Security Operations Analyst – Incident Response
Core42 · Dubai
Job description
About the role
We are seeking a hands‑on Analyst to lead the technical depth of our 24×7 Security Operations Center in Dubai. You will own security incidents from detection through containment, eradication and recovery while continuously improving our detection capabilities.
Key responsibilities
- Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private‑cloud platform and enterprise services.
- Perform triage and investigation of security events, acting as the senior technical decision point on genuine incidents.
- Investigate EDR and NDR alerts involving malware, credential theft, lateral movement, ransomware and other compromises.
- Own the full incident‑response lifecycle: identification, containment, eradication, recovery and post‑incident review.
- Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams.
- Lead cross‑team response efforts to ensure timely investigation, escalation and resolution.
- Develop, maintain and improve incident‑response playbooks and standard operating procedures.
- Create, tune and optimise Splunk correlation searches, alerts, dashboards and SPL queries.
- Reduce alert fatigue by tuning noisy detections and lowering false‑positive rates.
- Support onboarding of new log sources, validate log quality and manage Cribl Stream/Edge pipelines for log routing.
Required profile
- Hands‑on practitioner with deep technical knowledge of security operations.
- Senior escalation point and mentor for less‑experienced analysts.
- Comfortable working across virtualised and containerised infrastructure, including OpenStack and Red Hat OpenShift.
- Strong analytical and problem‑solving abilities.
- Excellent collaboration skills with platform, infrastructure, network and application teams.
Required skills
- Splunk (SIEM) and SPL query language.
- Cribl Stream/Edge for log pipeline management.
- Elastic Security (EDR) and Corelight (NDR).
- OpenStack and Red Hat OpenShift environments.
- Incident response lifecycle management.
- Log source onboarding, parsing, field extraction and normalization.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Arab Emirates.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 3 weeks from now
25 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Core42
Dubai