المحلل SOC - المستوى 3 مسؤول عن قيادة وإدارة فريق مركز عمليات الأمن لدى زينتك (SOC)، وضمان تقديم فعال لمراقبة الأمن، واكتشاف التهديدات، وتنسيق الاستجابة للحوادث، وخدمات الأمن التشغيلي. يوفر الدور القيادة التقنية والإشراف التشغيلي عبر وظائف SOC مع ضمان الامتثال لاتفاقيات مستوى الخدمة ومتطلبات العملاء واللوائح المحلية. المسؤوليات: إدارة عمليات SOC قياس SOC اليومية عبر جميع أنشطة المراقبة والاستجابة. ضمان تغطية المراقبة على مدار 24×7 وإدارة التحولات بشكل فعال. الإشراف على التعامل مع الحوادث والتصعيد والتحقيق. ضمان الالتزام باتفاقيات مستوى الخدمة وإجراءات التشغيل. مراقبة أداء SOC ومقاييس جودة الخدمة. إدارة الحوادث والتصعيد كنقطة التصعيد الأساسية للحوادث الأمنية عالية الخطورة. تنسيق أنشطة الاستجابة للحوادث عبر الفرق الفنية وأصحاب المصلحة. دعم الاحتواء والتحقيق والاقتلاع والتعافي. مراجعة تقارير الحوادث وضمان جودة مخرجات التحقيق. المشاركة في حوادث كبرى وإدارة الأزمات. القيادة والتطوير للفريق قيادة وتوجيه وتطوير محللي SOC عبر جميع المستويات. إجراء تقييمات الأداء، جلسات التوجيه، ومبادرات نقل المعرفة. دعم التوظيف، الإعداد والتدريب. الكشف عن التهديدات وتحسين العمليات دفع التحسين المستمر لقدرات المراقبة والكشف. مراجعة واعتماد حالات الاستخدام، وقواعد الترابط، ولوحات البيانات، وإجراءات التشغيل. تحديد الثغرات في تغطية الكشف وفعالية التشغيل. دعم نضج SOC ومبادرات تعزيز الخدمة. الحوكمة والتقارير وإدارة أصحاب المصلحة إعداد تقارير تشغيلية ومراجعات الخدمة. المشاركة في اجتماعات العملاء ومناقشات حوكمة الأمن. ضمان الامتثال بسياسات الأمن الداخلي والالتزامات التنظيمية. الحفاظ على الوثائق التشغيلية والإجراءات ودُليلة التشغيل.
الملف المرغوب فيه للمرشح
- خبرة في الأمن السيبراني لا تقل عن 5 سنوات وخبرة في تشغيل SOC لا تقل عن 3 سنوات
- خبرة سابقة في قيادة فرق عمليات الأمن
- خبرة قوية في منصات SIEM، واكتشاف التهديدات، والاستجابة للحوادث، وإدارة عمليات الأمن
- خبرة في بيئة مزود خدمات أمنية مُدارة (MSSP)
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الحاسب، تكنولوجيا المعلومات، الهندسة، أو مجال ذو صلة
The SOC Analyst - Tier 3 is responsible for leading and managing ZainTECH s Security Operations Center (SOC) team, ensuring effective delivery of security monitoring, threat detection, incident response coordination, and operational security services. The role provides technical leadership and operational oversight across SOC functions while ensuring compliance with service level agreements, customer requirements, and local regulations. Responsibilities: SOC Operations Management Lead daily SOC operations across all monitoring and response activities. Ensure continuous 24x7 monitoring coverage and effective shift management. Oversee incident handling, escalation, and investigation activities. Ensure adherence to customer SLAs and operational procedures. Monitor SOC performance and service quality metrics. Incident Management & Escalation Act as the primary escalation point for high-severity security incidents. Coordinate incident response activities across technical teams and stakeholders. Support containment, investigation, eradication, and recovery efforts. Review incident reports and ensure quality of investigation outputs. Participate in major incident and crisis management activities. Team Leadership & Development Lead, mentor, and develop SOC analysts across all levels. Conduct Performance reviews ,Coaching sessions and Knowledge transfer initiatives Support recruitment, onboarding, and training activities. Threat Detection & Operational Improvement Drive continuous improvement of monitoring and detection capabilities. Review and approve Use cases , Correlation rules , Dashboards and Operational procedures Identify gaps in detection coverage and operational effectiveness. Support SOC maturity and service enhancement initiatives. Governance, Reporting & Stakeholder Management Prepare operational reports and service reviews. Participate in customer meetings and security governance discussions. Ensure compliance with Internal security policies and Regulatory obligations. Maintain operational documentation, procedures, and playbooks.
Desired Candidate Profile
- Minimum 5 years of cybersecurity experience and minimum 3 years of SOC operations experience
- Previous experience leading security operations teams.
- Strong experience with in SIEM platforms , Threat detection , Incident response and Security operations management
- Experience working within a Managed Security Services Provider (MSSP) environment.
- Bachelor s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.