Senior Engineer SOC (SIEM)

🏢 CPX Affiliate
📍 Abu Dhabi, United Arab EmiratesFull-timeOn-site
📅 Posted: Today🔄 Updated: Today
CV%
✨ AI Summary
The Senior Engineer SOC (SIEM) role is critical for managing SIEM services within the Security Operations Center, primarily focusing on Splunk SIEM and Splunk UEBA. Responsibilities include onboarding log sources, optimizing telemetry, system updates, troubleshooting, and maintaining SIEM performance. The engineer will also contribute to SIEM architecture improvements and deployments. This position requires a Bachelor's degree in a relevant field, a minimum of 5 years of experience in SOC operations with Splunk SIEM expertise, and strong technical and communication skills. The role offers a salary of AED 20,000 - AED 21,000 per month for a 1-year extendable contract, with an immediate or maximum 1-month notice period.
Required Skills
Other
GIACSPL Search Processing Language
Information Technology
Solution ArchitectureAzureCloud ArchitectureNIST
Requirements
Requires a Bachelor's degree in computer science, Information Technology, or Cybersecurity. Must have at least 5 years of experience in SOC operations, with significant experience in Splunk SIEM management. Key skills include Splunk Certified Administrator, mastery of SPL, scripting (Python, Bash, PowerShell), and cloud/security certifications like CISSP, AWS, Azure, or Google Cloud. Excellent communication and documentation skills are essential.
Description
Important Note: -Given the urgency of this position, the recruitment process has been accelerated. Interviews are progressing actively, with all candidate assessments expected to be completed over the next two weeks.Title - Senior Engineer – SOC (SIEM)Important Information:Only candidates who meet the below criteria and are genuinely interested in the opportunity are encouraged to apply. Applications that do not align with the specified requirements may not be considered.Salary - AED 20,000 - AED 21,0000 per monthDuration - 1 year (can be extendable)Required Notice Period -Immediate or max 1 monthEducation - Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.Mandate Requirement:-Skills/Certifications (Technical & Non-Technical)Splunk Certified Administrator.Mastery of SPL (Search Processing Language) for complex queries, dashboards, and reports.Scripting skills (Python, Bash, PowerShell)Cloud-related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.Certified Information Systems Security Professional (CISSP), GIAC is preferred.Excellent communication and documentation skillsAbility to lead technical initiatives and work independentlyMinimum Work ExperienceA minimum of 5 years of experience in SOC operations, with significant experience in Splunk SIEM management.Prior experience in a technical role within a SOC or similar cybersecurity environment.The Senior SOC Engineer is responsible for managing SIEM services within the Security Operations Center, with a primary focus on Splunk SIEM and Splunk UEBA. This role involves onboarding new log sources, optimizing telemetry, ensuring system updates, troubleshooting issues, and maintaining SIEM performance. Additionally, the engineer will support SIEM architecture improvements and deployments aligned with business requirements.Key Responsibilities: Manage Splunk SIEM services within the SOC environment.Implement scalable Splunk-based SIEM solutions following best practices.Define data ingestion strategies, parsing logic, and correlation rules.Onboard new log sources and ensure proper integration with Splunk SIEM.Monitor and maintain critical log sources; troubleshoot and resolve issues promptly.Optimize telemetry for improved data collection, correlation, and reporting.Collaborate with SOC and threat intelligence teams to develop detection use cases.Create dashboards, alerts, and reports for proactive threat monitoring.Perform system updates, version upgrades, and feature rollouts.Ensure CIM compliance, field extractions, and data normalization.Maintain SIEM performance and troubleshoot Splunk-related issues.Evaluate and deploy Splunk apps and add-ons as needed.Document SIEM workflows, configurations, and operational procedures.Support continuous process improvements to enhance SOC efficiency. Work cross-functionally with IT, DevOps, and security teams.Characteristics: Profound knowledge and hands-on experience with Splunk SIEM, UEBA and other related technologies like CRIBL.Understanding of SOC workflows, MITRE ATT&CK framework, and threat detection methodologies.Ability to correlate data across multiple sources to identify patterns and anomalies.Strong understanding of cloud and network technologies, essential for efficient log source onboarding.Proven technical capabilities in a complex, fast-paced SOC environment.Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.Strong understanding of SOC operations, cybersecurity principles, and best practices.Excellent problem-solving skills and the ability to make decisions under pressure.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00