SOC L1 Analyst – SIEM Integration (Emirati National Only)
Job Summary
The SOC L1 Analyst (SIEM Integration Focus) supports realtime security monitoring log ingestion validation and firstlevel incident triage. The role blends SOC operations with SIEM onboarding and data quality assurance to strengthen enterprise threat visibility.
This position is exclusively open to Emirati Nationals supporting national workforce development and compliance requirements.
Monitor SIEM dashboards alerts and correlation rules for potential security incidents.
Validate log ingestion from firewalls IDS/IPS EDR/XDR servers cloud platforms IAM and network devices.
Support onboarding of new log sources using Syslog API agents connectors and event hubs.
Assist in maintaining parsers field extractions normalization rules and basic detection use cases.
Perform firstlevel triage: classify alerts escalate incidents and document findings.
Troubleshoot ingestion issues such as missing fields timestamp errors duplicate logs and parsing failures.
Coordinate with SOC L2/L3 security architects and infrastructure teams for issue resolution.
Ensure critical telemetry is available for investigations and threat monitoring.
Maintain documentation for integration procedures onboarding checklists and runbooks.
Understanding of SIEM architecture log flow and event correlation.
Experience with SIEM platforms such as Microsoft Sentinel Splunk QRadar ArcSight LogRhythm Elastic Security.
Familiarity with security log types: Windows Event Logs Linux syslog firewall/proxy logs AD logs cloud audit logs EDR telemetry.
Basic handson experience with log parsing regex JSON/XML formats syslog protocols and REST APIs.
Foundational knowledge of MITRE ATT&CK incident response detection engineering and threat monitoring.
Understanding of TCP/IP DNS HTTP/HTTPS VPN authentication protocols and IAM concepts.
Ability to analyze ingestion issues and support correlation troubleshooting.
Exposure to cloud SIEM integrations (AWS Azure GCP).
Familiarity with SOAR workflows.
Understanding of compliance logging requirements (ISO 27001 PCIDSS HIPAA GDPR).
Experience creating basic detections or use cases.
Exposure to threat intelligence feed integration.
Awareness of SIEM retention storage and licensing considerations.
Bachelors degree in Computer Science Cybersecurity IT or related field.
14 years of experience in SOC SIEM operations or log management.
Relevant certifications (advantage):
Microsoft Sentinel
Splunk Core
QRadar
Security / CySA
Opportunity to grow from SOC L1 to L2/L3 roles.
Handson exposure to enterprise SIEM integrations and detection engineering.
Supportive environment for Emirati talent development in cybersecurity.
Required Skills:
Enrolled in or recent graduate of a degree/diploma in Computer Science Information Technology or related field Fundamental understanding of operating systems networking and cloud-based services Strong problem-solving mindset with a passion for helping others Excellent written and verbal communication skills in English Self-motivated organized and able to thrive in a fully remote environment Basic knowledge of ticketing systems (e.g. Zendesk Freshdesk) is a plus
Required Education:
Enrolled in or recent graduate of a degree/diploma in Computer Science Information Technology or related field