Hey everyone,
We are looking to fill three open security positions in the UAE. For all three roles, the budget is 15,000 – 18,000 AED, and we need candidates who can start on a 30 day notice period.
Company: Dell
Contract: Full time
Salary: 15k to 18k
How to Apply: Please send your CV at [amin@infraassure.com](mailto:amin@infraassure.com) or [sales05@infraassure.com](mailto:sales05@infraassure.com)
Here are the details for each role:
- SOC Analyst L2
Overview
We're looking for a sharp SOC L2 Analyst to join the Dell Security Operations Center. You'll be the key link between our L1 monitors and the L3 threat hunting/IR teams. This role is all about deep-dive incident investigation and threat analysis, so you'll need solid analytical chops and hands-on experience with security tooling.
Responsibilities
- Take charge of complex security alerts escalated by the L1 team.
- Investigate and tackle incidents like malware, phishing, and unauthorized access.
- Connect the dots across various tools (SIEM, EDR, NDR) to spot attack patterns.
- Drive incident response steps: containment, eradication, and recovery support.
- Dig into logs across cloud environments, network devices, servers, and endpoints.
- Proactively hunt for threats using the latest intelligence feeds.
- Tweak and improve SIEM alerting and correlation rules.
- Write up clear incident reports and root cause analyses (RCA).
- Escalate the highly complex incidents to L3 or DFIR teams when needed.
- Work closely with IT and network teams to fix vulnerabilities.
Required Skills
- Solid background in a SOC environment at the L2 level.
- Hands-on skills with major SIEMs (Splunk, Microsoft Sentinel, QRadar).
- Experience using EDR/XDR solutions (CrowdStrike, Defender, SentinelOne).
- Strong grasp of network protocols (DNS, TCP/IP, HTTP/S) and common attack methods (ransomware, lateral movement, privilege escalation).
- Familiarity with the MITRE ATT&CK framework and NIST/ISO incident response lifecycles.
- Proven ability to correlate events and analyze logs.
- A good handle on Windows and/or Linux security basics.
- Basic scripting skills (Bash, Python, or PowerShell).
Preferred Skills
- Relevant industry certifications (e.g., Security+, CySA+, CEH, GIAC GCIH/GCIA) or vendor certs for Splunk/Sentinel.
- Hands-on experience with SOAR platforms (Cortex XSOAR, Splunk SOAR) and Threat Intel platforms (MISP, ThreatConnect).
- Familiarity with cloud security monitoring across AWS, Azure, or GCP.
- Background in utilizing advanced email security and phishing analysis tools.
- Unix/Linux DFIR Analyst
Overview
we are looking for a Linux/Unix DFIR specialist to join our cybersecurity squad. You'll be our go-to person for investigating security incidents and running deep forensic analysis specifically on Unix/Linux systems to figure out root causes, contain threats, and prevent them from coming back.
Responsibilities
- Drive the full incident response lifecycle (detection to recovery) for our Linux/Unix environments.
- Run both host-based and network-based forensics on Linux systems.
- Scour system logs, secure logs, and audit trails for indicators of compromise (IOCs).
- Perform advanced disk and memory forensics using standard industry tools.
- Lead threat hunting missions within our Linux infrastructure.
- Document all forensic findings, write up incident reports, and suggest remediation steps.
- Team up with SOC and Threat Intel to resolve active incidents.
- Build out forensic playbooks, procedures, and automation scripts.
- Help out with analyzing Linux-based malware when required.
- Ensure evidence handling and chain of custody procedures are strictly followed.
Required Skills
- Extensive hands-on experience with UNIX/Linux OS (Ubuntu, RHEL, CentOS, etc.).
- Proven track record in Digital Forensics and Incident Response (DFIR).
- Deep knowledge of Linux internals, file systems (XFS, ext3/4), and process management.
- Strong handle on logging mechanisms (syslog, auth.log, auditd).
- Comfortable using forensic toolkits like Sleuth Kit/Autopsy, and memory tools like Volatility/Rekall.
- Strong understanding of network protocols, attack vectors, and intrusion techniques.
- Knowledge of the MITRE ATT&CK framework and SIEM tools (Sentinel, QRadar, Splunk).
- Scripting abilities in Python, Bash, or similar.
Preferred Skills
- Core forensics or Linux certifications (GIAC GCFA/GCFE/GCIA, CEH, CHFI, or RHCSA/RHCE).
- Experience securing and monitoring Linux workloads in cloud environments (AWS, Azure, GCP).
- Exposure to major EDR/XDR platforms (CrowdStrike, SentinelOne, Defender).
- Understanding of container security (Docker, Kubernetes).
- Proven ability to maintain a cool head and communicate clearly during high-pressure, active incidents.
- Telecom DFIR Analyst
Overview
We need an experienced Telecom DFIR Analyst to help secure our telecom environments. This role is a unique blend of hardcore digital forensics and deep telecom knowledge (like 4G/5G, SS7, and IMS). You'll be investigating cyber incidents targeting core networks, signaling systems, and subscriber data platforms.
Responsibilities
- Run incident response operations across our telecom infrastructure, including Core, RAN, IMS, and OSS/BSS.
- Conduct digital forensics on network elements and telecom-specific IT platforms.
- Analyze signaling traffic (SIP, SS7, Diameter) to spot abuse and malicious activity.
- Investigate telecom-specific fraud cases like SIM swapping, roaming fraud, and call interception.
- Dig into logs from critical telecom nodes (MME, HLR/HSS, PCRF/PCF, SBC, MSC).
- Track down IOCs and map telecom threat techniques to the MITRE ATT&CK framework.
- Hunt for threats proactively across the telecom network.
- Work hand-in-hand with fraud management, network engineering, and SOC teams.
- Write up detailed forensic documentation, playbooks, and executive incident reports.
- Maintain strict chain of custody for legal and regulatory compliance.
Required Skills
- Strong professional background in Digital Forensics and Incident Response (DFIR).
- Deep understanding of telecom architectures, specifically 4G/5G Core (EPC/5GC), IMS, and RAN fundamentals.
- Practical experience analyzing telecom protocols (Diameter, SS7, SIP).
- Ability to parse and analyze logs from MME/AMF, HLR/HSS, and PCRF/PCF.
- Familiarity with common telecom threat vectors and fraud scenarios.
- Experience with SIEM platforms and network traffic analysis tools (like tcpdump or Wireshark).
- Solid grasp of the Linux/Unix systems that power telecom environments.
- Scripting experience (Bash, Python, etc.).
Preferred Skills
- Prior background working within telecom fraud management or telecom security operations teams.
- Industry security certs (GIAC GCFA/GCIA/GNFA, CEH, CHFI) or vendor-specific telecom security certifications (Ericsson, Huawei, Nokia).
- Exposure to 5G security architectures and network slicing concepts.
- Knowledge of cloud-native telecom infrastructure (SDN, NFV, Kubernetes).
- Familiarity with GSMA security frameworks and guidelines (like FS.11 or NESAS).
- Experience utilizing NDR and EDR/XDR tools in complex environments.
Source: r/UAEjobseekers · by /u/Appropriate-Pay-1401