Overview
The Security Engineer/SOC Lead acts as the onsite operational security focal point, coordinating monitoring, incident response, and remediation with a shared SOC. The role involves managing security alerts, maintaining incident records, and tracking technical security risks across infrastructure and cloud environments.
Full job description
Act as the onsite operational security focal point, coordinating security monitoring, incident response, technical remediation and reporting with shared SOC. Policy ownership, regulatory accountability and risk acceptance remain with the Entity.
• Coordinate security monitoring, alert triage and escalation with the shared SOC and relevant technical teams.
• Lead operational response to confirmed security incidents in accordance with approved procedures and authority.
• Collect and preserve technical evidence and maintain incident records, timelines and action tracking.
• Coordinate containment, remediation, recovery and post-incident reviews with stakeholders.
• Support security logging, SIEM integration, use-case tuning and monitoring coverage assessments.
• Track technical security risks and remediation dependencies across infrastructure, network, cloud and applications.
• Provide operational security reporting and support agreed awareness, exercise or readiness activities.
• Escalate policy, compliance and risk-acceptance decisions to the authorised Entity function.
Requirements
Minimum Experience and Qualifications
• Minimum 5 years of cybersecurity operations, SOC or incident-response experience.
• Practical experience with SIEM platforms such as Splunk, QRadar or equivalent.
• Strong knowledge of security monitoring, incident handling, network/endpoint telemetry and threat analysis.
• Security+, CEH, GCIA or equivalent certification preferred.
• Strong written reporting, stakeholder coordination and evidence-handling capability.
Preferred Profile
• Previous experience supporting UAE government or regulated security environments.
• Working knowledge of TDRA security, hosting and incident coordination processes.
• Arabic language capability for onsite stakeholder coordination.
Expected Contribution
• Security events are escalated and coordinated within the confirmed response procedures.
• Incident evidence, decisions, actions and dependencies remain traceable.
• The shared SOC and onsite teams operate with clear ownership and handoffs.
• Policy and risk decisions are not assumed without Entity authority.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Imported from freehire's public, keyless open-job API after the index reported the posting open. The upstream record supplied this canonical employer, ATS, or official public-board URL; repost-only sources and protected portal URLs are excluded. No login, CAPTCHA, private candidate data, or protected job-board session was accessed.
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
BlackStone eIT Careers (Workable) ↗Browse current Job and Scholarship listings from BlackStone eIT Careers (Workable) →