Summary
This role serves as the primary technical and operational Subject Matter Expert (SME) for Automation, Integration, and Playbook development, collaborating with multiple teams to ensure successful outcomes.
Main Responsibilities:
- Provide technical and thought leadership, optimizing processes and systems.
- Support pre-sales, sales, and business development for new and existing services.
- Collaborate with internal peers and external stakeholders to implement and deliver cyber defense services.
- Assist in the Service Transition process, ensuring smooth transitions for customers and infrastructure into operations.
- Work proactively and collaboratively with peers for mutually beneficial outcomes.
- Support the detection, mitigation, containment, and response to cyber security incidents through effective integration and capabilities of assets.
- Create, optimize, and document processes, procedures, and workflows; track and report SLAs, KPIs, and OLAs.
- Initiate, support, and manage incidents, problems, risks, and compliance activities; available 24/7 as needed.
Key Requirements:
- Degree in Computer Science, Information Systems, Electrical Engineering, or a related field.
- Depth of skills in at least three areas: Security Controls Operations, Cyber Incident Response, Cyber Security Detection, Managed Services Integration, Cyber Threat Intelligence, Threat Hunting.
- 4+ years experience in PAN Cortex XSOAR (Demisto SOAR).
- Working Knowledge of Cyber Threats, Threat Actors, TTPs and how to mitigate threats in different contexts (on-prem, cloud, distributed).
- ITIL Accreditation (or relevant experience).
- Expert skills across SIEM, NGFW, CTI, WAF, plus O365 and service management tools.
- Experience in the design, implementation, maintenance and optimization of custom Playbooks for the detection, protection, containment, and mitigation of Cyber security related threats and incidents.
- Strong scripting and integration skills, in languages such as Python, GO, Kusto/KQL, PowerShell.
- Expert skills in Information Security Technologies (e.g., SIEM, NGFW, CTI, WAF) as well as IT systems, including Office 365, Service Management Tools, and the interfaces provided by IT & security systems that can be used for integration, automation, and orchestration.
- Certifications: Mandatory (PCSAE OR PCSE)
Other Details:
- Location: Abu Dhabi - UAE
- Team Structure: Collaboration with Cyber Defense, Platforms & Architecture, and Managed Controls teams.