Security Analyst, Abu Dhabi, UAE

This job is OPEN to APPLY for ALL Nationalities, unless otherwise specified.



The opportunity


Security Analyst, Core42 - Abu Dhabi, UAE. We are looking for a senior Security Analyst to anchor the technical depth of our 24x7 Security Operations Centre. This role detects, triages, investigates and responds to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate is a hands-on practitioner who can own an incident end to end - from the first alert in Splunk through containment, eradication and recovery - while also raising the quality of our detections and acting as a senior escalation point and mentor for less-experienced analysts. The environment is a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR) and Corelight (NDR). Comfort working across virtualised and containerised infrastructure log sources is expected. The role reports to the SOC Manager and operates on a full-time, 24x7 rotational shift basis.

 

Your key responsibilities

Security monitoring, triage & detection

Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
Serve as the senior escalation point for front-line analysts, providing investigative guidance and validating findings before escalation
Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise
Incident response (full lifecycle)

Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post-incident review
Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
Lead the response on assigned incidents and coordinate cross-team activity to ensure timely investigation, escalation and resolution
Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident
SIEM, detection engineering & log pipeline

Create, tune and optimise Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic, weighing false-positive cost against miss cost when making tuning decisions
Support onboarding of new log sources and validate log quality, parsing, field extraction and normalisation
Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalisation, optimising data flow and Splunk licence consumption
Threat hunting & intelligence

Conduct hypothesis-driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response
Identify patterns, trends and indicators of compromise (IOCs) to proactively detect and prevent recurrence
Documentation, reporting & governance

Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned in the case-management platform
Contribute to the continuous improvement of security monitoring use cases and detection rules
Support audit and compliance requirements by providing evidence of incident-management activities
Working arrangement

Operate within a 24x7 SOC, participating in rotational day, evening and night shifts, including weekends and public holidays on a rotational basis
Meet defined acknowledgement, triage and escalation SLAs on each shift and complete structured shift handovers to maintain continuity of in-flight incidents
 

What we’re looking for



(a) Required skills / qualifications

Bachelor's degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
5-8 years in security operations, incident response or SOC monitoring, with at least 2 years at a senior level
Proven hands-on experience with Splunk Enterprise / Splunk Cloud - advanced SPL, dashboard development, correlation searches, alert creation and tuning, and administration
Demonstrated experience with Cribl Stream / Cribl Edge - log routing, parsing, filtering, enrichment and pipeline management
Strong background in incident analysis, investigation, evidence handling, escalation management and full-lifecycle response aligned with industry standards, including playbook and SOP development and RCA
Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation and response
Threat frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain and Diamond Model
Strong understanding of networking: TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS
Proficiency in Windows and Linux environments
Proficiency in Python, Bash or PowerShell for automation and analysis
Familiarity with private-cloud and platform log sources: Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
ServiceNow, Jira or equivalent ticketing/case management for incident tracking, evidence attachment, escalation notes and closure documentation
(b) Preferred skills / qualifications

Splunk Core Certified Power User or Splunk Certified Admin
Cribl Certified Admin
GIAC certifications relevant to detection and response - GCIA, GCIH, GCDA or GCFA
Blue Team Level 2 (BTL2) or equivalent hands-on defensive certification
Experience monitoring OpenStack and Kubernetes/OpenShift environments
Familiarity with detection-as-code practices (version control and peer review of detection content)
 


DETAILS TO REGISTER FOR THIS JOB:

Make Sure Your CV is ATS-friendly.

https://careers.core42.ai/job/Security-Analyst/882-en_US?utm_source=LinkedIn

πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²

What is an ATS CV?

Applicant Tracking System or "ATS", is the software that 'READS' your CV and stores this information in a database. Like this:

Applicant Tracking System Correct Parsing

If the CV is not made as per the RULES of the ATS, the information will get messed up in the database. In the image below, 'PMP' has gone into the 'Mobile Number' column. The Mobile Number '052 1234567' has gone into the 'Main Skill' column.

Applicant Tracking System Incorrect Parsing

So a recruiter searching for a candidate with PMP certification, will never find this person, in spite of his 'CV information' existing in the database...

...And, he will wonder why he gets rejected in spite of being a PERFECT MATCH for the Job.


Our leading services are as follows. Click the link as per your experience level:


πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²


πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²

Read the recommendations our customers have given us, on my LinkedIn profile:

https://www.linkedin.com/in/shabbirfkagalwala/details/recommendations/

Navigate here for more testimonials/feedback about our expertise and results:

www.dubai-forever.com/resume-writing-feedback.html
www.dubai-forever.com/cv-writing-reviews.html

Also, read reviews about "www.Dubai-Forever.Com" on TrustPilot.com, the world's most trusted review site...


πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²

Navigate here for the Latest CV Samples & Templates, APPROVED by recruiters. For FREE!:

https://www.dubai-forever.com/cv-writing-sample.html


πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²

Join the Fastest Growing Job Group on LinkedIn:

Fastest Growing LinkedIn Job Groups in UAE/GCC, Join for Free

Join the Middle East's Best Job Groups on Whatsapp:

Dubai, Abu Dhabi, UAE, Middle East Whatsapp Jobs Groups, Join for Free

Join our Telegram Group:

Fastest Growing Telegram Job Groups in UAE/GCC, Join for Free

Submit your CV here, as well:

Submit Your CV for GCC Jobs

We support the Far-Sighted, Growth-Oriented Vision announced by the UAE, Saudi Arabia, Qatar, Oman, Kuwait and Bahrain.

It's an exciting time and the next 30 - 40 years will see massive growth in jobs in the GCC countries.

Excited about working in the GCC? Click on one of the banners below...


UAE Vision 2021 Saudi Vision 2030 Qatar Vision 2030 Bahrain Vision 2030 Kuwait Vision 2035 Oman Vision 2040

---------PAID ADVERTISEMENT------------

Watch, Like, and Subscribe to the YouTube Channels:

House of Focus creates original cinematic Deep Focus Music and immersive Flow State Soundtracks™ designed for studying, coding, reading, writing, creative work, and distraction-free productivity.

https://www.youtube.com/@HouseofFocus-28

Indian Folk Originals - We create original Punjabi folk-inspired wedding songs built around the biggest moments of Indian celebrations.

https://www.youtube.com/@IndianFolkOriginals

Hedgehog Haven - Discover beautifully crafted, photorealistic hedgehog videos set in tranquil forests, cozy gardens, misty mornings, gentle rain, autumn leaves, snowy landscapes, and magical natural habitats from around the world.

https://www.youtube.com/@HedgehogHaven-6

If you want to promote your services/products as well, get in touch with us.

SOCIAL INITIATIVE:

We publish job vacancies on this Job Portal (https://www.dubai-jobs.me) and our Whatsapp groups (www.dubai-forever.com/whatsapp-jobs.html) for the benefit of job-seekers.

It is to help people who are searching for jobs from across the world.

This is a Social Initiative from our team @ dubai-forever.com, so please help in this Noble Task by Forwarding these jobs within your Network.

Do this GOOD DEED.

You never know who will benefit from it.

You've heard about KARMA right?

It's waiting to give you 10X of whatever you do... Do the Good Deed. FORWARD NOW!


πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²   πŸ‡§πŸ‡­   πŸ‡°πŸ‡Ό   πŸ‡¦πŸ‡ͺ   πŸ‡ΈπŸ‡¦   πŸ‡ΆπŸ‡¦   πŸ‡΄πŸ‡²

No comments:

Popular Posts