←  Back to all vacancies

Expert Engineer/Security Operation Centre

Etisalat E&

Telecommunications

πŸ“ Dubai, United Arab Emirates
πŸ’Ό Full-time
πŸ•’ Posted 2 weeks ago

Job description

Role Overview

Expert Engineer/Security Operations Centre at Etisalat E&. This role serves as the Subject Matter Expert for advanced security monitoring and incident management within the Cyber Security function.

Role Purpose

Oversee advanced security monitoring and incident management activities, serving as the primary escalation point for complex or high-severity security incidents. Provide technical leadership and validation before handover to Incident Response teams, while mentoring SOC engineers and driving continuous improvement of security operations processes.

Key Responsibilities

Security Monitoring & Investigation

  • Serve as the primary contact for advanced security monitoring, threat detection, and investigation methodologies.
  • Lead in-depth analysis of security events from multiple sources, including SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data.
  • Conduct deep-dive technical investigations for high-impact or ambiguous alerts.
  • Utilize SIEM, IDS/IPS, firewalls, endpoint detection, and network telemetry to investigate security incidents.
  • Apply MITRE ATT&CK and DEFEND frameworks to map detected threats and enhance threat-hunting capabilities.
  • Analyze threat intelligence feeds and apply IOC/TTP indicators to operational detection logic.
  • Monitor Anti-DDoS solutions and understand mitigation at an operational level.

Detection & Content Development

  • Design, tune, and validate detection rules and alerts for multiple platforms (SIEM, EDR, NDR, IDS/IPS, firewalls).
  • Develop and maintain SOC playbooks and runbooks to ensure consistent investigation standards.
  • Identify gaps in detection coverage and recommend improvements.
  • Continuously support the content development team by recommending detection rule tuning to reduce false positives and by proposing new advanced correlation rules, behavioral detections, and anomaly-based use cases.
  • Build and execute complex queries (KQL, SPL, or vendor-specific languages) for detection and investigation.
  • Ensure effective detection and monitoring across hybrid environments, including on-premises, cloud, and telco cloud.

Incident & Quality Management

  • Act as the final technical validation authority before escalating to Incident Response (IR) teams.
  • Validate alerts and investigation outputs from SOC engineers to ensure quality and accuracy.
  • Review and quality-check investigation reports before closure.
  • Participate in major incident calls as the SOC technical lead.
  • Conduct post-incident detection gap analysis.
  • Support SOC shift staff in maintaining SLA compliance.

Team Leadership & Mentoring

  • Lead and supervise team members to ensure effective incident detection and response.
  • Provide technical guidance and escalation support to SOC analysts for complex or high-severity incidents.
  • Mentor analysts and organize trainings to maintain team expertise.
  • Conduct trainings and technical workshops.
  • Lead internal technical workshops and purple-team collaboration exercises.
  • Develop knowledge articles, technical documentation, and use-case libraries.
  • Ability to mentor and coach SOC engineers on technical best practices, complex investigations, and use-case development.

Automation & Process Improvement

  • Drive automation opportunities through SOAR playbooks and workflows.
  • Identify automation potential in SOC manual processes and workflows and design their transformation into automated SOC/IR playbooks and modules within SOAR, such as FortiSOAR and Splunk SOAR.
  • Contribute to continuous improvement of SOC processes and content.

Threat Intelligence & External Engagement

  • Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities.
  • Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders.
  • Participate in the RFP process to provide technical recommendations and propose best-fit solutions.
  • Awareness of the current threat landscape, malware trends, and attack vectors, with the ability to translate this into operational detection priorities.

Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, or a related field (or equivalent work experience).
  • 8–10 years of experience in cybersecurity.
  • Mandatory: Team Lead experience.
  • Deep experience in monitoring and interpreting SIEM outputs, including log correlation, alert triage, and threat prioritization.
  • Advanced log analysis skills across endpoints, network, identity systems, and cloud environments.
  • Experience with SIEM technologies such as Splunk, Microsoft Sentinel, etc., EDR, and Threat Intelligence Platforms.
  • Experience in documenting investigations, creating runbooks, and maintaining operational knowledge repositories.

Skills & Competencies

  • Cybersecurity-related certification(s).
  • Ability to design, validate, and tune detection rules and alerts for multiple platforms (SIEM, EDR, NDR, IDS/IPS, firewalls).
  • Proficiency in building and executing complex queries (KQL, SPL, or vendor-specific languages) for detection and investigation.
  • Expertise in identifying automation potential in SOC manual processes and workflows.
  • Strong knowledge of network protocols (TCP/IP, HTTP/S, DNS, FTP, SMTP) and ability to identify malicious activity patterns.
  • Strong capability to validate alerts and investigation outputs from SOC engineers to ensure quality and accuracy.
  • Understanding of the global threat landscape through analysis of cyber threat intelligence.

Additional Information

Preferred Certifications

  • CISM
  • CISSP
  • Microsoft Sentinel training
  • Splunk training

People looking at this role also searched

Report this job

⚑ Quick Apply

Create your account and upload your CV to apply for β€” takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.