×
Register Here to Apply for Jobs or Post Jobs. X

SIEM SOAR Detection Engineer

Job in Abu Dhabi, UAE/Dubai
Listing for: Visionary Tech Services
Full Time position
Listed on 2026-03-05
Job specializations:
  • Engineering
    Systems Engineer, Cybersecurity
  • IT/Tech
    Systems Engineer, Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 200000 AED Yearly AED 120000.00 200000.00 YEAR
Job Description & How to Apply Below

Our client is a leading cybersecurity firm establishing a next-generation Security Operations Center (SOC) to deliver world-class monitoring, detection, and incident response capabilities. Built on advanced analytics, automation, and threat intelligence, this SOC is designed to serve as a central pillar of enterprise defense across diverse digital environments. The company is seeking exceptional security professionals to shape, lead, and evolve this capability into a benchmark for operational excellence and resilience.

We are seeking an experienced SOC Automation & Detection Engineer to support the development and enhancement of the SOC's detection and automation capabilities. This role combines detection engineering, SIEM content development, and SOAR workflow automation, enabling consistent and scalable security operations.

The engineer will build and tune analytic rules, optimize SIEM ingestion pipelines, and design automation workflows that streamline triage, enrichment, and response actions. While strong experience with Microsoft Sentinel is required, experience with additional SIEM platforms such as Splunk, QRadar, Elastic, or Log Rhythm is highly valued. The engineer will collaborate closely with Senior Engineers, SOC Analysts, Threat Hunters, and DFIR teams to improve both detection fidelity and operational efficiency.

Key

Skill Areas
  • Automation:
    Azure Logic Apps, SOAR workflows, enrichment logic
Responsibilities
  • Develop and maintain SIEM detection content, alerts, and analytic rules across platforms.
  • Build KQL queries to support alerting, enrichment, investigations, and automated responses.
  • Design, develop, and maintain SOAR automation workflows, including enrichment playbooks and triage automations.
  • Collaborate with the Senior SOC Automation & Detection Engineer to align detection triggers with SOAR workflows.
  • Assist with the onboarding, validation, and optimisation of log sources to support detections and automation.
  • Conduct tuning cycles to reduce false positives and improve detection accuracy.
  • Provide query and analytic support to SOC Analysts during investigations.
  • Document detection logic, automation workflows, lifecycle updates, and engineering procedures.
  • Identify telemetry gaps and propose ingestion and schema improvements.
  • Assist in converting threat intelligence insights and threat hunting findings into detections and playbooks.
Requirements
  • 2-4 years of experience in SIEM engineering, detection development, or security automation.
  • Strong hands‑on experience with Microsoft Sentinel, especially KQL and analytic rule creation.
  • Practical experience building or maintaining SOAR playbooks (Logic Apps preferred).
  • Familiarity with at least one additional SIEM platform (Splunk, QRadar, Elastic, Log Rhythm).
  • Understanding of detection lifecycle management, tuning, and correlation fundamentals.
  • Basic scripting capability (Power Shell or Python).
  • Strong understanding of MITRE ATT&CK and attacker techniques.
  • Certifications such as SC-200, AZ‑500 or similar are beneficial.
Technical Skills
  • Platforms:
    Microsoft Sentinel, Splunk, QRadar, Elastic
  • Automation:
    Azure Logic Apps, SOAR workflows, enrichment logic
  • Analytics: KQL, SIEM rules, correlation logic
  • Telemetry:
    Identity, endpoint, cloud, network logs
  • Scripting:
    Power Shell or Python
  • Frameworks: MITRE ATT&CK
Benefits
  • Build and refine the automation and detection backbone of a modern SOC.
  • Directly influence the efficiency, scalability, and maturity of SOC operations.
  • Work with advanced cloud‑native technologies in a collaborative engineering environment.
  • Clear pathway to senior engineering, threat hunting, or DFIR growth.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary