📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

This job is no longer available

This job expired on 06/09/2026. It no longer accepts applications.

Security Operations Analyst (L3 Incident Analyst)

Core42 · Abou Dabi

Senior 🇬🇧 English
Splunk SPL Cribl Elastic Security Corelight OpenStack Red Hat OpenShift Incident response Detection engineering

Job description

About the role

Core42 is seeking a senior Incident Analyst (L3) to lead its 24×7 Security Operations Center in Abu Dhabi. The analyst will own the full lifecycle of security incidents on the company’s private‑cloud platform, from detection in Splunk to containment, eradication and recovery.

Key responsibilities

  • Monitor security alerts and events in Splunk, identifying threats, anomalies and malicious activity across the private‑cloud platform and enterprise services.
  • Perform triage and deep investigation of security events, acting as the senior technical decision point.
  • Serve as the L3 escalation point for L1/L2 analysts, providing guidance and validating findings.
  • Investigate EDR and NDR alerts involving malware, credential theft, lateral movement, ransomware and other compromises.
  • Own incidents end‑to‑end, coordinating containment, remediation and post‑incident review with platform, infrastructure, network and application teams.
  • Develop and maintain incident response playbooks, SOPs and improve them after major incidents.
  • Create, tune and optimise Splunk correlation searches, dashboards and SPL queries to enhance detection quality and reduce alert fatigue.

Required profile

  • Hands‑on senior security analyst with extensive experience in incident response and SOC environments.
  • Proven ability to mentor junior analysts and act as an escalation point.
  • Comfort working with virtualised and containerised infrastructures such as OpenStack and Red Hat OpenShift.

Required skills

  • Splunk (SIEM) and SPL query language
  • Cribl data pipeline
  • Elastic Security (EDR)
  • Corelight (NDR)
  • OpenStack
  • Red Hat OpenShift
  • Incident response lifecycle and playbook development
  • Detection engineering and threat hunting

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Core42.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Arab Emirates.

💬 Chat with us on Telegram Chat on WhatsApp

Published 2 months ago

52 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Core42

Abou Dabi