SIEM Engineer L3
DXC Technology- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
DXC Technology | United Arab Emirates | On-site Senior Analyst
Function: Cyber Security – Managed Detection & Response
Job Summary
DXC Technology is seeking an experienced SIEM Engineer – L3 to engineer, administer, optimize, and support enterprise SIEM capabilities within a complex Managed Detection & Response (MDR) environment in the UAE.
The role will provide advanced technical support for security monitoring and detection capabilities, with a strong focus on SIEM engineering, log source onboarding, detection content, platform integrations, performance optimization, and L3 troubleshooting.
Key Responsibilities
- Engineer, configure, administer, maintain, and optimize enterprise SIEM platforms supporting SOC/MDR operations.
- Onboard security and operational log sources across endpoints, servers, networks, security devices, applications, databases, identity platforms, and cloud environments.
- Configure and troubleshoot collectors, agents, connectors, APIs, parsers, normalization, and data ingestion pipelines.
- Develop and tune correlation rules, detection use cases, alerts, dashboards, reports, and threat monitoring content.
- Map detection use cases against MITRE ATT&CK techniques and relevant threat scenarios.
- Integrate SIEM with SOAR, EDR/XDR, IAM/PAM, threat intelligence, vulnerability management, network security, and cloud security platforms.
- Provide L3 troubleshooting for complex SIEM platform, ingestion, parsing, integration, performance, and data-quality issues.
- Support SOC/MDR analysts during advanced investigations, threat hunting, and major security incidents.
- Optimize detection coverage and alert quality while reducing false positives and detection gaps.
- Monitor SIEM platform health, capacity, availability, and performance and support upgrades and technical improvements.
- Collaborate with SOC analysts, detection engineers, threat intelligence, incident response, and infrastructure teams.
- Maintain accurate technical documentation for log sources, integrations, configurations, detection rules, and operational procedures.
Required Experience
- 7+ years of cybersecurity experience, including strong hands-on SIEM engineering, administration, or implementation experience.
- Strong experience with enterprise SIEM technologies such as Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, Google Security Operations/Chronicle, or equivalent.
- Hands-on experience with log onboarding, parsing, normalization, correlation, data ingestion, and troubleshooting.
- Experience developing and tuning SIEM correlation rules, detection logic, alerts, dashboards, and security use cases.
- Strong understanding of SOC/MDR operations, incident response, threat detection, threat hunting, and MITRE ATT&CK.
- Experience integrating SIEM with multiple enterprise security technologies and cloud environments.
- Working knowledge of query or scripting languages such as KQL, SPL, AQL, YARA-L, Python, or PowerShell.
- Strong analytical, troubleshooting, and problem-solving capabilities.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related discipline.
- Previous experience supporting a SOC, MDR, MSSP, or large enterprise security monitoring environment.
- Experience with security monitoring across Azure, AWS, or GCP environments.
- UAE/GCC experience is advantageous.
- Certifications such as Microsoft SC-200, Splunk, QRadar, GIAC, Security+, CySA+, or equivalent are preferred.
Join DXC Technology and contribute to strengthening enterprise threat detection and Managed Detection & Response capabilities in the UAE.
More Info
Key Skills
detection logic
SIEM engineering
security use cases
log onboarding
Splunk Enterprise Security
data ingestion
Microsoft Sentinel
KQL
MITRE ATT CK
YARA-L
correlation rules
Google Security Operations Chronicle
threat detection
SOC MDR operations
Correlation
Alerts
