HamburgerMenu
hirist

Security Operations Lead - SIEM Tools

Good Co
8 - 15 Years
Overseas/International

Posted on: 04/08/2026

Job Description

Roles & Responsibilities :

- Lead and manage the Security Operations Center (SOC) function, ensuring 24x7 monitoring, detection, investigation, and response to cybersecurity incidents.

- Own the operational security posture by managing threat detection, incident response, vulnerability management, and security monitoring processes.

- Develop and maintain SOC processes, playbooks, escalation procedures, and incident response workflows aligned with industry standards.

- Lead a team of security analysts, engineers, and incident responders; provide mentoring, coaching, and performance management.

- Monitor and analyze security alerts from SIEM, EDR, IDS/IPS, firewalls, cloud security platforms, and other security tools.

- Drive incident investigations, root cause analysis, containment, remediation, and post-incident reviews.

- Manage threat intelligence operations, including identifying emerging threats, indicators of compromise (IOCs), and attack patterns.

- Improve SOC maturity through automation, SOAR implementation, process optimization, and operational metrics.

- Define and track SOC KPIs/KRIs, including incident response time, detection effectiveness, false positives, and threat trends.

- Collaborate with infrastructure, cloud, application, and compliance teams to strengthen security controls.

- Support security audits, regulatory compliance requirements, and risk assessments.

- Ensure alignment with cybersecurity frameworks such as ISO 27001, NIST CSF, MITRE ATT&CK, and industry best practices.

- Coordinate with external vendors, managed security service providers (MSSPs), and incident response partners when required.

- Prepare executive-level security reports, dashboards, and risk updates for senior management.

Preferred Candidate Profile:

- Experience: 815 years of experience in cybersecurity, with significant experience leading SOC operations, incident response, or security monitoring teams.

- Proven experience managing a SOC team in an enterprise environment, preferably in UAE/GCC markets.

- Strong hands-on experience with:

1. SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, LogRhythm, or similar

2. EDR/XDR solutions: CrowdStrike, SentinelOne, Microsoft Defender, Palo Alto Cortex, etc.

3. Threat intelligence and security analytics platforms

4. Vulnerability management tools

5. Cloud security monitoring (Azure/AWS/GCP)

- Strong understanding of:

1. Security incident lifecycle management

2. Threat hunting methodologies

3. Malware analysis fundamentals

4. Network security concepts

5. Identity and access management (IAM)

6. Security architecture and controls

- Experience developing SOC processes, operational procedures, and automation workflows.

- Ability to lead investigations involving advanced persistent threats (APTs), phishing, ransomware, and insider threats.

- Strong stakeholder management skills with the ability to communicate security risks to technical and business leadership.

- Experience working with compliance and regulatory requirements such as ISO 27001, NIST, PCI-DSS, GDPR, UAE regulatory frameworks, or similar.

Preferred Certifications :

- CISSP (Certified Information Systems Security Professional)

- CISM (Certified Information Security Manager)

- GIAC certifications (GCIH, GCIA, GCFA, etc.)

- OSCP / OSCE

- CEH (preferred but not mandatory)

- CCSP / Azure Security Engineer / AWS Security Specialty

- ISO 27001 Lead Auditor / Lead Implementer

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...