{"id":1142969,"url":"https://alion.io/job/e-engineerincident-management","title":"Engineer/Incident Management","company":{"id":196,"name":"e&","domain":"eand.com","url":"https://alion.io/company/eand","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"A","score":95,"open_postings":4,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":85,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Abu Dhabi, United Arab Emirates"],"countries":["AE"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":41000,"max_usd":90000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":2457},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DNS","optional":false},{"name":"Incident Management","optional":false},{"name":"Linux","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"SIEM","optional":false},{"name":"Windows","optional":false},{"name":"Wireshark","optional":false}],"status":"closed","first_seen_at":"2026-09-23T11:40:34Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-10-02T00:21:08Z","board_verified":false,"closed_at":"2026-10-02T00:21:08Z","days_open":8,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":8},"description":"We are seeking a technical SOC Specialist with 3-5 years' experience to drive high-level incident response and threat detection within our 24/7 Security Operations Center. This role is responsible for the full incident lifecycle-from initial triage and traffic analysis to host recovery and remediation. The ideal candidate combines deep knowledge of Windows/Linux environments with the ability to design automated SOAR playbooks that enhance our defensive posture.\n Incident Management & Response\nReal-Time Monitoring: Provide continuous 24/7 oversight of security events and alerts.\nTriage & Prioritization: Manage and categorize alerts from SIEM, Anti-DDoS, and other security solutions based on urgency and risk.\nIncident Response Operations: Lead technical response activities, including host triage, containment, and recovery.\nRemediation & Analysis: Conduct remote system analysis and implement remediation efforts using strong correlation skills.\nLifecycle Management: Maintain the full incident response lifecycle and ensure all actions adhere to established SLAs (Service Level Agreements). \nSecurity Automation & Intelligence\nSOAR Optimization: Identify opportunities for automation in manual workflows and design automated playbooks and modules in the SOAR platform.\nThreat Analysis: Apply a detailed understanding of the MITRE ATT&CK Framework to identify and map attacker techniques.\nThreat Intelligence: Analyze global threat landscapes, including cyber threat intelligence, new vulnerabilities, and exploit code to stay ahead of adversaries.\nVulnerability Assessment: Study vulnerabilities and provide technical recommendations for corrective actions and reporting.\nTechnical Expertise & Maintenance\nPlatform Mastery: Maintain deep knowledge of Security Technologies, Operating Systems (Windows & Linux), and deep-packet analysis tools like Wireshark.\nLog Analysis: Utilize extensive experience in log correlation and analysis to detect and investigate suspicious patterns.\nIncident Documentation: Ensure all findings, communication, and mitigation steps are thoroughly recorded in the ticketing system.\n BSc in Computer Science, Electrical/Computer/Software Engineering.\nMandatory: SIEM Based Trainings, FortiSOAR Training\nPreferred: GCIH Certified, Incident Handler Training, Linux+, Security+, CCNA, CCNA Security, FortiSOAR Certification\nThorough experience in Security Operations Center environment.\nExperience in handling Cyber Security Incidents.\nExperience with SIEM technologies such as ArcSight, Microsoft Sentinel, etc. and Threat Intelligence Platform.\nExpertise in gauging automation potential in SOC manual processes/workflows and designing their transformation into automated SOC/IR playbooks and Modules within FortiSOAR.\nUnderstanding the global threat landscape by analyzing cyber threat intelligence.\nExtensive experience in Incident Response activities and skilled in Log Analysis.\nAbility to write and execute complex queries using KQL (Kusto Query Language) \nExperience with Anti-DDoS solutions, preferably at a Service Provider level.\nMonitoring experience of security tools like SIEM, Anti-DDoS, IPS, EDR, firewalls, and MFA systems.\nFlexible to work in shifts and willing to assist team overtime if needed.\nSound understanding of common network services (Web, Mail, FTP, DNS etc.), network vulnerabilities and network attack patterns.","description_format":"text","description_chars":3375,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Mobile Networks","Broadband","Telecom Infrastructure"],"lifecycle":[{"event":"open","at":"2026-09-23T13:13:02Z"},{"event":"close","at":"2026-10-02T00:21:08Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/e-engineerincident-management","json_url":"https://alion.io/job/e-engineerincident-management.json","meta":{"generated_at":"2026-10-02T03:03:10Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4192,"day_limit":5000,"remaining_today":808,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}