←  Back to all vacancies

Engineer/Incident Management

Etisalat E&

Telecommunications

📍 Abu Dhabi, United Arab Emirates
💼 Full-time
🕒 Posted 4 days ago

Job description

Role Overview

Engineer/Incident Management at Etisalat E& — a technical SOC Specialist role responsible for high-level incident response and threat detection within a 24/7 Security Operations Center.

Role Purpose

Drive the full incident lifecycle—from initial triage and traffic analysis to host recovery and remediation—while designing automated SOAR playbooks that enhance the organization's defensive posture.

Key Responsibilities

Incident Management & Response

  • Provide continuous 24/7 oversight of security events and alerts.
  • Manage and categorize alerts from SIEM, Anti-DDoS, and other security solutions based on urgency and risk.
  • Lead technical response activities, including host triage, containment, and recovery.
  • Conduct remote system analysis and implement remediation efforts using strong correlation skills.
  • Maintain the full incident response lifecycle and ensure all actions adhere to established SLAs (Service Level Agreements).

Security Automation & Intelligence

  • Identify opportunities for automation in manual workflows and design automated playbooks and modules in the SOAR platform.
  • Apply detailed understanding of the MITRE ATT&CK Framework to identify and map attacker techniques.
  • Analyze global threat landscapes, including cyber threat intelligence, new vulnerabilities, and exploit code to stay ahead of adversaries.
  • Study vulnerabilities and provide technical recommendations for corrective actions and reporting.

Technical Expertise & Maintenance

  • Maintain deep knowledge of Security Technologies, Operating Systems (Windows & Linux), and deep-packet analysis tools like Wireshark.
  • Utilize extensive experience in log correlation and analysis to detect and investigate suspicious patterns.
  • Ensure all findings, communication, and mitigation steps are thoroughly recorded in the ticketing system.

Qualifications & Experience

  • BSc in Computer Science, Electrical/Computer/Software Engineering.
  • 3–5 years' experience in a Security Operations Center environment.
  • Thorough experience handling cyber security incidents.
  • Experience with SIEM technologies such as ArcSight, Microsoft Sentinel, and Threat Intelligence Platform.
  • Expertise in gauging automation potential in SOC manual processes and workflows and designing their transformation into automated SOC/IR playbooks and modules within FortiSOAR.
  • Extensive experience in incident response activities and skilled in log analysis.
  • Experience with Anti-DDoS solutions, preferably at a Service Provider level.
  • Sound understanding of common network services (Web, Mail, FTP, DNS), network vulnerabilities, and network attack patterns.

Skills & Competencies

  • Mandatory: SIEM-based trainings, FortiSOAR Training.
  • Preferred: GCIH Certified, Incident Handler Training, Linux+, Security+, CCNA, CCNA Security, FortiSOAR Certification.
  • Deep knowledge of Windows and Linux environments.
  • Ability to write and execute complex queries using KQL (Kusto Query Language).
  • Monitoring experience of security tools including SIEM, Anti-DDoS, IPS, EDR, firewalls, and MFA systems.
  • Understanding of global threat landscape by analyzing cyber threat intelligence.

Additional Information

  • Flexible to work in shifts and willing to assist team overtime if needed.

People looking at this role also searched

Report this job

⚡ Quick Apply

Create your account and upload your CV to apply for — takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.