Expert Engineer/Security Operation Centre
منذ 6 ساعات
abu dhabi, الإمارات العربية المتحدة
Forensic Focus
دوام كامل
مجانًا عبر البريد الإلكتروني أو Google
احفظ هذه الوظيفة وحافظ على تنظيم بحثك
قم بإنشاء حساب مجاني لحفظ الوظائف وإنشاء التنبيهات والعودة إلى هذه القائمة من لوحة التحكم الخاصة بك.
مجانًا عبر البريد الإلكتروني أو Google
بالمتابعة، فإنك توافق على الشروط & سياسة الخصوصية.
# Expert Engineer/Security Operation Centre*e& UAE*Abu Dhabi, Abu Dhabi EmirateOnsite
· Senior
· Full-time### The RoleThe position sits within a security operations centre and covers end-to-end forensic investigations and incident response. Day-to-day work includes host-based and network forensics, malware triage, threat hunting using MITRE ATT&CK, cloud IR across AWS and Azure, and producing high-quality reports for technical and non-technical stakeholders while meeting SLA requirements.### Skills & ExperienceCandidates need at least six years of DFIR experience with strong hands-on use of EnCase, FTK, Cellebrite, Oxygen and Volatility, plus SIEM platforms such as Sentinel and Splunk. SANS certifications — particularly GCFA, GCFE and GCIH — are required, alongside KQL query writing, Python or PowerShell scripting, and familiarity with Docker or Kubernetes.### Who It SuitsThis role suits an experienced DFIR practitioner who thrives in high-pressure SOC environments, is equally comfortable conducting deep host-level investigations and cloud forensics, and can clearly communicate complex findings to diverse audiences. Those with broad investigation exposure beyond EDR and SIEM tooling will be particularly well placed.
· Senior
· Full-time### The RoleThe position sits within a security operations centre and covers end-to-end forensic investigations and incident response. Day-to-day work includes host-based and network forensics, malware triage, threat hunting using MITRE ATT&CK, cloud IR across AWS and Azure, and producing high-quality reports for technical and non-technical stakeholders while meeting SLA requirements.### Skills & ExperienceCandidates need at least six years of DFIR experience with strong hands-on use of EnCase, FTK, Cellebrite, Oxygen and Volatility, plus SIEM platforms such as Sentinel and Splunk. SANS certifications — particularly GCFA, GCFE and GCIH — are required, alongside KQL query writing, Python or PowerShell scripting, and familiarity with Docker or Kubernetes.### Who It SuitsThis role suits an experienced DFIR practitioner who thrives in high-pressure SOC environments, is equally comfortable conducting deep host-level investigations and cloud forensics, and can clearly communicate complex findings to diverse audiences. Those with broad investigation exposure beyond EDR and SIEM tooling will be particularly well placed.