BlackStone eIT

Security Engineer / SOC Lead

BlackStone eIT Dubai, Dubai, United Arab Emirates

IT Services and IT Consulting · 1,001-5,000 employees

12 h ago
security Senior (5-10 yrs) Full-time United Arab Emirates
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will act as the onsite focal point for coordinating security monitoring, incident response, and technical remediation with the shared SOC. They are responsible for maintaining incident records, tracking security risks, and providing operational reporting to stakeholders.

What they look for

Security Monitoring Incident Response SIEM Splunk QRadar Threat Analysis Network Telemetry Endpoint Telemetry Risk Management Compliance Technical Remediation Security Reporting Stakeholder Coordination Evidence Handling Cloud Security

Requirements

Candidates must have at least 5 years of experience in cybersecurity operations, SOC, or incident response. Proficiency with SIEM platforms and strong knowledge of network/endpoint telemetry are required, with relevant certifications like Security+, CEH, or GCIA preferred.

Full description

Act as the onsite operational security focal point, coordinating security monitoring, incident response, technical remediation and reporting with shared SOC. Policy ownership, regulatory accountability and risk acceptance remain with the Entity.

•     Coordinate security monitoring, alert triage and escalation with the shared SOC and relevant technical teams.

•     Lead operational response to confirmed security incidents in accordance with approved procedures and authority.

•     Collect and preserve technical evidence and maintain incident records, timelines and action tracking.

•     Coordinate containment, remediation, recovery and post-incident reviews with stakeholders.

•     Support security logging, SIEM integration, use-case tuning and monitoring coverage assessments.

•     Track technical security risks and remediation dependencies across infrastructure, network, cloud and applications.

•     Provide operational security reporting and support agreed awareness, exercise or readiness activities.

•     Escalate policy, compliance and risk-acceptance decisions to the authorised Entity function.

Minimum Experience and Qualifications•     Minimum 5 years of cybersecurity operations, SOC or incident-response experience.

•     Practical experience with SIEM platforms such as Splunk, QRadar or equivalent.

•     Strong knowledge of security monitoring, incident handling, network/endpoint telemetry and threat analysis.

•     Security+, CEH, GCIA or equivalent certification preferred.

•     Strong written reporting, stakeholder coordination and evidence-handling capability.

Preferred Profile•     Previous experience supporting UAE government or regulated security environments.

•     Working knowledge of TDRA security, hosting and incident coordination processes.

•     Arabic language capability for onsite stakeholder coordination.

Expected Contribution•     Security events are escalated and coordinated within the confirmed response procedures.

•     Incident evidence, decisions, actions and dependencies remain traceable.

•     The shared SOC and onsite teams operate with clear ownership and handoffs.

•     Policy and risk decisions are not assumed without Entity authority.

Similar roles