📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Security Operations Analyst – Incident Response

Core42 · Dubai

Senior 🇬🇧 English
Splunk SPL Cribl Elastic Security Corelight OpenStack Red Hat OpenShift SIEM EDR NDR incident response

Job description

About the role

We are seeking a hands‑on Analyst to lead the technical depth of our 24×7 Security Operations Center in Dubai. You will own security incidents from detection through containment, eradication and recovery while continuously improving our detection capabilities.

Key responsibilities

  • Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private‑cloud platform and enterprise services.
  • Perform triage and investigation of security events, acting as the senior technical decision point on genuine incidents.
  • Investigate EDR and NDR alerts involving malware, credential theft, lateral movement, ransomware and other compromises.
  • Own the full incident‑response lifecycle: identification, containment, eradication, recovery and post‑incident review.
  • Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams.
  • Lead cross‑team response efforts to ensure timely investigation, escalation and resolution.
  • Develop, maintain and improve incident‑response playbooks and standard operating procedures.
  • Create, tune and optimise Splunk correlation searches, alerts, dashboards and SPL queries.
  • Reduce alert fatigue by tuning noisy detections and lowering false‑positive rates.
  • Support onboarding of new log sources, validate log quality and manage Cribl Stream/Edge pipelines for log routing.

Required profile

  • Hands‑on practitioner with deep technical knowledge of security operations.
  • Senior escalation point and mentor for less‑experienced analysts.
  • Comfortable working across virtualised and containerised infrastructure, including OpenStack and Red Hat OpenShift.
  • Strong analytical and problem‑solving abilities.
  • Excellent collaboration skills with platform, infrastructure, network and application teams.

Required skills

  • Splunk (SIEM) and SPL query language.
  • Cribl Stream/Edge for log pipeline management.
  • Elastic Security (EDR) and Corelight (NDR).
  • OpenStack and Red Hat OpenShift environments.
  • Incident response lifecycle management.
  • Log source onboarding, parsing, field extraction and normalization.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Core42.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Arab Emirates.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 3 weeks from now

25 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Core42

Dubai