Senior SOC Analyst
On-siteDubai, Dubai, United Arab Emirates
Job Summary
Hunt proactively across infrastructure, cloud, identity, and endpoint using hypotheses rather than waiting for alerts. Build, tune, and maintain detections mapped to real attacker TTPs, and push back on tuning decisions that trade visibility for noise reduction. Own incidents end to end, triaging, containing, and reporting root causes to drive actual fixes. Partner with Red Team on purple-team exercises to turn findings into detections, and extend monitoring coverage into the AI agent stack to catch prompt injection and credential exposure. Perform malware analysis and reverse engineering to understand threats beyond sandbox reports, while mentoring junior analysts.
Required Qualifications
- 6+ years in a SOC, threat hunting, or DFIR role
- real incident ownership
- Real depth in at least three of: EDR internals and endpoint telemetry, cloud security monitoring (AWS/GCP), network forensics, malware analysis, SIEM and detection-as-code, identity threat hunting
- Comfortable writing your own detection logic and tooling in Python or a proper query language
- You think like an attacker when you write a detection
- You know the difference between reducing noise and creating a blind spot
- You can write a report that gets fixed
Desired Qualifications
- GCFA, GCIH, GCIA, or equivalent DFIR/detection engineering credential
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.