Skip to content
DnsLister Forum

Where domain hunters compare notes

Hiring for SOC L2 and DFIR Roles

Hey everyone,

We are looking to fill three open security positions in the UAE. For all three roles, the budget is 15,000 – 18,000 AED, and we need candidates who can start on a 30 day notice period.

Company: Dell
Contract: Full time
Salary: 15k to 18k

How to Apply: Please send your CV at [amin@infraassure.com](mailto:amin@infraassure.com) or [sales05@infraassure.com](mailto:sales05@infraassure.com)

Here are the details for each role:

  1. SOC Analyst L2

Overview
We're looking for a sharp SOC L2 Analyst to join the Dell Security Operations Center. You'll be the key link between our L1 monitors and the L3 threat hunting/IR teams. This role is all about deep-dive incident investigation and threat analysis, so you'll need solid analytical chops and hands-on experience with security tooling.

Responsibilities

  • Take charge of complex security alerts escalated by the L1 team.
  • Investigate and tackle incidents like malware, phishing, and unauthorized access.
  • Connect the dots across various tools (SIEM, EDR, NDR) to spot attack patterns.
  • Drive incident response steps: containment, eradication, and recovery support.
  • Dig into logs across cloud environments, network devices, servers, and endpoints.
  • Proactively hunt for threats using the latest intelligence feeds.
  • Tweak and improve SIEM alerting and correlation rules.
  • Write up clear incident reports and root cause analyses (RCA).
  • Escalate the highly complex incidents to L3 or DFIR teams when needed.
  • Work closely with IT and network teams to fix vulnerabilities.

Required Skills

  • Solid background in a SOC environment at the L2 level.
  • Hands-on skills with major SIEMs (Splunk, Microsoft Sentinel, QRadar).
  • Experience using EDR/XDR solutions (CrowdStrike, Defender, SentinelOne).
  • Strong grasp of network protocols (DNS, TCP/IP, HTTP/S) and common attack methods (ransomware, lateral movement, privilege escalation).
  • Familiarity with the MITRE ATT&CK framework and NIST/ISO incident response lifecycles.
  • Proven ability to correlate events and analyze logs.
  • A good handle on Windows and/or Linux security basics.
  • Basic scripting skills (Bash, Python, or PowerShell).

Preferred Skills

  • Relevant industry certifications (e.g., Security+, CySA+, CEH, GIAC GCIH/GCIA) or vendor certs for Splunk/Sentinel.
  • Hands-on experience with SOAR platforms (Cortex XSOAR, Splunk SOAR) and Threat Intel platforms (MISP, ThreatConnect).
  • Familiarity with cloud security monitoring across AWS, Azure, or GCP.
  • Background in utilizing advanced email security and phishing analysis tools.
  1. Unix/Linux DFIR Analyst

Overview
we are looking for a Linux/Unix DFIR specialist to join our cybersecurity squad. You'll be our go-to person for investigating security incidents and running deep forensic analysis specifically on Unix/Linux systems to figure out root causes, contain threats, and prevent them from coming back.

Responsibilities

  • Drive the full incident response lifecycle (detection to recovery) for our Linux/Unix environments.
  • Run both host-based and network-based forensics on Linux systems.
  • Scour system logs, secure logs, and audit trails for indicators of compromise (IOCs).
  • Perform advanced disk and memory forensics using standard industry tools.
  • Lead threat hunting missions within our Linux infrastructure.
  • Document all forensic findings, write up incident reports, and suggest remediation steps.
  • Team up with SOC and Threat Intel to resolve active incidents.
  • Build out forensic playbooks, procedures, and automation scripts.
  • Help out with analyzing Linux-based malware when required.
  • Ensure evidence handling and chain of custody procedures are strictly followed.

Required Skills

  • Extensive hands-on experience with UNIX/Linux OS (Ubuntu, RHEL, CentOS, etc.).
  • Proven track record in Digital Forensics and Incident Response (DFIR).
  • Deep knowledge of Linux internals, file systems (XFS, ext3/4), and process management.
  • Strong handle on logging mechanisms (syslog, auth.log, auditd).
  • Comfortable using forensic toolkits like Sleuth Kit/Autopsy, and memory tools like Volatility/Rekall.
  • Strong understanding of network protocols, attack vectors, and intrusion techniques.
  • Knowledge of the MITRE ATT&CK framework and SIEM tools (Sentinel, QRadar, Splunk).
  • Scripting abilities in Python, Bash, or similar.

Preferred Skills

  • Core forensics or Linux certifications (GIAC GCFA/GCFE/GCIA, CEH, CHFI, or RHCSA/RHCE).
  • Experience securing and monitoring Linux workloads in cloud environments (AWS, Azure, GCP).
  • Exposure to major EDR/XDR platforms (CrowdStrike, SentinelOne, Defender).
  • Understanding of container security (Docker, Kubernetes).
  • Proven ability to maintain a cool head and communicate clearly during high-pressure, active incidents.
  1. Telecom DFIR Analyst

Overview
We need an experienced Telecom DFIR Analyst to help secure our telecom environments. This role is a unique blend of hardcore digital forensics and deep telecom knowledge (like 4G/5G, SS7, and IMS). You'll be investigating cyber incidents targeting core networks, signaling systems, and subscriber data platforms.

Responsibilities

  • Run incident response operations across our telecom infrastructure, including Core, RAN, IMS, and OSS/BSS.
  • Conduct digital forensics on network elements and telecom-specific IT platforms.
  • Analyze signaling traffic (SIP, SS7, Diameter) to spot abuse and malicious activity.
  • Investigate telecom-specific fraud cases like SIM swapping, roaming fraud, and call interception.
  • Dig into logs from critical telecom nodes (MME, HLR/HSS, PCRF/PCF, SBC, MSC).
  • Track down IOCs and map telecom threat techniques to the MITRE ATT&CK framework.
  • Hunt for threats proactively across the telecom network.
  • Work hand-in-hand with fraud management, network engineering, and SOC teams.
  • Write up detailed forensic documentation, playbooks, and executive incident reports.
  • Maintain strict chain of custody for legal and regulatory compliance.

Required Skills

  • Strong professional background in Digital Forensics and Incident Response (DFIR).
  • Deep understanding of telecom architectures, specifically 4G/5G Core (EPC/5GC), IMS, and RAN fundamentals.
  • Practical experience analyzing telecom protocols (Diameter, SS7, SIP).
  • Ability to parse and analyze logs from MME/AMF, HLR/HSS, and PCRF/PCF.
  • Familiarity with common telecom threat vectors and fraud scenarios.
  • Experience with SIEM platforms and network traffic analysis tools (like tcpdump or Wireshark).
  • Solid grasp of the Linux/Unix systems that power telecom environments.
  • Scripting experience (Bash, Python, etc.).

Preferred Skills

  • Prior background working within telecom fraud management or telecom security operations teams.
  • Industry security certs (GIAC GCFA/GCIA/GNFA, CEH, CHFI) or vendor-specific telecom security certifications (Ericsson, Huawei, Nokia).
  • Exposure to 5G security architectures and network slicing concepts.
  • Knowledge of cloud-native telecom infrastructure (SDN, NFV, Kubernetes).
  • Familiarity with GSMA security frameworks and guidelines (like FS.11 or NESAS).
  • Experience utilizing NDR and EDR/XDR tools in complex environments.

Source: r/UAEjobseekers · by /u/Appropriate-Pay-1401

Leave a Reply

Your email address will not be published. Required fields are marked *