This job has been added to your Saved jobs.
You have reached the limit of 20 Saved Jobs. If you want to create a new one, please manage your Saved Jobs.
Security Engineer (Defense) - Relocate to Dubai (UAE)
Top 3 reasons to join us
- Competitive salary with housing & living support
- Collaborate with team of diverse nationalities
- Opportunity to become a key member in UAE team
Job description
Position Overview
The Detection & Response Engineer combines detection engineering and incident-response functions in a single role. The incumbent will author and tune high-fidelity detections, harden security baselines and lead critical incident response engagements from containment through root-cause analysis. Success is measured by the velocity and quality of rule promotion, reduced false positives, rapid mean-time-to-respond, and shortened detection windows for emerging TTPs.
Core Responsibilities
1. Detection Engineering
• Author, refine, and promote SIEM/XDR analytics using Sigma, KQL, and SPL.
• Develop and maintain parsers/ETL pipelines; normalise telemetry across Windows, M365/OAuth, AWS, and Azure logs.
• Operate a test harness to replay attack chains and quantify false-positive / false-negative rates before production release
2. Security Baseline Hardening
• Implement and update security controls via IaC (Terraform, CloudFormation, Ansible).
• Drive configuration compliance for operating systems, identity platforms, and cloud services.
3. Incident Response (P1 Lead)
• Serve as primary responder for Priority-1 incidents: containment, scoping, eradication, and recovery.
• Produce detailed timelines, root-cause analyses, and lessons-learned reports.
4. Continuous Audit, Improvement & Governance
• Conduct periodic audits to benchmark compliance coverage
• Promote rules through formal change-control processes, including peer review and rollback plans.
• Measure and report FP/FN statistics; collaborate with Purple Team to prioritise coverage gaps and new TTPs.
5. Threat Research & Replay
• Integrate threat-intel feeds; lead replay exercises to verify detection efficacy against new vulnerabilities and adversary techniques.
• Publish internal knowledge articles to disseminate findings and guidance.
Your skills and experience
Required Qualifications
- Proficiency in Sigma, Kusto Query Language (KQL), and Splunk Processing Language (SPL).
- Demonstrated experience parsing Windows eventing, M365/OAuth, and AWS/Azure telemetry.
- Hands-on DFIR triage: memory, disk, and network artefact acquisition and analysis.
- Competence with IaC or configuration-management tooling (Terraform, CloudFormation, Ansible, or equivalent).
- Fluency in at least one scripting language (Python, PowerShell, or Bash) for automation.
- Excellent written and verbal communication skills for executive and technical audiences.
Preferred Credentials
- GIAC Certified Detection Analyst (GCDA)
- GIAC Certified Incident Handler (GCIH)
Microsoft SC-200, AWS Security Specialty, or equivalent cloud-security certification
Why you'll love working here
We go the extra mile to ensure your experience working onsite in the UAE is seamless, rewarding, and enriching:
• Flexible Work Hours: Enjoy a balanced lifestyle with a 6-hour workday, from 10:00 AM to 5:00 PM, including a 1-hour lunch break.
• 30 Days of Paid Leave: Accumulate your annual 30-day leave for longer holidays, travel adventures, or quality time with family.
• Flight Benefits: We provide a round-trip flight to Dubai when you onboard, plus two return flights to Vietnam each year so you can stay close to home while building a global career.
• Supported Living: We take care of your accommodation and support daily living expenses to ensure a comfortable, stress-free experience from day one. Our team will support you every step of the way.
• Visa & Legal Assistance: We sponsor your visa and handle all required legal procedures, giving you peace of mind throughout the relocation process.
• Modern Central Office: Our office is in the heart of vibrant Dubai, with easy access to metro lines, shopping malls, green parks, and world-class amenities.
• Onsite Support: You’ll have the ongoing support of our HR and admin teams, dedicated to helping you settle in and thrive — both professionally and personally.
________________________________________
If you’re passionate about taking your tech career to an international stage — we’d love to hear from you.
Virtual Security Lab Cyber Risk Management Services L.L.C