Cloud Security & SIEM Engineer (SOC)
On-siteDubai, Dubai, United Arab Emirates
Job Summary
Monitor and protect workloads across AWS, Microsoft Azure, and Google Cloud Platform by identifying misconfigurations, excessive permissions, and insecure network exposure. Integrate cloud security telemetry with SIEM platforms like Securonix, Microsoft Sentinel, and Splunk to develop detection rules, correlate alerts, and investigate suspicious authentication attempts, compromised identities, and unauthorized access. Automate security operations using Python, PowerShell, or Bash to streamline log parsing, enrichment, and incident response workflows. Support cloud network segmentation, Zero Trust initiatives, and compliance audits while maintaining audit-ready documentation and log retention policies.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline
- 3–8 years of relevant experience in cybersecurity, cloud security, SIEM engineering, or Security Operations Centre environments
- Practical experience with at least one major cloud provider: AWS, Microsoft Azure, or Google Cloud Platform
- Strong understanding of IaaS, PaaS, and SaaS security responsibilities
- Working knowledge of cloud shared-responsibility models
- Hands-on knowledge of identity and access management, RBAC, least privilege, MFA, and privileged-access monitoring
- Experience with cloud network security concepts, including VPCs, virtual networks, security groups, firewalls, segmentation, and Zero Trust
- Experience with at least one enterprise SIEM platform, preferably Securonix, Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM
- Experience integrating cloud logs into a SIEM through native connectors, APIs, or agents
- Knowledge of cloud audit, authentication, network, DNS, and activity logs
- Experience investigating cloud security alerts and supporting incident-response activities
- Working knowledge of Python, PowerShell, or Bash
- Strong analytical, troubleshooting, and documentation skills
- Ability to work independently in a fast-paced, onsite SOC environment
- Candidates who are currently available in the UAE or able to join immediately
Desired Qualifications
- Multi-cloud security experience across AWS, Azure, and GCP
- Experience monitoring Kubernetes and container environments, including AKS, EKS, and ECS
- Knowledge of Terraform, CloudFormation, or Bicep
- Experience with AWS Lambda, Amazon EventBridge, or Azure Logic Apps
- Familiarity with cloud security posture management and cloud workload protection platforms
- Experience creating SIEM detection rules, use cases, dashboards, and automated response playbooks
- Understanding of MITRE ATT&CK techniques relevant to cloud environments
- Knowledge of PCI DSS, HIPAA, ISO 27001, NIST, CIS Benchmarks, or other recognised security frameworks
- Experience supporting compliance audits and log-retention requirements
- Exposure to threat hunting and behavioural anomaly detection in cloud environments
- Certified Cloud Security Professional – CCSP
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
- Microsoft Security Operations Analyst – SC-200
- Relevant SIEM Administrator or SIEM Engineer certification
- Other recognised cloud security or SOC certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.