcome. Suggested certifications include:
- CompTIA Security+, CySA+, or equivalents
- Microsoft Security Operations Analyst
- Elastic, Palo Alto, LogRhythm, ArcSight, or other SIEM certifications
- GIAC certifications in incident response, forensics, security operations
- Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or similar offensive security credentials
- Cloud security certifications
While certifications add value, practical hands-on experience remains paramount.
Candidate Profile
- Curious about technical challenges and adept at investigating complex security issues.
- Focused operationally and effective in live client environments.
- Capable of managing immediate incident response priorities alongside long-term platform improvements.
- Communicates confidently with analysts, engineers, stakeholders, and management.
- Owns responsibilities and delivers professional-quality results.
- Interested in modern security analytics, automation, AI-supported operations, and integrated cyber defense systems.
Why Join Command Post
- Opportunity to work directly with enterprise customers in Qatar and UAE.
- Exposure to a wide range of security technologies and operational environments.
- Contribute to AI-enabled cybersecurity platform development and delivery.
- Engage in activities spanning security operations, threat hunting, investigation, engineering, automation, and platform transformation.
- Be part of a growing regional cybersecurity firm with prospects for advancement into senior technical, consulting, platform engineering, or security leadership roles.