Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Company Description
Dynova is an all-in-one cybersecurity service for startups and growing companies across the UAE and GCC, delivered via a virtual CISO on a monthly subscription model. Instead of fragmented security purchases, Dynova provides end-to-end ownership of security outcomes, with vCISOs directing priorities and engineers implementing controls, continuous penetration testing, and 24/7 SOC operations.
Role Overview
We are looking for an experienced Senior SOC Analyst to join our Cyber Defence function. The role will be responsible for advanced security monitoring, incident investigation and response, threat hunting, detection improvement, and supporting junior SOC analysts.
The successful candidate should have strong hands-on experience investigating security incidents across endpoints, identity, cloud, network, and application environments and be comfortable taking ownership of incidents from initial detection through containment and remediation.
Key Responsibilities
Monitor, investigate, and respond to security alerts and incidents across SIEM, EDR/XDR, email security, identity, cloud, network, and application platforms.
Perform Tier 2/Tier 3 investigation and escalation for complex security incidents.
Conduct incident triage, determine scope and impact, identify root cause, and recommend containment and remediation actions.
Perform threat hunting using SIEM, EDR/XDR, threat intelligence, and other security telemetry.
Analyze suspicious authentication activity, malware, phishing, endpoint events, network activity, cloud events, and potential account compromise.
Develop and improve SIEM detection rules, correlation rules, queries, dashboards, and alerting logic.
Map detection and investigation activities against the MITRE ATT&CK framework.
Identify false positives and work with security engineering teams to improve detection quality.
Support incident response activities, evidence collection, investigation timelines, and post-incident reviews.
Create and maintain SOC playbooks, SOPs, escalation procedures, and investigation guides.
Coordinate with IT, Cloud, DevOps, Application Security, IAM, and other teams during security incidents.
Mentor junior SOC analysts and review escalated investigations.
Support vulnerability, threat intelligence, and security monitoring activities.
Produce incident reports, SOC metrics, management reports, and security trend analysis.
Participate in an on-call / 24x7 SOC operating model where required.
Required Experience & Skills
4–7+ years of cybersecurity experience, with significant hands-on SOC/incident response experience.
Strong experience with enterprise SIEM platforms, preferably Elastic Security, Microsoft Sentinel, Splunk, or similar.
Strong experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, Cortex XDR, or equivalent.
Strong understanding of:
Windows and Linux security
Microsoft Entra ID / Active Directory
AWS and/or Azure security logs
Network security and common protocols
Email security and phishing investigations
IAM and authentication attacks
Experience investigating compromised accounts, malware, suspicious PowerShell, lateral movement, privilege escalation, and cloud security events.
Ability to write and analyze queries using KQL, ES|QL, EQL, Lucene, SPL, or similar query languages.
Good understanding of MITRE ATT&CK and common attacker TTPs.
Strong incident documentation and stakeholder communication skills.
Willingness to work in shifts
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.