All open roles
IT outsourcingUrgent
Cybersecurity and Managed Security
محلل مركز العمليات الأمنية، المستوى الثاني
You will work the second line of a 24 by 7 security operations centre in Abu Dhabi, serving clients in energy, financial services and government-adjacent sectors. Tier 1 triages. You investigate. When an alert turns out to be real, you are the person who determines scope, contains it and briefs the client.
Abu DhabiOnsiteFull timeMid
What you will do
- Investigate escalated security alerts across endpoint, network, identity and cloud telemetry.
- Determine whether an alert is a true positive, establish scope and impact, and drive containment in line with the client's incident response plan.
- Perform threat hunting against current intelligence rather than waiting for alerts.
- Tune detection rules to cut false positives, because alert fatigue is itself a security failure.
- Write incident documentation and client-facing briefings that a non-technical executive can act on.
- Support post-incident review and control improvement.
- Mentor Tier 1 analysts.
What you bring
- At least three years in a SOC or incident response role, with at least one year at second line or above.
- Hands-on command of a SIEM such as Microsoft Sentinel, Splunk or QRadar, and of EDR tooling.
- Real understanding of attacker behaviour mapped to MITRE ATT and CK.
- Ability to read logs and reconstruct a timeline.
- English at C1 for client reporting, Arabic at B1 or above helpful for local client interaction.
- Willingness to work twelve hour rotating shifts.
Nice to have
- Certification such as GCIH, GCIA, CySA+ or OSCP.
- Cloud security depth in Azure or AWS.
- Scripting for automation.
- Experience with OT or ICS environments in energy.
What we offer
- Four on four off shift pattern, which gives real recovery time.
- Shift allowance on top of base salary.
- Funded certification pathway.
- Employment visa and medical insurance in line with UAE law.
- Progression into threat hunting, detection engineering, incident response lead and SOC management.
How the process works
Apply on this page. The first step takes under two minutes. Every application gets a response from our talent team.
Apply
Apply for this role
The first step takes under two minutes and every application gets a response.
