Senior SOC Analyst – Managed Security Services
Location:
UAE / Middle East (On‑site / Shift‑based)
Employment type:
Full‑time
Department:
Managed Security Services – SOC
Experience:
3‑6 years (SOC / Security Operations)
Reports to:
SOC Team Lead
ITHR Technologies Consulting LLC is a technology consulting and professional services organisation supporting enterprises across the UAE and Middle East with digital transformation, cybersecurity, ERP implementation, talent solutions, managed services, and custom application development. Our cybersecurity practice offers Managed SOC, Digital Forensics & Incident Response (DFIR), Vulnerability Assessment & Penetration Testing (VAPT), Network Security, Brand Protection, Security Advisory, and Managed Security Services.
Our Managed SOC delivers 24/7 threat monitoring, detection, and response to customers across the region. As we expand our portfolio, we seek an experienced Senior SOC Analyst to strengthen our Security Operations Centre and deliver high‑quality threat detection, investigation, and incident response services.
We are looking for a technically strong and experienced Senior SOC Analyst to join the ITHR Security Operations team. This hands‑on L3‑level role involves owning complex alert investigations, leading incident response activities, conducting proactive threat hunting, and continuously improving detection capabilities across customer environments. As a senior SOC member, you will act as the escalation point for junior analysts, contribute to playbook development, and maintain quality and consistency of SOC deliverables, including customer reporting and post‑incident documentation.
Key Responsibilities- Perform in‑depth triage, investigation, and analysis of security alerts across multiple customer SIEM environments.
- Act as the L3 escalation point for complex or high‑severity incidents escalated by L1/L2 analysts.
- Lead incident response activities including containment, eradication, recovery, and post‑incident review.
- Conduct proactive threat hunting using MITRE ATT&CK, threat intelligence, and customer‑specific risk profiles.
- Develop and tune SIEM detection rules, correlation logic, and alert thresholds.
- Develop and maintain SOC runbooks and incident response playbooks.
- Produce high‑quality incident reports suitable for both technical and business audiences.
- Integrate and ope rationalise threat intelligence including IOCs, TTPs, and threat actor profiles.
- Investigate activity across EDR, network, identity, cloud, and application log sources.
- Mentor and guide L1 and L2 analysts through technical coaching and case reviews.
- Support customer onboarding including log source validation, baseline reviews, and detection use case configuration.
- Participate in shift handovers ensuring complete transfer of active investigations and operational awareness.
- 3‑6 years of hands‑on SOC or Security Operations experience.
- Minimum 1‑2 years operating at an L2/L3 level.
- Strong experience performing alert triage, incident investigation, and response.
- MSSP experience highly desirable.
- Hands‑on experience with one or more SIEM platforms:
Microsoft Sentinel, Splunk, IBM QRadar, Elastic SIEM. - Experience with EDR solutions including:
Crowd Strike Falcon, Sentinel One, Microsoft Defender for Endpoint. - Strong understanding of MITRE ATT&CK.
- Solid knowledge of TCP/IP, DNS, HTTP/S, firewalls, proxies, and network attack techniques.
- Experience analysing Windows and Linux artefacts: event logs, process trees, registry, persistence mechanisms, scheduled tasks.
- Excellent documentation and customer reporting skills.
- Must possess at least one mandatory certification listed below.
- Blue Team Level 2 (BTL2)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- CompTIA CASP+
- Blue Team Level 1 (BTL1)
- Microsoft SC-200 Security Operations Analyst
- EC‑Council Certified SOC Analyst (CSA)
- CompTIA CySA+
- GIAC Cyber Threat Intelligence (GCTI)
- MSSP or multi‑tenant SOC experience.
- Experience with SOAR platforms such as Microsoft Sentinel SOAR, Palo Alto XSOAR, or Splunk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).