Lead SOC Engineer (SIEM)
CPX
Date: 1 day ago
City: Abu Dhabi
Contract type: Full time

Job Purpose
The SOC Senior Engineer, Splunk, is a critical role responsible for delivering SIEM /SOAR management services, particularly focusing on Splunk, within the Security Operations Center (SOC). Working closely with the SOC Principal Engineer, SIEM, this role encompasses onboarding new log sources, enhancing and optimizing telemetry, ensuring system updates, resolving issues, and maintaining SIEM performance according to best practices. Reporting to the Senior SOC Engineering & Architecture Manager, the SOC Senior Engineer, Splunk, is a professional with a solid foundation in SOC operations.
Job Responsibilities
Key Focus Areas
Key Activities
Key Responsibilities:
Skills/Certifications (Technical & Non-Technical)
The SOC Senior Engineer, Splunk, is a critical role responsible for delivering SIEM /SOAR management services, particularly focusing on Splunk, within the Security Operations Center (SOC). Working closely with the SOC Principal Engineer, SIEM, this role encompasses onboarding new log sources, enhancing and optimizing telemetry, ensuring system updates, resolving issues, and maintaining SIEM performance according to best practices. Reporting to the Senior SOC Engineering & Architecture Manager, the SOC Senior Engineer, Splunk, is a professional with a solid foundation in SOC operations.
Job Responsibilities
Key Focus Areas
Key Activities
Key Responsibilities:
- Deliver Splunk SIEM /SOAR management services within the SOC environment.
- Collaborate with the SOC Principal Engineer, SIEM, in onboarding new log sources to the SIEM/SOAR platform.
- Maintain and govern SOC critical log sources, ensuring their proper functionality and integration with Splunk SIEM /SOAR.
- Detect log source issues, coordinate with customers to diagnose and resolve them in a timely manner.
- Enhance and optimize telemetry within the Splunk environment to improve data collection, correlation, and reporting.
- Perform regular system updates to ensure Splunk functionality and security are up to date.
- Resolve Splunk-related issues promptly and efficiently.
- Maintain the performance of the Splunk SIEM /SOAR according to established best practices.
- Participate in continuous process improvements to increase SOC efficiency and effectiveness.
- Provide regular and accurate reports on Splunk services and SOC operations to relevant stakeholders.
- Contribute to SOC architecture strategy and implementation initiatives related to Splunk.
- Assist in the mentorship and development of junior SOC engineers.
- Profound knowledge and hands-on experience with Splunk SIEM/SOAR and other related technologies like CRIBL.
- Strong understanding of cloud and network technologies, essential for efficient log source onboarding.
- Proven technical capabilities in a complex, fast-paced SOC environment.
- Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.
- Strong understanding of SOC operations, cybersecurity principles, and best practices.
- Excellent problem-solving skills and the ability to make decisions under pressure.
- Ability to collaborate effectively with a variety of team members, including interfacing with customers to resolve issues.
- High proficiency in written and verbal communication
Skills/Certifications (Technical & Non-Technical)
- Certified Information Systems Security Professional (CISSP), preferred.
- Certified Information Security Manager (CISM), preferred.
- Splunk Certified Architect or Splunk Certified Administrator.
- Cloud-related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.
- Networking certifications such as CCNA or CCNP are advantageous.
- A minimum of 6 years of experience in SOC operations, with significant experience in Splunk SIEM management.
- Prior experience in a technical role within a SOC or similar cybersecurity environment.
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Environmental Health & Safety Professional - Excellent Opportunity for Emirati Fresh Graduates - Dubai or Abu Dhabi, UAE
Siemens,
Abu Dhabi
2 hours ago
Environmental Health & Safety Professional – Excellent Career Opportunity for Emirati NationalsLocation: Dubai or Abu Dhabi, UAEWe empower our people to stay resilient and relevant in a constantly evolving world. We’re looking for people who are always searching for creative ways to grow and learn. People who want to make a real impact, now and in the future. Does that...

Admissions Assistant
International Schools Partnership Limited,
Abu Dhabi
6 hours ago
Admissions Assistant Role ProfilePurpose of RoleThe Admissions Assistant will be a true ambassador of the School, providing a professional and highly focused customer-service approach. As a representative of the School, the post holder will also work to develop links and partnerships with the parent, businesses, and local community contacts to support mutual development and growth whilst raising the profile and...

Store Manager - Abu Dhabi
Apparel Group,
Abu Dhabi
9 hours ago
Job DescriptionPOSITION OBJECTIVE Achieve company objectives, ensuring the highest levels of customer service are provided by retail staff and ensure they have the skills and support required for maximizing sales Implement operating procedures at the store as per the company and Brand standards Promote the Loyalty Program of the company for maximizing loyalty and repeat sales Provide feedback to the...
