Senior Detection and Response Engineer

SpiderSilk
SpiderSilk

Other Engineering

Posted on Sep 4, 2026

Detection and Response Engineer

Location: Dubai/Abu Dhabi
Department: Engineering
Reports To: CTO

Who We Are!

Back in 2019, spiderSilk was born with a bold idea: build regional, sovereign cybersecurity IP that could stand tall on the global stage.

Our mission? To shake up the way organizations protect their ever-changing digital worlds with continuous, intelligent, and autonomous security that doesn’t miss a beat.

We’re a global mix of curious minds, problem-solvers, and passionate builders, all united by one goal: making the internet a safer place for everyone. Around here, we thrive on vision, energy, and a strong sense of ownership.

If this feels like your kind of crew, you’ll probably fit right in.

About the Role:

Today, when SilkRunner investigates an alert, we largely rely on the agents themselves to tell us whether the investigation was good. We need a human with real SOC experience to own that judgement.

You will be the person who looks at an agent-generated investigation and says whether it holds up: is the conclusion valid, is the evidence sufficient, is it comprehensive enough that an L1 or L2 analyst could actually act on it, or does it need more. You will then hold that same conversation with customers, with the credibility of someone who has run these investigations themselves and seen what their own team produced.

This is a hands-on technical role, not a people management role. We are looking for the senior engineer or SOC lead who stayed close to the incidents, not someone who moved away from them.

What you will do

  • Review and validate the investigations SilkRunner produces: assess whether the analysis is correct, the evidence is sufficient, and the report meets the standard a real SOC would expect

  • Define what "good" looks like for an investigation report, and turn that into a standard the platform and the team can be measured against

  • Identify where investigations fall short and feed that back into how the agents investigate, enrich and report

  • Work directly with customers on investigation quality, walking them through reports and taking their feedback on what their analysts need

  • Understand how we integrate with customer environments and how telemetry is retrieved for an investigation, for example pulling incidents from Microsoft Sentinel and querying telemetry with KQL

  • Bring automation thinking to how investigations and triage workflows are run

What you will bring

  • Solid hands-on experience in SOC operations, at senior security engineer, SOC lead or SOC manager level, with the emphasis on investigating incidents rather than managing teams

  • Deep familiarity with how incidents are triaged and investigated: the methods, the tools, the workflows, and what a good investigation write-up actually contains

  • Strong working knowledge of SIEM and security tooling, alerts, logs and telemetry, and the ability to correlate across sources

  • Enough technical depth to understand how we integrate with customer stacks and how telemetry is queried. Microsoft stack exposure (Sentinel, Defender, KQL) is a strong plus. We are not expecting deep specialisation, but you should be able to look at a query or an integration and understand what it is doing and why

  • Experience automating parts of SOC work, built on genuine security understanding rather than scripting alone

  • The confidence and clarity to sit in front of a customer and defend or challenge an investigation on its merits

Nice to have

  • Experience setting or auditing quality standards for SOC output, such as report review, QA of analyst work, or peer review processes

  • Exposure to MSSP or multi-customer SOC environments

  • Threat hunting experience across cloud and hybrid estates