Responsibilities:
Security monitoring & event analysis
Provide continuous 24x7 monitoring of customer and enterprise security environments through shift-based operations.
Monitor and analyze security events generated from SIEM platforms, IDS/IPS solutions, Endpoint Detection & Response (EDR) tools, firewalls, email security gateways, web security solutions, and cloud security platforms.
Review and assess security alerts to determine whether activity represents a legitimate security threat or a false positive.
Perform initial event validation, classification, and prioritization based on severity, risk, and potential business impact.
Identify suspicious behavior, indicators of compromise (IOCs), and anomalous activities requiring further investigation.
Incident triage & escalation
Perform first-level analysis and triage of security alerts and events.
Create and manage incident tickets within approved incident management platforms.
Categorize incidents based on severity, impact, urgency, and threat classification.
Escalate validated incidents to SOC Analyst - Tier 2 teams in accordance with approved escalation procedures.
Ensure escalations include complete and accurate investigation details to support efficient handover and further analysis.
Maintain incident tracking and ensure timely updates throughout the incident lifecycle.
SIEM operations & security monitoring
Utilize SIEM platforms to monitor security events, review alerts, execute predefined searches and queries, and support basic investigations.
Support operational activities including alert validation, monitoring dashboard review, log analysis, and security event correlation.
Assist with identifying false positives and escalating tuning recommendations where required.
Support the overall effectiveness and reliability of monitoring operations.
Documentation & reporting
Maintain accurate records of investigations, observations, and escalation activities.
Document security incidents and monitoring activities in accordance with operational procedures.
Participate in shift handovers and ensure continuity of investigations between teams.
Support operational reporting and SOC performance metrics activities.
Governance, compliance & operational excellence
Follow approved SOC procedures, playbooks, and operational standards.
Ensure compliance with internal security policies and customer contractual obligations.
Handle customer information with strict confidentiality and professionalism.
Participate in training, simulation exercises, and continuous improvement initiatives.
Maintain awareness of emerging cybersecurity threats and attack techniques.
Our culture & code of conduct:
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- Minimum 1 year of SOC operations experience
- Familiarity with SIEM consoles, alert triage, and SOC monitoring workflow; willingness to work rotating shifts
- Foundational networking and operating-system knowledge is preferable
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field
- Security+, CEH, or any relevant certification preferred
المسؤوليات:
مراقبة الأمن وتحليل الأحداث
توفير مراقبة مستمرة على مدار 24x7 لبيئات أمان العملاء والمؤسسة من خلال عمليات تعتمد على الورديات.
مراقبة وتحليل الأحداث الأمنية الناتجة من منصات SIEM، حلول IDS/IPS، أدوات Endpoint Detection & Response (EDR)، الجدران النارية، بوابات أمان البريد الإلكتروني، حلول أمان الويب، ومنصات أمان السحابة.
مراجعة وتقييم التنبيهات الأمنية لتحديد ما إذا كانت النشطة تمثل تهديد أمني حقيقي أم إيجابية خاطئة.
إجراء التحقق الأول من الحدث، التصنيف، وتحديد الأولوية بناءً على الشدة والخطر والتأثير المحتمل على الأعمال.
تحديد السلوك المشبوه، ومؤشرات الاختراق (IOCs)، والأنشطة الشاذة التي تتطلب تحقيقاً إضافياً.
فرز الحوادث وتصعيدها
إجراء التحليل الأولي وفرز التنبيهات والأحداث الأمنية.
إنشاء وتسجيل تذاكر الحوادث ضمن منصات إدارة الحوادث المعتمدة.
تصنيف الحوادث بناءً على الشدة والتأثير والإلحاح والتصنيف التهديدي.
تصعيد الحوادث التي تم التثبت منها إلى فرق SOC Analyst - Tier 2 وفقاً لإجراءات التصعيد المعتمدة.
التأكد من أن التصعيد يتضمن تفاصيل تحقيق كاملة ودقيقة لدعم النقل السلس والتحليل الإضافي.
الحفاظ على تتبع الحوادث والتأكد من التحديثات في الوقت المناسب طوال دورة حياة الحادث.
عمليات SIEM والمراقبة الأمنية
استخدام منصات SIEM لمراقبة الأحداث الأمنية، مراجعة التنبيهات، تنفيذ عمليات بحث واستفسارات معرفة مسبقة، ودعم التحقيقات الأساسية.
دعم الأنشطة التشغيلية بما في ذلك التحقق من التنبيهات، مراجعة لوحات المراقبة، تحليل السجلات، وارتباط الأحداث الأمنية.
المساعدة في تحديد الإيجابيات الخاطئة وتصعيد التوصيات لضبط الإعدادات عند الحاجة.
دعم فاعلية وموثوقية عمليات المراقبة بشكل عام.
التوثيق والتقارير
الحفاظ على سجلات دقيقة للتحقيقات والملاحظات وأنشطة التصعيد.
توثيق الحوادث الأمنية وأنشطة المراقبة وفق إجراءات التشغيل.
المشاركة في تسليم الورديات والتأكد من استمرار التحقيقات بين الفرق.
دعم التقارير التشغيلية ونشاط قياسات أداء SOC.
الحوكمة والامتثال والتميز التشغيلي
اتباع إجراءات SOC المعتمدة ودفاتر اللعب والمعايير التشغيلية.
ضمان الامتثال لسياسات الأمان الداخلية والتزامات العملاء التعاقدية.
التعامل مع معلومات العملاء بسرية ومهنية عالية.
المشاركة في التدريب، وتمارين المحاكاة، ومبادرات التحسين المستمر.
الحفاظ على الوعي بالتهديدات السيبرانية الناشئة وتقنيات الهجوم.
ثقافتنا ومدى سلوكنا:
في ZainTECH، نفخر بثقافة تقوم على التعاون والابتكار والنزاهة التي لا تقبل المساس بجودتها. نبحث عن أفراد يشاركوننا هذه القيم وملتزمون بمركزيّة العملاء والتميز الأخلاقي. من المتوقع أن يلتزم جميع الموظفين بمدونة السلوك لدينا، التي تشكل الإطار التوجيهي للسلوك المسؤول في كل ما نقوم به — من كيفية تعاملنا مع بعضنا البعض إلى كيفية تعاملنا مع العملاء والشركاء حول العالم.
المتطلبات
- خبرة لا تقل عن سنة واحدة في عمليات SOC
- الإلمام بعناصر SIEM، فرز التنبيهات، وتدفق عمل مراقبة SOC؛ الرغبة في العمل بنظام الورديات المتناوبة
- معرفة أساسية بالشبكات ونظام التشغيل مفضلة
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الحاسوب، تكنولوجيا المعلومات، الهندسة، أو مجال ذي صلة
- يفضل شهادة Security+ أو CEH أو أي شهادة ذات صلة