7 дней назад
Security Analyst / SOC (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Analyst / SOC (Cybersecurity): Monitoring, triaging, and investigating security alerts across SIEM, EDR/XDR, cloud, identity, and email platforms with an accent on alert validation, evidence gathering, and incident escalation. Focus on analyzing correlated events, executing SOC playbooks, documenting investigations, and improving operational monitoring effectiveness.
Location: Cairo, Egypt; hybrid work with work from home up to 2 days per week depending on team needs
Company
provides technology and communications solutions for airports, airlines, borders, and the global air travel industry.
What you will do
- Monitor security alerts and events across SIEM, EDR/XDR, cloud, identity, email, and other security platforms.
- Triage alerts and determine whether activity is malicious, benign, or a false positive.
- Investigate low- to medium-severity alerts, gather evidence, and escalate complex or high-risk cases.
- Execute SOC playbooks, standard operating procedures, and investigation workflows.
- Document investigations, timelines, evidence, and actions in ticketing systems.
- Support shift handovers, vulnerability monitoring, compliance activities, knowledge-base updates, and SOC process improvements.
Requirements
- 1–3 years of experience in security operations or a related cybersecurity role.
- Experience investigating alerts with EDR/XDR solutions such as Microsoft Defender, Cortex XDR, or CrowdStrike Falcon.
- Experience with IT service management or ticketing platforms such as ServiceNow.
- Fundamental understanding of SIEM technologies, preferably Elastic or Splunk.
- Basic knowledge of Windows, Linux, Active Directory, Azure/Entra ID, networking, and common cyber threats.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field, plus an industry-recognized cybersecurity certification such as Security+, GSEC, CySA+, SC-200, AZ-900, or SC-900.
Nice to have
- Participation in cybersecurity training, Capture the Flag competitions, cyber labs, or other hands-on learning activities.
- Exposure to cloud security monitoring in Microsoft Azure, Microsoft 365, or AWS.
- Familiarity with the MITRE ATT&CK framework and its use in security monitoring and threat investigations.
Culture & Benefits
- Inclusive environment operating across 200 countries and 60 languages and cultures.
- Flex Day arrangements to adapt working hours to personal needs.
- Flex-Location benefit allowing work from any location in the world for up to 30 days per year.
- Employee Assistance Program and Champion Health wellbeing platform.
- Access to professional development platforms including LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, Pluralsight, and other specialized programs.
- Competitive benefits aligned with the local market and employment status.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →