18 часов назад
Expert Service Operations Security / SOC (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Expert Service Operations Security / SOC (Cybersecurity): Leading advanced SOC investigations, detection engineering, security monitoring, and automation for an international air-transport technology provider with an accent on technical escalation, detection coverage, and SOC maturity. Focus on designing MITRE ATT&CK-aligned detections, improving SIEM/SOAR/XDR integrations, and analyzing complex security incidents.
Location: Cairo, Egypt; hybrid work with work-from-home up to 2 days per week depending on team needs
Company
provides technology and communications solutions for airports, airlines, borders, and transportation and government organizations worldwide.
What you will do
- Serve as the highest technical escalation point for SOC investigations, monitoring activities, and high-severity security events.
- Lead advanced investigations across endpoint activity, network events, security telemetry, and investigative evidence.
- Provide technical leadership and mentoring to SOC Analysts and Senior SOC Analysts.
- Design, implement, validate, tune, and improve detection use cases, correlation rules, analytics, and monitoring content.
- Map detection coverage to MITRE ATT&CK and improve SIEM, SOAR, XDR, and security monitoring integrations.
- Prepare technical reports and recommendations and support incident escalations, audits, cyber simulations, and security assessments.
Requirements
- 5–8 years of experience in Security Operations or Cyber Defense, including at least 3 years in a SOC role.
- Advanced expertise in security investigations, detection engineering, security monitoring, and technical SOC operations.
- Expert knowledge of SIEM, SOAR, and XDR platforms; experience with Elastic, Cortex, Microsoft Defender, or CrowdStrike is preferred.
- Hands-on experience with Python, PowerShell, APIs, security automation, Azure or cloud security, identity security, and enterprise security environments.
- Practical knowledge of the MITRE ATT&CK framework and threat intelligence.
- Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field, plus at least one recognized cybersecurity certification such as CISSP, GCIH, GCIA, SC-200, CySA+, or ECIH.
Nice to have
- Experience evaluating, testing, and implementing new security technologies and SOC capabilities.
- Experience with tabletop exercises, cyber simulations, audits, and security assessments.
- Ability to translate detection gaps, security risks, and technical findings into actionable recommendations for SOC leadership and CISO-level stakeholders.
Culture & Benefits
- Inclusive environment across international teams and cultures.
- Flex Day to adapt the workday to personal plans.
- Flex-Location option allowing up to 30 days per year working from any location in the world.
- Employee Assistance Program and Champion Health wellbeing platform.
- Access to professional development platforms including LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, Pluralsight, and other specialized programs.
- Competitive benefits aligned with the local market and employment status.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →