About the Role
We are seeking an experienced Cyber Security Engineer with deep expertise in SIEM (Security Information and Event Management) solutions to join our security operations team in Doha, Qatar. This role focuses on designing, implementing, and optimizing enterprise-grade SIEM platforms to strengthen threat detection, incident response, and compliance posture across a large-scale infrastructure. The ideal candidate will have a proven track record of deploying SIEM in complex, multi-site environments and will play a critical role in advancing our security monitoring capabilities.
Key Responsibilities
- Design, deploy, and maintain SIEM solutions (e.g., Splunk, QRadar, LogRhythm, Microsoft Sentinel) across hybrid cloud and on-premise environments
- Develop and tune correlation rules, use cases, and dashboards for real-time threat detection and alerting
- Integrate log sources from firewalls, endpoints, servers, cloud platforms (AWS, Azure, GCP), identity systems, and applications
- Lead incident response investigations using SIEM analytics, threat intelligence feeds, and forensic data
- Collaborate with SOC analysts to reduce false positives, improve mean time to detect (MTTD) and mean time to respond (MTTR)
- Automate enrichment, triage, and response workflows using SOAR platforms or custom scripting (Python, PowerShell)
- Ensure SIEM coverage aligns with regulatory frameworks (NIA, QCB, GDPR, ISO 27001) and internal compliance requirements
- Conduct regular health checks, performance tuning, and capacity planning for SIEM infrastructure
- Mentor junior engineers and document architecture, runbooks, and detection logic
Requirements
- Minimum 3 years of hands-on experience designing and implementing SIEM solutions in large enterprise environments
- Expert-level knowledge of at least one major SIEM platform: Splunk, IBM QRadar, LogRhythm, Elastic, or Microsoft Sentinel
- Strong understanding of log ingestion pipelines, parsing, normalization, and data modeling (CIM, ASIM, OCSF)
- Proficiency in writing complex correlation searches, SPL/KQL/Regex, and building detection logic for MITRE ATT&CK techniques
- Experience with cloud security logging (AWS CloudTrail, GuardDuty, Azure Activity Logs, GCP Audit Logs)
- Solid grasp of network protocols, Windows/Linux internals, Active Directory, and common attack vectors
- Scripting/automation skills in Python, PowerShell, or Bash for SIEM administration and SOAR integration
- Relevant certifications: Splunk Certified Admin/Architect, GCFA, GCIA, CISSP, or equivalent highly valued
- Fluent in English; Arabic language proficiency is a strong advantage for the Qatar market
Preferred Qualifications
- Experience with SOAR platforms (Palo Alto Cortex XSOAR, Splunk SOAR, FortiSOAR)
- Background in threat hunting, purple teaming, or red team collaboration
- Familiarity with Qatar's National Information Assurance (NIA) framework and Qatar Central Bank (QCB) cybersecurity guidelines
- Previous work experience in the GCC region or with multinational organizations operating in Qatar
- Knowledge of OT/ICS security monitoring and industrial SIEM use cases