Location: Qatar or Dubai, UAE Working Arrangement: Full-time, on-site at client locations Company: Command Post About Command Post Command Post is a cybersecurity and AI technology company delivering advanced security operations, threat intelligence, application security, AI assurance, governance, risk, compliance, and privacy solutions. We are expanding our regional delivery capability and are seeking a hands-on SOC & Security Platform Analyst to support customer security operations and security technology environments across Qatar and Dubai. This role is suitable for candidates from either of the following backgrounds:An experienced SOC analyst with strong operational, threat-hunting, and incident investigation capabilities. A technical security platform engineer with experience deploying, managing, and improving SIEM, SOAR, endpoint security, and security monitoring platforms. Role Overview The successful candidate will work on-site within customer environments, supporting day-to-day security operations and the implementation, administration, and optimisation of security monitoring platforms. The role requires a practical understanding of how security alerts, endpoint telemetry, logs, threat intelligence, detection rules, and automated response workflows come together to support an effective Security Operations Centre. Candidates do not need to be equally strong across every area. We are interested in experienced SOC practitioners, technical platform engineers, or candidates who combine elements of both disciplines. Key Responsibilities Security Operations and Incident Investigation Monitor, triage, investigate, and respond to security alerts and incidents. Analyse events from endpoints, networks, cloud services, identity platforms, applications, and security controls. Conduct structured investigations to determine incident scope, impact, root cause, and required containment actions. Perform proactive threat hunting using indicators, behavioural patterns, attack techniques, and threat intelligence. Document investigation findings, evidence, timelines, decisions, and recommended remediation actions. Support the development and maintenance of incident response procedures, investigation playbooks, and escalation processes. Identify recurring security issues and recommend improvements to controls, monitoring, and operational processes. Support customer reporting, operational reviews, and incident briefings. Security Platform Engineering Configure, administer, and optimise SIEM and security analytics platforms. Support log source onboarding, parsing, normalisation, enrichment, correlation, and data quality validation. Develop and maintain detection rules, use cases, alert logic, dashboards, reports, and monitoring workflows. Tune security use cases to reduce false positives while maintaining appropriate detection coverage. Integrate endpoint, network, cloud, identity, vulnerability, threat intelligence, and application security data sources. Support SOAR playbooks, workflow automation, case management, and response orchestration. Monitor platform health, ingestion performance, storage, integrations, connectors, and service availability. Assist with upgrades, troubleshooting, platform testing, documentation, and operational handover. Work with customer infrastructure, security, network, cloud, and application teams to resolve technical issues. Relevant Technology Experience Experience with one or more of the following platforms is highly desirable:Palo Alto Cortex XSIAM or XSIEMMicrosoft Sentinel Elastic Stack or ELKOpen Search Log Rhythm Arc Sight Other enterprise SIEM, SOAR, security analytics, or log-management platforms Experience in the following areas will also be valuable:Endpoint Detection and Response and Extended Detection and Response technologies Endpoint protection platforms Device and log-source onboarding Detection engineering and use-case management Security orchestration and automated response Dashboard and security reporting development Threat intelligence integration Cloud security monitoring Identity and access monitoring Network security monitoring Vulnerability management integrations Required Experience and Skills Practical experience working within a SOC, security operations team, managed security service, or security engineering function. Strong understanding of security monitoring, alert triage, incident investigation, and escalation processes. Working knowledge of common attacker techniques, indicators of compromise, and the MITRE ATT&CK framework. Ability to analyse security logs and telemetry from multiple sources. Experience with SIEM queries, dashboards, detection rules, correlation logic, or platform administration. Understanding of endpoint protection, EDR, XDR, firewalls, identity systems, cloud platforms, and common enterprise infrastructure. Ability to investigate technical issues methodically and communicate findings clearly. Strong written documentation and customer communication skills. Ability to work independently within a customer environment while collaborating with wider technical teams. Willingness and ability to work full-time on-site in Qatar or Dubai. Advantageous Experience The following experience would be considered an advantage:Digital forensics or forensic investigation. Malware analysis. Incident response and containment. Threat-hunting programme development. Detection engineering. Offensive security, penetration testing, red teaming, or vulnerability assessment. Security automation using Python, Power Shell, APIs, or scripting. Cloud security experience across Microsoft Azure, AWS, or Google Cloud. Experience supporting regulated organisations or critical infrastructure. Experience working in consulting, professional services, or customer-facing technical roles. Qualifications Relevant technical qualifications, certifications, or equivalent practical experience are welcomed. Useful certifications may include:Comp TIA Security+, CySA+, or equivalent Microsoft Security Operations Analyst Elastic, Palo Alto, Log Rhythm, Arc Sight, or SIEM-specific certifications GIAC incident response, forensic, or security operations certifications CEH, OSCP, or other offensive security certifications Cloud security certifications Certifications are beneficial but will not replace strong practical experience. Candidate Profile The ideal candidate is:Technically curious and comfortable investigating complex security problems. Operationally focused and able to work effectively in live customer environments. Capable of balancing incident response priorities with longer-term platform improvement. Confident communicating with analysts, engineers, customer stakeholders, and management. Able to take ownership of assigned activities and deliver work to a professional standard. Interested in working with modern security analytics, automation, AI-assisted security operations, and integrated cyber defence platforms. Why Join Command Post Work directly with enterprise customers across Qatar and the UAE. Gain exposure to a broad range of security technologies and operating environments. Contribute to the development and delivery of AI-enabled cybersecurity platforms. Work across security operations, threat hunting, incident investigation, detection engineering, automation, and security platform transformation. Join a growing regional cybersecurity company with opportunities to develop into senior technical, consulting, platform engineering, or security operations leadership roles. Application Please apply with an up-to-date CV outlining your experience in security operations, incident investigation, threat hunting, SIEM or SOAR engineering, endpoint security, and security platform administration. Candidates should also confirm whether they are applying for the Qatar-based or Dubai-based position. The role title could also be advertised as SOC & SIEM Platform Analyst or Security Operations & Platform Engineer depending on whether you want to attract more operational analysts or engineering-focused candidates.