SOC Lead
SOC Lead – UAE
Location: Dubai/Abu Dhabi
Department: Engineering
Reports To: CTO
Who We Are!
Back in 2019, spiderSilk was born with a bold idea: build regional, sovereign cybersecurity IP that could stand tall on the global stage.
Our mission? To shake up the way organizations protect their ever-changing digital worlds with continuous, intelligent, and autonomous security that doesn’t miss a beat.
We’re a global mix of curious minds, problem-solvers, and passionate builders, all united by one goal: making the internet a safer place for everyone. Around here, we thrive on vision, energy, and a strong sense of ownership.
If this feels like your kind of crew, you’ll probably fit right in.
About the Role:
Today, when SilkRunner investigates an alert, we largely rely on the agents themselves to tell us whether the investigation was good. We need a human with real SOC experience to own that judgement.
You will be the person who looks at an agent-generated investigation and says whether it holds up: is the conclusion valid, is the evidence sufficient, is it comprehensive enough that an L1 or L2 analyst could actually act on it, or does it need more. You will then hold that same conversation with customers, with the credibility of someone who has run these investigations themselves and seen what their own team produced.
This is a hands-on technical role, not a people management role. We are looking for the senior engineer or SOC lead who stayed close to the incidents, not someone who moved away from them.
Responsibilities:
Own corporate IT operations and infrastructure, including the endpoint fleet and the full onboarding and offboarding lifecycle
Run identity and access management: SSO, provisioning, joiner/mover/leaver flows, access reviews and least privilege
Manage the device estate through MDM, including enrolment, baseline configuration, patching and compliance policy
Administer our productivity and SaaS stack, including licensing, tenant configuration and app governance
Own networking and connectivity: firewalls, VPN, Wi-Fi and switching across our sites
Keep IT controls aligned to SOC 2 and ISO 27001, and work with security on endpoint protection and EDR coverage
Run the service desk: ticketing, SLAs, escalation paths and the reporting that shows where the recurring pain is
Lead and develop a small IT and helpdesk team, and manage vendors, contracts and IT budget
What you will bring
Proven experience owning corporate IT end to end, including endpoint fleet management and onboarding and offboarding at scale
Strong hands-on identity and access management: Okta, Microsoft Entra ID (Azure AD), JumpCloud or Google Workspace
Device and endpoint management through MDM: Intune, Jamf, Kandji or Mosyle
Microsoft 365 and/or Google Workspace administration at admin level, not end user level
Networking and connectivity experience across firewalls, VPN, Wi-Fi and switching, with tools such as Fortinet, Palo Alto, Cisco Meraki or Zscaler
IT security and compliance experience, including SOC 2 and ISO 27001 control ownership or audit support, and endpoint security or EDR. Given that we are a security company, this is weighted heavily
Service desk and ITSM ownership using Jira Service Management, Freshservice, ServiceNow or Zendesk
Experience leading a small IT or helpdesk team, and managing vendors and budgets
Nice to have
Experience in a regulated or high-security environment
Scripting or automation for provisioning and fleet management (PowerShell, Python, Bash)
Multi-site or multi-region IT support experience across the GCC
- Department
- Dark Web & Threat Intel
- Locations
- Dubai
- Remote status
- Hybrid