Job Description
Role Overview
The SOC L1 Analyst (SIEM Integration Focus) supports real‑time security monitoring, log ingestion validation, and first‑level incident triage. The role blends SOC operations with SIEM onboarding and data quality assurance to strengthen enterprise threat visibility.
This position is exclusively open to Emirati Nationals, supporting national workforce development and compliance requirements.
Key Responsibilities
Monitor SIEM dashboards, alerts, and correlation rules for potential security incidents.
Validate log ingestion from firewalls, IDS/IPS, EDR/XDR, servers, cloud platforms, IAM, and network devices.
Support onboarding of new log sources using Syslog, API, agents, connectors, and event hubs.
Assist in maintaining parsers, field extractions, normalization rules, and basic detection use cases.
Perform first‑level triage: classify alerts, escalate incidents, and document findings.
Troubleshoot ingestion issues such as missing fields, timestamp errors, duplicate logs, and parsing failures.
Coordinate with SOC L2/L3, security architects, and infrastructure teams for issue resolution.
Ensure critical telemetry is available for investigations and threat monitoring.
Maintain documentation for integration procedures, onboarding checklists, and runbooks.
Requirements
Required Skills & Knowledge
Understanding of SIEM architecture, log flow, and event correlation.
Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, Elastic Security.
Familiarity with security log types: Windows Event Logs, Linux syslog, firewall/proxy logs, AD logs, cloud audit logs, EDR telemetry.
Basic hands‑on experience with log parsing, regex, JSON/XML formats, syslog protocols, and REST APIs.
Foundational knowledge of MITRE ATT&CK, incident response, detection engineering, and threat monitoring.
Understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, authentication protocols, and IAM concepts.
Ability to analyze ingestion issues and support correlation troubleshooting.
Preferred Skills
Exposure to cloud SIEM integrations (AWS, Azure, GCP).
Familiarity with SOAR workflows.
Understanding of compliance logging requirements (ISO 27001, PCI‑DSS, HIPAA, GDPR).
Experience creating basic detections or use cases.
Exposure to threat intelligence feed integration.
Awareness of SIEM retention, storage, and licensing considerations.
Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, IT, or related field.
1–4 years of experience in SOC, SIEM operations, or log management.
Relevant certifications (advantage):
Microsoft Sentinel
Splunk Core
QRadar
Security+ / CySA+
Benefits
Opportunity to grow from SOC L1 to L2/L3 roles.
Hands‑on exposure to enterprise SIEM integrations and detection engineering.
Supportive environment for Emirati talent development in cybersecurity.
Requirements
Enrolled in or recent graduate of a degree/diploma in Computer Science, Information Technology, or related field Fundamental understanding of operating systems, networking, and cloud-based services Strong problem-solving mindset, with a passion for helping others Excellent written and verbal communication skills in English Self-motivated, organized, and able to thrive in a fully remote environment Basic knowledge of ticketing systems (e.g., Zendesk, Freshdesk) is a plus