المحلل SOC - المستوى 2 مسؤول عن مراقبة الأمن المتقدمة، وتحقيق الحوادث، وتحليل التهديدات، وأنشطة هندسة الكشف ضمن مركز عمليات الأمن في ZainTECH (SOC). تلعببت هذه الدور دور نقطة التصعيد الأساسية للحوادث الأمنية التي حُددت من قبل محللي المستوى 1 وتلعب دوراً حاسماً في التحقق من التهديدات، وإجراء التحقيقات، ودعم أنشطة الاستجابة للحوادث عبر بيئات المؤسسة والحكومة والبنى التحتية الحيوية.
المسؤوليات:
مراقبة الأمن والتحقيق في الحوادث
- التحقيق في حوادث الأمن وتحليلها التي تصعيدها محللو SOC من المستوى 1.
- التحقق من الأحداث الأمنية وتحديد النطاق والتأثير والجدارة والأخطار التجارية.
- إجراء ترابط متقدم وتحليل للسجلات والتنبيهات ونشاط الشبكة والبيانات الطرفية ومعلومات التهديد.
- إجراء تحليل السبب الجذري لحوادث الأمن وتحديد مؤشرات الاختراق (IOCs).
- دعم احتواء الحوادث والقضاء عليها وعمليات التعافي.
- تصعيد الحوادث التي تتطلب تحقيقاً متخصصاً أو دعم استجابة للحوادث.
كشف التهديدات والصيد عن التهديدات
- القيام بأنشطة صيد تهديدات استباقية لتحديد الأنشطة الخبيثة التي قد تتجاوز الضوابط الآلية.
- استخدام مصادر معلومات التهديد لتحديد التهديدات الناشئة وتكتيكات المهاجمين.
- تحليل أنماط الهجوم والمؤشرات والسلوكيات المرتبطة بالبرمجيات الخبيثة، وبرمجيات الفدية، والتهديدات من الداخل، والتهديدات المستمرة والمتقدمة (APT).
- تحديد فرص تحسين تغطية الكشف عبر البيئات المراقبة.
SIEM وهندسة الكشف
- تطوير وتعديل وتحسين حالات استخدام SIEM وقواعد الترابط.
- دعم إنشاء وصيانة منطق الكشف ولوحات التحكم والتقارير والتنبيهات وتدفقات مراقبة.
- تقليل الإيجابية الكاذبة من خلال الضبط وتحسين القواعد.
- دعم إدراج وتكامل مصادر السجلات الجديدة.
إدارة الحوادث والتقارير
- الحفظ المفصل لسجلات الحوادث ووثائق التحقيق.
- إعداد التحليل الفني وتقارير الحوادث.
- دعم مقاييس التشغيل والتقارير ومراجعات الخدمة.
- التأكد من امتثال أنشطة معالجة الحوادث للإجراءات المحددة وSLA.
القيادة الفنية ونقل المعرفة
- تقديم الإرشاد والتوجيه لمحللي SOC من المستوى 1.
- دعم تطوير المحلل من خلال التدريب وتبادل المعرفة التقنية.
- المشاركة في مبادرات التحسين المستمر وبرامج نضج SOC.
- المساهمة في تطوير العمليات والدليل والإجراءات.
ثقافتنا ومدونة السلوك:
في ZainTECH، نفخر بثقافة مبنية على التعاون والابتكار والنزاهة التي لا تقبل التنازلات. نبحث عن أفراد يشاركون هذه القيم وممن يلتزمون بالتركيز على العميل والتميز الأخلاقي. يُتوقع من جميع الموظفين الالتزام بمدونة السلوك لدينا، التي تعمل كإطار توجيهي للسلوك المسؤول في كل ما نقوم به—from كيفية عملنا مع بعضنا البعض إلى كيفية تعاملنا مع العملاء والشركاء عالمياً.
الملف الشخصي المرغوب للمرشح
- خبرة لا تقل عن 3 سنوات في الأمن السيبراني المُدار / عمليات SOC على مستوى تحقيق.
- خبرة قوية في تحقيقات SIEM، وتطوير قواعد الكشف، وتحليل السجلات والشبكات، وتحسين حالات الاستخدام.
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الكمبيوتر، تكنولوجيا المعلومات، الهندسة، أو مجال ذو صلة.
- يفضل الحصول على شهادة Security+ أو GCIA أو GCIH.
The SOC Analyst - Tier 2 is responsible for advanced security monitoring, incident investigation, threat analysis, and detection engineering activities within ZainTECH s Security Operations Center (SOC). The role serves as the primary escalation point for security incidents identified by L1 analysts and plays a critical role in validating threats, conducting investigations, and supporting incident response activities across enterprise, government, and critical infrastructure environments.
Responsibilities:
Security Monitoring & Incident Investigation
- Investigate and analyze security incidents escalated by SOC L1 analysts.
- Validate security events and determine scope, impact, severity, and business risk.
- Perform advanced correlation and analysis of logs, alerts, network activity, endpoint telemetry, and threat intelligence.
- Conduct root cause analysis of security incidents and identify indicators of compromise (IOCs).
- Support incident containment, eradication, and recovery activities.
- Escalate incidents requiring specialized investigation or incident response support.
Threat Detection & Threat Hunting
- Perform proactive threat hunting activities to identify malicious activity that may bypass automated controls.
- Utilize threat intelligence sources to identify emerging threats and attacker tactics.
- Analyze attack patterns, indicators, and behaviors associated with Malware ,Ransomware ,Insider threats ,Advanced Persistent Threats (APTs)
- Identify opportunities to improve detection coverage across monitored environments.
SIEM & Detection Engineering
- Develop, tune, and optimize SIEM use cases and correlation rules.
- Support creation and maintenance of Detection logic , Dashboards ,Reports ,Alerts and Monitoring workflows
- Reduce false positives through tuning and rule optimization.
- Support onboarding and integration of new log sources.
Incident Management & Reporting
- Maintain detailed incident records and investigation documentation.
- Prepare technical analysis and incident reports.
- Support operational metrics, reporting, and service reviews.
- Ensure incident handling activities comply with established procedures and SLAs.
Technical Leadership & Knowledge Transfer
- Provide guidance and mentoring to L1 SOC Analysts.
- Support analyst development through coaching and technical knowledge sharing.
- Participate in continuous improvement initiatives and SOC maturity programs.
- Contribute to process, playbook, and procedure development.
Our Culture & Code of Conduct:
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do from how we work with each other to how we engage with clients and partners globally.
Desired Candidate Profile
- Minimum 3 years experience in managed cybersecurity / SOC operations at an investigative level.
- Strong SIEM investigation, detection-rule development, log and network analysis, and use-case tuning.
- Bachelor s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security +, GCIA, GCIH certification preferred