المحلل الأمني لـ SOC - المستوى 1 مسؤول عن توفير مراقبة أمان على مدار 24/7، وفرز التنبيهات، وتحليل الأحداث، وتصعيد الحوادث ضمن مركز عمليات الأمن المُدار من زينتك (SOC). كخط الدفاع الأول ضد تهديدات الأمن السيبراني، يراقب البيئة الخاصة بالعملاء باستمرار، يتحقق من أحداث الأمن، ويتأكد من تحديد الحوادث الأمنية المحتملة وتصنيفها وتوثيقها وتصعيدها وفق الإجراءات المعتمدة واتفاقيات مستوى الخدمة.
المسؤوليات:
المراقبة الأمنية وتحليل الأحداث
- توفير مراقبة مستمرة على مدار 24x7 لبيئات الأمان الخاصة بالعملاء والمؤسسات من خلال عمليات وردية.
- مراقبة وتحليل أحداث الأمان الناتجة عن منصات SIEM، وحلول IDS/IPS، وأدوات Endpoint Detection & Response (EDR)، وجدران الحماية، وبوابات أمان البريد الإلكتروني، وحلول أمان الويب ومنصات أمان السحابة.
- مراجعة وتقييم التنبيهات الأمنية لتحديد ما إذا كانت النشاط يمثل تهديد أمني حقيقي أم إيجابية كاذبة.
- إجراء التحقق الأول من الحدث، والتصنيف، وتحديد الأولوية بناءً على الشدة والمخاطر والتأثير المحتمل على الأعمال.
- تحديد السلوك المشبوه، ومؤشرات الاختراق (IOCs)، والأنشطة الشذوذية التي تتطلب مزيداً من التحقيق.
فرز الحوادث والتصعيد
- إجراء التحليل والتقييم من المستوى الأول لتنبيهات وأحداث الأمن.
- إنشاء وإدارة تذاكر الحوادث ضمن منصات إدارة الحوادث المعتمدة.
- تصنيف الحوادث بناءً على الشدة، والتأثير، والإلحاح، وتصنيف التهديد.
- تصعيد الحوادث التي تم التحقق منها إلى فرق SOC Analyst - Tier 2 وفق إجراءات التصعيد المعتمدة.
- التأكد من أن تتضمن عمليات التصعيد تفاصيل تحقيق كاملة ودقيقة لدعم نقل المعرفة والتحليل الإضافي بشكل فعال.
- الحفاظ على تتبع الحوادث والتأكد من التحديثات في جميع مراحل دورة الحادث.
عمليات SIEM ومراقبة الأمان
- استخدام منصات SIEM لمراقبة أحداث الأمان، ومراجعة التنبيهات، وتنفيذ عمليات بحث واستفسارات محددة، ودعم التحقيقات الأساسية.
- دعم الأنشطة التشغيلية بما في ذلك التحقق من التنبيهات، ومراجعة لوحات المراقبة، وتحليل السجلات وربط أحداث الأمن.
- المساعدة في تحديد الإيجابيات الكاذبة والتصعيد بتوصيات ضبط المستوى عند الحاجة.
- دعم الفعالية والاعتمادية العامة لعمليات المراقبة.
التوثيق والتقارير
- الحفاظ على سجلات دقيقة للتحقيقات والملاحظات وأنشطة التصعيد.
- توثيق الحوادث الأمنية وأنشطة المراقبة وفق الإجراءات التشغيلية.
- المشاركة في تسليم المناوبات وضمان استمرارية التحقيقات بين الفرق.
- دعم تقارير التشغيل وأنشطة مقاييس أداء SOC.
الحوكمة والامتثال والتميز التشغيلي
- اتباع الإجراءات والكتب التشغيلية وقيَم SOC المعتمدة.
- التأكد من الامتثال لسياسات الأمان الداخلية والتزامات العملاء التعاقدية.
- التعامل مع معلومات العميل بسرية واحترافية عالية.
- المشاركة في التدريب، وتمارين المحاكاة، ومبادرات التحسين المستمر.
- الحفاظ على الوعي بالتهديدات السيبرانية الناشئة وأساليب الهجوم.
ثقافتنا ومدونة قواعد السلوك:
نفخر في زينTECH بثقافة مبنية على التعاون والابتكار ونزاهة لا تقبل المساومة. نبحث عن أفراد يشاركون هذه القيم ملتزمين بالمركزية للعميل والتميز الأخلاقي. يتوقع من جميع الموظفين الالتزام بمدونة قواعد السلوك التي تشكل إطاراً توجيهياً للسلوك المسؤول في كل ما نفعله، بدءاً من طريقة تعاملنا مع بعضنا البعض وحتى تفاعلنا مع العملاء والشركاء عالميًا.
الملف المرشح المطلوب
- خبرة عملية لا تقل عن سنة واحدة في عمليات SOC
- الإلمام بلوحات SIEM وفرز التنبيهات وسير عمل مراقبة SOC؛ الاستعداد للعمل بنظام النوبات المتناوبة.
- معرفة أساسية بالشبكات وأنظمة التشغيل تعتبر مفضلة.
- درجة البكالوريوس في الأمن السيبراني، أو معلومات الأمان، أو علوم الحاسوب، أو تكنولوجيا المعلومات، أو الهندسة، أو مجال ذي صلة.
- شهادة Security+، CEH أو أي شهادة ذات صلة مفضلة
The SOC Analyst - Tier 1 is responsible for providing 24x7 security monitoring, alert triage, event analysis, and incident escalation services within ZainTECH s Managed Security Operations Center (SOC). As the first line of defense against cybersecurity threats, the role continuously monitors customer environments, validates security events, and ensures potential security incidents are identified, classified, documented, and escalated in accordance with established procedures and service level agreements.
Responsibilities:
Security Monitoring & Event Analysis
- Provide continuous 24x7 monitoring of customer and enterprise security environments through shift-based operations.
- Monitor and analyze security events generated from SIEM platforms, IDS/IPS solutions, Endpoint Detection & Response (EDR) tools, Firewalls, Email security gateways, Web security solutions and Cloud security platforms
- Review and assess security alerts to determine whether activity represents a legitimate security threat or a false positive.
- Perform initial event validation, classification, and prioritization based on severity, risk, and potential business impact.
- Identify suspicious behavior, indicators of compromise (IOCs), and anomalous activities requiring further investigation.
Incident Triage & Escalation
- Perform first-level analysis and triage of security alerts and events.
- Create and manage incident tickets within approved incident management platforms.
- Categorize incidents based on Severity, Impact, Urgency and Threat classification
- Escalate validated incidents to SOC Analyst - Tier 2 teams in accordance with approved escalation procedures.
- Ensure escalations include complete and accurate investigation details to support efficient handover and further analysis.
- Maintain incident tracking and ensure timely updates throughout the incident lifecycle.
SIEM Operations & Security Monitoring
- Utilize SIEM platforms to Monitor security events, Review alerts, Execute predefined searches and queries, Support basic investigations
- Support operational activities including Alert validation, Monitoring dashboard review, Log analysis and Security event correlation
- Assist with identifying false positives and escalating tuning recommendations where required.
- Support the overall effectiveness and reliability of monitoring operations.
Documentation & Reporting
- Maintain accurate records of investigations, observations, and escalation activities.
- Document security incidents and monitoring activities in accordance with operational procedures.
- Participate in shift handovers and ensure continuity of investigations between teams.
- Support operational reporting and SOC performance metrics activities.
Governance, Compliance & Operational Excellence
- Follow approved SOC procedures, playbooks, and operational standards.
- Ensure compliance with Internal security policies and Customer contractual obligations.
- Handle customer information with strict confidentiality and professionalism.
- Participate in training, simulation exercises, and continuous improvement initiatives.
- Maintain awareness of emerging cybersecurity threats and attack techniques.
Our Culture & Code of Conduct:
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do from how we work with each other to how we engage with clients and partners globally.
Desired Candidate Profile
- Minimum 1 year of SOC operations experience
- Familiarity with SIEM consoles, alert triage, and SOC monitoring workflow; willingness to work rotating shifts.
- Foundational networking and operating-system knowledge is preferable.
- Bachelor s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security +, CEH or any relevant certification preferred