وصف الوظيفة
وصف الوظيفة – مهندس أمان السحابة و SIEM (SOC) المسمى الوظيفي: مهندس أمان السحابة و SIEM قسم: مركز عمليات الأمن (SOC) الموقع: دبي، الإمارات العربية المتحدة نوع التوظيف: دائم، بدوام كامل ترتيب العمل: حضوراً ميداناً الخبرة المطلوبة: 3–8 سنوات (مستوى متوسط) تاريخ الانضمام: الأفضلية للمقبلين فوراً دور عام نحن نبحث عن مهندس أمان سحابة و SIEM ماهر للانضمام إلى مركز عمليات الأمن لدى عميلنا في دبي.
سيكون المرشح الناجح مسؤولاً عن تأمين بيئات السحابة، ودمج التيلما الأمني للسحابة مع منصات SIEM، ومراقبة نشاط السحابة، والتحقيق في أحداث الأمن، وأتمتة عمليات الأمن.
يتطلب الدور خبرة عملية عبر AWS، Microsoft Azure، أو Google Cloud Platform، إلى جانب معرفة قوية بدمج SIEM، وتسجيل البيانات السحابية الأصلية، وإدارة الهوية والوصول، وأمن الشبكات، وأتمتة الأمن.
يجب أن يكون المرشح المثالي قادرًا على ترجمة نشاط السحابة إلى قدرات مراقبة أمنية قابلة للتنفيذ، واكتشاف، وتحري، واستجابة.
المسؤوليات الأساسية عمليات أمان السحابة رصد وحماية أحمال العمل والخدمات المستضافة عبر AWS وMicrosoft Azure وGoogle Cloud Platform.
تطبيق مبادئ أمان السحابة عبر بيئات IaaS وPaaS وSaaS.
فهم وتنفيذ ضوابط الأمان بناءً على نموذج المسؤولية المشتركة لكل مزود سحابة.
التعرف على إخفاقات إعدادات أمان السحابة، والأذونات المفرطة، وكشف الشبكة غير الآمن، وغيرها من مخاطر الأمن.
دعم تنفيذ وتحسين مستمر لمعايير أمان السحابة، والضوابط، وإجراءات التشغيل.
المساعدة في تقييمات أمان السحابة، ومراجعات المخاطر، وأنشطة التصحيح.
إدارة الهوية والوصول تنفيذ ومراجعة التحكم في الوصول القائم على الأدوار ونماذج الوصول الأقل امتيازاً.
رصد الحسابات المميزة، وحسابات الخدمات، وأنشطة المصادقة، وتغييرات الأذونات.
دعم تطبيق المصادقة متعددة العوامل وضوابط الوصول المشروطة.
التحقيق في محاولات المصادقة المشبوهة، وتصعيد الامتياز، وهويات مخترقة، ووصول غير مصرح به.
إجراء مراجعات دورية للأدوار والسماحات وسياسات الوصول.
أمان الشبكات السحابية رصد وتأمين شبكات السحابة، بما في ذلك VPCs والشبكات الافتراضية والشبكات الفرعية ومجموعات الأمان والجدران النارية وقواعد التوجيه، وقيود وصول الشبكة.
مراجعة سجلات تدفق VPC والشبكات الافتراضية لتحديد نشاط شبكي مشبوه أو غير مصرح به.
دعم تقسيم الشبكة السحابية ومبادرات الأمان النزيه الصفري.
المساعدة في تأمين الاتصالات بين السحابة والأنظمة المحلية والبيئات الهجينة.
التحقيق في التهديدات المعتمدة على الشبكة، والمرور غير العادي، والاتصالات غير المصرح بها، والموارد السحابية المكشوفة.
دمج وارتقاء SIEM وواجهات المراقبة دمج خدمات السحابة وتيلميت الأمن مع منصات SIEM مثل: Securonix وMicrosoft Sentinel وSplunk وIBM QRadar وElastic SIEM
إعداد والحفاظ على موصلات أصلية للسحابة وتكاملات مبنية على واجهة API وتغذية سجلات بالعمل عن طريق العAgents.
استقبال والتحقق وتطبيع وفحص مصادر سجلات السحابة.
تطوير وتحسين قواعد الكشف وقواعد الترابط ولوحات المعلومات والتنبيهات والتقارير واستفسارات التحقيق.
ضمان أن تُجمع سجلات أمان السحابة بشكل صحيح وتُفكك وتُصنف وتُغنى وتُحتفظ بها.
رصد إخفاقات الاستيعاب وفجوات البيانات ومشاكل التحليل وتغييرات حجوم السجلات غير الطبيعية.
تسجيل الدخول والسحابة وتحليلها تكوين ومراقبة AWS CloudWatch وAWS CloudTrail وAzure Monitor وسجلات النشاط في Azure وخدمات التسجيل الأصلية ذات الصلة.
جمع وتحليل السجلات الأمنية ذات الصلة، بما في ذلك: نشاط API والإدارة، سجلات المصادقة والوصول، سجلات تدفق VPC والشبكة، سجلات DNS، سجلات الجدار الناري ومجموعات الأمان، سجلات التدقيق والتغيير في التكوين، سجلات الحاويات والتنسيق، سجلات AKS وEKS وECS.
إجراء تحليل السجلات واستخراج الحقول وتصنيف الأحداث والتصفية والتشفير والتغذية بالبيانات.
تحديد نشاط غير اعتيادي وشذوذ سلوكي باستخدام تحليلات SIEM وأدوات الرصد الأصلية للسحابة.
الحفاظ على تغطية تسجيل كافية لدعم المراقبة الأمنية والتحقيقات ومتطلبات التدقيق.
اكتشاف الحوادث الأمنية والاستجابة رصد وتصنيف تنبيهات أمان السحابة الناتجة عن SIEM ومنصات أمان أصلية سحابياً.
التحقيق في النشاط المشبوه، وهويات مخترقة، ووصول غير مصرح به، وتغييرات إعدادات السحابة، واحتمالية تعريض البيانات.
تحديد شدة الحادث ونطاقه وتأثيره على الأعمال وجذر المشكلة.
التصعيد وفق إجراءات SOC والجدول الزمني للاستجابة.
دعم الاحتواء والتخفيف والتعافي وأنشطة المراجعة ما بعد الحادث.
توثيق نتائج التحقيق والأدلة والإجراءات والتوصيات.
المساهمة في تطوير كتيبات استجابة للحوادث للحالة السحابية وحالات الاستخدام.
الأتمتة ونشر السحابة الآمن تطوير سكريبتات باستخدام Python أو PowerShell أو Bash لأتمتة الأمن وتحليل السجلات وتغذيتها والتحقق والتحقيق.
أتمتة عمليات SOC وأمان السحابة المتكررة حيثما أمكن.
استخدام أدوات البنية كرمز مثل Terraform وAWS CloudFormation وAzure Bicep لدعم نشرات سحابية آمنة.
مراجعة قوالب البنية كرمز للمخاطر الأمنية وضعف التكوين.
تطوير سير عمل أمني باستخدام خدمات مثل: AWS Lambda وAmazon EventBridge وAzure Logic Apps وخدمات الأتمتة والتنسيق الأصلية للسحابة.
دعم تعزيز الإنذار الآلي والإخطار والاحتواء والتعافي وسير العمل فيما يتعلق بالتصحيح.
الامتثال والحوكمة دعم سياسات الاحتفاظ بالسجلات والتأكد من حماية سجلات الأمان من التعديل أو الحذف غير المصرح به.
الحفاظ على أدلة جاهزة للتدقيق تتعلق بالوصول إلى السحابة والنشاط الإداري وأحداث الأمان وتحقيقات الحوادث.
دعم متطلبات الامتثال المرتبطة بالأطر والمعايير المعمول بها، بما في ذلك PCI DSS وHIPAA عند الاقتضاء.
الحفاظ على وثائق تقنية وإجراءات أمان السحابة وسجلات الدمج ودليل التشغيل.
المشاركة في عمليات التدقيق والتقييم الأمني واختبار الضوابط بشكل دوري.
المؤهلات والخبرة المطلوبة درجة البكالوريوس في الأمن السيبراني أو تكنولوجيا المعلومات أو علوم الحاسوب أو الهندسة أو تخصص ذي صلة.
3–8 سنوات من الخبرة ذات الصلة في الأمن السيبراني، أمان السحابة، هندسة SIEM، أو بيئات مركز عمليات الأمن.
خبرة عملية مع مزود سحابة واحد على الأقل: AWS أو Azure أو Google Cloud Platform.
فهم قوي لمسؤوليات أمان IaaS وPaaS وSaaS.
معرفة عملية بنماذج المسؤولية المشتركة للسحابة.
معرفة عملية بإدارة الهوية والوصول والRBAC والحد الأدنى من الامتياز و MFA ورصد الوصول المميز.
خبرة بمفاهيم أمان الشبكات السحابية، بما في ذلك VPCs والشبكات الافتراضية والمناطق والشِدادات وجدران الحماية والتقسيم وZero Trust.
خبرة مع منصة SIEM مؤسسية على الأقل، ويفضل Securonix وMicrosoft Sentinel وSplunk وIBM QRadar أو Elastic SIEM.
خبرة في دمج سجلات السحابة في SIEM من خلال موصلات أصلية أو واجهات برمجة تطبيقات أو وكلاء.
معرفة بسجلات التدقيق المصادقة والشبكة وDNS والنشاط.
خبرة في التحقيق في تنبيهات أمان السحابة ودعم استجابات الحوادث.
معرفة عملية بـ Python أو PowerShell أو Bash.
قدرات تحليلية قوية وحل مشكلات وتوثيق فعال.
القدرة على العمل بشكل مستقل في بيئة SOC ميدانية سريعة الإيقاع.
المهارات المفضلة خبرة أمن سحابي متعددة عبر AWS وAzure وGCP.
خبرة رصد بيئات Kubernetes والحاويات، بما في ذلك AKS وEKS وECS.
معرفة بـ Terraform أو CloudFormation أو Bicep.
خبرة مع AWS Lambda وAmazon EventBridge أو Azure Logic Apps.
الاطلاع على إدارة وضع الأمان في السحابة ومنصات حماية أعباء العمل السحابية.
خبرة في إنشاء قواعد كشف SIEM وحالات الاستخدام ولوحات المعلومات وسير العمل الآلي للاستجابة.
فهم تقنيات MITRE ATT&CK المتعلقة بالبيئات السحابية.
معرفة بـ PCI DSS وHIPAA وISO 27001 وNIST وCIS Benchmarks أو أطر أمان معترف بها أخرى.
خبرة في دعم تدقيق الامتثال ومتطلبات الاحتفاظ بالسجلات.
تعرض لاستطلاع الصيادين والبحث عن الشذوذ السلوكي في بيئات السحابة.
الشهادات المفضلة أي من الشهادات التالية ستكون مفيدة: Certified Cloud Security Professional – CCSP AWS Certified Security – Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Microsoft Security Operations Analyst – SC-200 شهادة SIEM Administrator أو SIEM Engineer ذات صلة شهادات معتمدة أخرى في أمان السحابة أو SOC المهارات الأساسية أساسيات أمان السحابة وSOC التفكير التحليلي والتحري ربط أحداث الأمن وتحليل السجلات أولوية الحوادث والاستجابة نهج قائم على الأتمتة دقة الملاحظات توثيق تقني واضح والتنسيق مع أصحاب المصلحة القدرة على إدارة الحوادث الأمنية في ظروف زمنية دقيقة ملف المرشح المفضل هو محترف أمان سحابي متمرس مع خبرة عملية في SIEM وSOC.
يجب أن يكون الفرد قادرًا على إدراج مصادر سجلات السحابة، وتطوير حالات مراقبة، والتحقيق في أحداث أمان السحابة، وأتمتة أنشطة الأمان التشغيلية.
سيكون المفضلين في الإمارات أو القادرين على الانضمام فوراً مفضلين.
Job description
Job Description – Cloud Security & SIEM Engineer (SOC) Job Title: Cloud Security & SIEM Engineer Department: Security Operations Centre (SOC) Location: Dubai, UAE Employment Type: Permanent, Full-Time Work Arrangement: Onsite Experience Required: 3–8 years (Mid-Level) Joining Date: Immediate joiners preferred Role Summary We are seeking a skilled Cloud Security & SIEM Engineer to join our client’s Security Operations Centre in Dubai.
The successful candidate will be responsible for securing cloud environments, integrating cloud security telemetry with SIEM platforms, monitoring cloud activity, investigating security events, and automating security operations.
The role requires hands-on experience across AWS, Microsoft Azure, or Google Cloud Platform, along with strong knowledge of SIEM integration, cloud-native logging, identity and access management, network security, and security automation.
The ideal candidate should be able to translate cloud activity into actionable security monitoring, detection, investigation, and response capabilities.
Key Responsibilities Cloud Security Operations Monitor and protect workloads and services hosted across AWS, Microsoft Azure, and Google Cloud Platform.
Apply cloud security principles across IaaS, PaaS, and SaaS environments.
Understand and implement security controls based on the shared responsibility model of each cloud provider.
Identify cloud security misconfigurations, excessive permissions, insecure network exposure, and other security risks.
Support the implementation and continuous improvement of cloud security standards, controls, and operational procedures.
Assist with cloud security assessments, risk reviews, and remediation activities.
Identity and Access Management Implement and review role-based access control and least-privilege access models.
Monitor privileged accounts, service accounts, authentication activities, and permission changes.
Support the enforcement of multi-factor authentication and conditional access controls.
Investigate suspicious authentication attempts, privilege escalation, compromised identities, and unauthorised access.
Conduct periodic reviews of cloud roles, permissions, and access policies.
Cloud Network Security Monitor and secure cloud networks, including VPCs, virtual networks, subnets, security groups, firewalls, routing rules, and network access controls.
Review VPC and virtual network flow logs to identify suspicious or unauthorised network activity.
Support cloud network segmentation and Zero Trust security initiatives.
Assist in securing connectivity between cloud, on-premises, and hybrid environments.
Investigate network-based threats, anomalous traffic, unauthorised connections, and exposed cloud resources.
SIEM Integration and Monitoring Integrate cloud services and security telemetry with SIEM platforms such as: Securonix Microsoft Sentinel Splunk IBM QRadar Elastic SIEM Configure and maintain cloud-native connectors, API-based integrations, and agent-based log ingestion.
Onboard, validate, normalise, and troubleshoot cloud log sources.
Develop and optimise detection rules, correlation rules, dashboards, alerts, reports, and investigation queries.
Ensure that cloud security logs are accurately collected, parsed, classified, enriched, and retained.
Monitor ingestion failures, data gaps, parsing issues, and abnormal log-volume changes.
Cloud Logging and Analysis Configure and monitor AWS CloudWatch, AWS CloudTrail, Azure Monitor, Azure Activity Logs, and related cloud-native logging services.
Collect and analyse security-relevant logs, including: API and administrative activity Authentication and access logs VPC and network flow logs DNS logs Firewall and security-group logs Audit and configuration-change logs Container and orchestration logs AKS, EKS, and ECS logs Conduct log parsing, field extraction, event classification, filtering, masking, and enrichment.
Identify unusual activity and behavioural anomalies using SIEM analytics and cloud-native monitoring tools.
Maintain adequate logging coverage to support security monitoring, investigations, and audit requirements.
Security Incident Detection and Response Monitor and triage cloud security alerts generated by SIEM and cloud-native security platforms.
Investigate suspicious activity, compromised identities, unauthorised access, cloud configuration changes, and potential data exposure.
Determine the severity, scope, business impact, and root cause of cloud security incidents.
Escalate confirmed incidents in accordance with SOC procedures and response timelines.
Support containment, remediation, recovery, and post-incident review activities.
Document investigation findings, evidence, response actions, and recommendations.
Contribute to the development of cloud-specific incident-response playbooks and use cases.
Automation and Secure Cloud Deployment Develop scripts using Python, PowerShell, or Bash for security automation, log parsing, enrichment, validation, and investigation.
Automate repetitive SOC and cloud security processes where appropriate.
Use Infrastructure as Code tools such as Terraform, AWS CloudFormation, and Azure Bicep to support secure cloud deployments.
Review Infrastructure as Code templates for security risks and configuration weaknesses.
Develop security workflows using services such as: AWS Lambda Amazon EventBridge Azure Logic Apps Cloud-native automation and orchestration services Support automated alert enrichment, notification, containment, and remediation workflows.
Compliance and Governance Support log-retention policies and ensure that security logs are protected against unauthorised alteration or deletion.
Maintain audit-ready evidence relating to cloud access, administrative activity, security events, and incident investigations.
Support compliance requirements aligned with applicable frameworks and standards, including PCI DSS and HIPAA where relevant.
Maintain technical documentation, cloud security procedures, integration records, and operational runbooks.
Participate in periodic audits, security assessments, and control-testing activities.
Required Qualifications and Experience Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
3–8 years of relevant experience in cybersecurity, cloud security, SIEM engineering, or Security Operations Centre environments.
Practical experience with at least one major cloud provider: AWS, Microsoft Azure, or Google Cloud Platform.
Strong understanding of IaaS, PaaS, and SaaS security responsibilities.
Working knowledge of cloud shared-responsibility models.
Hands-on knowledge of identity and access management, RBAC, least privilege, MFA, and privileged-access monitoring.
Experience with cloud network security concepts, including VPCs, virtual networks, security groups, firewalls, segmentation, and Zero Trust.
Experience with at least one enterprise SIEM platform, preferably Securonix, Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
Experience integrating cloud logs into a SIEM through native connectors, APIs, or agents.
Knowledge of cloud audit, authentication, network, DNS, and activity logs.
Experience investigating cloud security alerts and supporting incident-response activities.
Working knowledge of Python, PowerShell, or Bash.
Strong analytical, troubleshooting, and documentation skills.
Ability to work independently in a fast-paced, onsite SOC environment.
Preferred Skills Multi-cloud security experience across AWS, Azure, and GCP.
Experience monitoring Kubernetes and container environments, including AKS, EKS, and ECS.
Knowledge of Terraform, CloudFormation, or Bicep.
Experience with AWS Lambda, Amazon EventBridge, or Azure Logic Apps.
Familiarity with cloud security posture management and cloud workload protection platforms.
Experience creating SIEM detection rules, use cases, dashboards, and automated response playbooks.
Understanding of MITRE ATT&CK techniques relevant to cloud environments.
Knowledge of PCI DSS, HIPAA, ISO 27001, NIST, CIS Benchmarks, or other recognised security frameworks.
Experience supporting compliance audits and log-retention requirements.
Exposure to threat hunting and behavioural anomaly detection in cloud environments.
Preferred Certifications Any of the following certifications would be advantageous: Certified Cloud Security Professional – CCSP AWS Certified Security – Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Microsoft Security Operations Analyst – SC-200 Relevant SIEM Administrator or SIEM Engineer certification Other recognised cloud security or SOC certifications Key Competencies Strong cloud security and SOC fundamentals Analytical and investigative thinking Security-event correlation and log analysis Incident prioritisation and response Automation-oriented approach Attention to detail Clear technical documentation Effective communication and stakeholder coordination Ability to manage security incidents under time-sensitive conditions Candidate Profile The preferred candidate is a hands-on cloud security professional with practical SIEM and SOC experience.
The individual should be capable of onboarding cloud log sources, developing monitoring use cases, investigating cloud security events, and automating operational security activities.
Candidates who are currently available in the UAE or able to join immediately will be given preference.