L2 SOC / Splunk

VaporVM · SA

Posted Aug 11, 2026Source: indeed
View & apply on the employer's site ↗

Original posting on indeed. You apply directly with the employer — we never auto-apply.

Job description

**Date Posted:** 11 August, 2026 **Industry:** IT Services and IT Consulting **Location:** VAPORVM IT SERVICES DMCC **Job Description:** -------------------- **L2 SOC / Splunk Engineer — 1 Position** ========================================= **Nationality:** Saudi National **Location:** Saudi Arabia **Department:** Security Operations Center (SOC) **Level:** L2 **Positions:** 1 ### **Job Summary** The L2 SOC / Splunk Engineer will be responsible for advanced security monitoring, incident investigation, threat analysis, and escalation management. The role requires strong hands\-on experience with **Splunk Enterprise Security**, SIEM operations, incident response, and security event correlation. ### **Key Responsibilities** * Perform advanced monitoring and investigation of security incidents using Splunk. * Analyze and correlate events across multiple security and IT data sources. * Investigate escalated incidents from L1 analysts. * Conduct detailed root\-cause analysis of security incidents. * Validate and investigate suspicious activities and potential threats. * Develop and optimize Splunk searches and correlation rules. * Review and tune existing Splunk detection use cases. * Reduce false positives and improve detection accuracy. * Develop and maintain dashboards and operational reports. * Analyze: + Malware activity + Phishing attempts + Account compromise + Privilege escalation + Lateral movement + Data exfiltration + Suspicious network activity + Endpoint threats * Utilize MITRE ATT\&CK techniques during investigations. * Perform threat hunting activities using Splunk. * Support incident containment and remediation activities. * Coordinate with L1 and L3 teams during major incidents. * Prepare detailed incident investigation reports. * Participate in incident response and crisis management activities. * Support development and enhancement of SOC use cases. * Monitor and maintain SOC KPIs and SLAs. * Provide technical guidance to L1 engineers. * Participate in 24×7 SOC shift operations when required.

Is this role a fit for you?

Upload any CV — a short AI chat builds your profile, scores how well you fit roles like this across the Gulf, and tailors an ATS-ready CV to each. Free to start. No job promises — you always apply yourself.

Start free — get matched

Similar roles

Listing aggregated from indeed. Built for the Gulf. No job or interview promises — we make your search faster and your CV stronger.