SOC / Security Platform Analyst
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security, Information Security & Data Protection
Working Arrangement: Full-time, on-site at client locations
Company: Command Post
About Command PostCommand Post is a cybersecurity and AI technology company delivering advanced security operations, threat intelligence, application security, AI assurance, governance, risk, compliance, and privacy solutions.
We are expanding our regional delivery capability and are seeking a hands-on SOC & Security Platform Analyst to support customer security operations and security technology environments across Qatar and Dubai.
This role is suitable for candidates from either of the following backgrounds:
- An experienced SOC analyst with strong operational, threat-hunting, and incident investigation capabilities.
- A technical security platform engineer with experience deploying, managing, and improving SIEM, SOAR, endpoint security, and security monitoring platforms.
The successful candidate will work on-site within customer environments, supporting day-to-day security operations and the implementation, administration, and optimisation of security monitoring platforms.
The role requires a practical understanding of how security alerts, endpoint telemetry, logs, threat intelligence, detection rules, and automated response workflows come together to support an effective Security Operations Centre.
Candidates do not need to be equally strong across every area. We are interested in experienced SOC practitioners, technical platform engineers, or candidates who combine elements of both disciplines.
Key Responsibilities Security Operations and Incident Investigation- Monitor, triage, investigate, and respond to security alerts and incidents.
- Analyse events from endpoints, networks, cloud services, identity platforms, applications, and security controls.
- Conduct structured investigations to determine incident scope, impact, root cause, and required containment actions.
- Perform proactive threat hunting using indicators, behavioural patterns, attack techniques, and threat intelligence.
- Document investigation findings, evidence, timelines, decisions, and recommended remediation actions.
- Support the development and maintenance of incident response procedures, investigation playbooks, and escalation processes.
- Identify recurring security issues and recommend improvements to controls, monitoring, and operational processes.
- Support customer reporting, operational reviews, and incident briefings.
- Configure, administer, and optimise SIEM and security analytics platforms.
- Support log source onboarding, parsing, normalisation, enrichment, correlation, and data quality validation.
- Develop and maintain detection rules, use cases, alert logic, dashboards, reports, and monitoring workflows.
- Tune security use cases to reduce false positives while maintaining appropriate detection coverage.
- Integrate endpoint, network, cloud, identity, vulnerability, threat intelligence, and application security data sources.
- Support SOAR playbooks, workflow automation, case management, and response orchestration.
- Monitor platform health, ingestion performance, storage, integrations, connectors, and service availability.
- Assist with upgrades, troubleshooting, platform testing, documentation, and operational handover.
- Work with customer infrastructure, security, network, cloud, and application teams to resolve technical issues.
Experience with one or more of the following platforms is highly desirable:
- Palo Alto Cortex XSIAM or XSIEM
- Microsoft Sentinel
- Elastic Stack or ELK
- Open Search
- Log Rhythm
- Arc Sight
- Other enterprise SIEM, SOAR, security analytics, or log-management platforms
Experience in the following areas will also be valuable:
- Endpoint Detection and Response and Extended Detection and Response technologies
- Endpoint protection platforms
- Device and log-source onboarding
- Detection engineering and use-case management
- Security orchestration and automated response
- Dashboard and security reporting development
- Cloud security monitoring
- Identity and access monitoring
- Network security monitoring
- Vulnerability management integrations
- Practical experience working within a SOC, security operations team, managed security service, or security engineering function.
- Strong understanding of security monitoring, alert triage, incident investigation, and escalation processes.
- Working knowledge of common attacker techniques, indicators of compromise, and the MITRE ATT&CK framework.
- Ability to analyse security logs and telemetry from multiple sources.
- Experience with SIEM queries, dashboards, detection rules, correlation logic, or platform administration.
- Understanding of endpoint protection, EDR, XDR, firewalls, identity systems, cloud platforms, and common enterprise infrastructure.
- Ability to investigate technical issues methodically and communicate findings clearly.
- Strong written documentation and customer communication skills.
- Ability to work independently within a customer environment while collaborating with wider…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).