Job description
The SOC engineer is responsible for the design, implementation, configuration, and continuous optimization of ZainTECH's Security Operations Centre (SOC) technology platforms, ensuring secure, scalable, and resilient security monitoring services for enterprise and government customers across the MENA region.
This is a hands-on engineering role focused on designing and maintaining Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and supporting security technologies. The role owns the end-to-end lifecycle of security monitoring capabilities - from onboarding new log sources and developing detection content to automating operational workflows and continuously enhancing SOC performance - while ensuring solutions align with customer requirements, cybersecurity best practices, and operational standards.
Responsibilities
SIEM & security platform engineering
Design, implement, configure, and maintain enterprise SIEM and SOAR platforms supporting ZainTECH's Managed Security Services portfolio.
Deploy and maintain highly available, scalable, and secure SOC infrastructure across customer environments.
Manage platform upgrades, patching, configuration management, and lifecycle activities to ensure platform stability and performance.
Ensure SOC technologies remain aligned with operational, security, and customer requirements.
Detection engineering & security content
Develop, maintain, and optimise SIEM detection content, including correlation rules, dashboards, reports, alerts, watchlists, and use cases.
Improve detection capabilities by analysing emerging threats, attack techniques, and operational trends.
Reduce false positives through continuous tuning and refinement of detection logic.
Map detection capabilities to recognised cybersecurity frameworks such as MITRE ATT&CK.
Platform integration & automation
Integrate security technologies, cloud platforms, infrastructure, and third-party solutions into the SIEM ecosystem.
Develop custom parsers, connectors, and data ingestion mechanisms to support new customer environments.
Design and implement SOAR playbooks to automate investigation, enrichment, notification, and response activities.
Optimise data collection, normalisation, and event processing to improve operational efficiency.
Operational support & continuous improvement
Provide technical support to SOC analysts during security investigations and major incident response activities.
Troubleshoot platform issues and perform root cause analysis to maintain service availability.
Produce technical documentation, implementation guides, and operational runbooks.
Identify opportunities to improve SOC maturity through automation, process optimisation, and engineering best practices.
Collaborate with cybersecurity consulting, incident response, product management, and delivery teams to continuously enhance Managed Security Services.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- 3-5 years of hands-on experience designing, implementing, and administering SIEM platforms within enterprise or Managed Security Services environments.
- Strong experience with one or more SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, ArcSight, LogRhythm, or Elastic Security.
- Experience integrating multiple security technologies, including EDR, firewalls, IDS/IPS, cloud security platforms, identity platforms, and threat intelligence feeds.
- Working knowledge of Windows, Linux, networking, scripting, APIs, and automation technologies.
- Experience implementing SOAR platforms and security automation workflows.
- Knowledge of MITRE ATT&CK, threat intelligence integration, and detection engineering principles.
- Experience supporting enterprise cloud environments including Microsoft Azure, AWS, or Google Cloud Platform.
- Experience working within a Managed Security Services Provider (MSSP) environment.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security+, CEH or any relevant certification preferred.
وصف الوظيفة
المهندس الأمني SOC مسؤول عن تصميم وتنفيذ وتكوين وتحسين مستمر لمنصات تقنيات مركز عمليات الأمن (SOC) في ZeinTECH، لضمان خدمات مراقبة أمنية آمنة وقابلة للتوسع ومرنة للعملاء المؤسسيين والحكوميين عبر منطقة الشرق الأوسط وشمال أفريقيا.
هذا دور هندسي عملي يركز على تصميم وصيانة أنظمة إدارة المعلومات والأحداث الأمنية (SIEM)، وتنسيق الأمان والتشغيل والاستجابة (SOAR)، وتكنولوجيا الأمن المدعومة. يتولى الدور دورة الحياة الكاملة لقدرات مراقبة الأمن من تسجيل مصادر السجلات الجديدة وتطوير محتوى الكشف إلى أتمتة سير العمل التشغيلي وتحسين أداء SOC باستمرار، مع التأكد من توافق الحلول مع متطلبات العميل، وأفضل ممارسات الأمن السيبراني، والمعايير التشغيلية.
المسؤوليات
هندسة SIEM ومنصة الأمن
تصميم وتنفيذ وتكوين وصيانة منصات SIEM وSOAR المؤسسية الداعمة لمحفظة خدمات الأمن المدارة من ZeinTECH.
نشر وصيانة بنية SOC عالية التوفر وقابلة للتوسع وآمنة عبر بيئات العملاء.
إدارة ترقية المنصة والتحديثات وإدارة التكوين وأنشطة دورة الحياة لضمان استقرار وأداء المنصة.
ضمان بقاء تقنيات SOC متوافقة مع متطلبات التشغيل والأمن والعملاء.
هندسة الكشف ومحتوى الأمان
تطوير وصيانة وتحسين محتوى كشف SIEM، بما في ذلك قواعد الترابط ولوحات القياس والتقارير والتنبيهات وقوائم المراقبة وحالات الاستخدام.
تحسين قدرات الكشف من خلال تحليل التهديدات الناشئة وتقنيات الهجوم والاتجاهات التشغيلية.
تقليل الإيجابيات الكاذبة من خلال ضبط وتحسين منطق الكشف باستمرار.
ربط قدرات الكشف بإطارات الأمن السيبراني المعترف بها مثل MITRE ATT&CK.
التكامل المنصّات والأتمتة
دمج تقنيات الأمن ومنصات السحابة والبنية التحتية وحلول الطرف الثالث ضمن منظومة SIEM.
تطوير محولات مخصصة وروابط وم mechanisms إدخال البيانات لدعم بيئات العملاء الجديدة.
تصميم وتنفيذ خطوط لعب SOAR لأتمتة التحقيق والتغذية والإخطار والاستجابة.
تحسين جمع البيانات والتحويل والتعامل مع الأحداث لرفع الكفاءة التشغيلية.
الدعم التشغيلي والتحسين المستمر
تقديم الدعم الفني لمحللي SOC خلال التحقيقات الأمنية وأنشطة الاستجابة للحوادث الكبرى.
استكشاف مشاكل المنصة والتحليل الجذري للمشاكل للحفاظ على توفّر الخدمة.
إنتاج وثائق فنية وأدلة التنفيذ ودليل التشغيل.
تحديد فرص تحسين نضج SOC من خلال الأتمتة وتحسين العمليات وتبني أفضل الممارسات الهندسية.
التعاون مع استشاريي الأمن السيبراني والاستجابة للحوادث وإدارة المنتجات وفرق التوصيل لتعزيز خدمات الأمن المدارة باستمرار.
ثقافتنا وقواعد السلوك
في ZeinTECH، نفخر بثقافة قائمة على التعاون والابتكار والنزاهة غير القابلة للمساومة. نبحث عن أفراد يشاركون هذه القيم وملتزمون بالتركيز على العميل والتميز الأخلاقي. يتوقع من جميع الموظفين الالتزام بمدونة السلوك لدينا، التي تعمل كإطار توجيهي للسلوك المسؤول في كل ما نقوم به — من كيفية العمل مع بعضنا البعض إلى كيفية التعامل مع العملاء والشركاء عالميًا.
المتطلبات
- 3-5 سنوات من الخبرة العملية في تصميم وتنفيذ وإدارة منصات SIEM ضمن بيئات المؤسسات أو خدمات الأمن المدارة.
- خبرة قوية مع واحدة أو أكثر من منصات SIEM مثل Microsoft Sentinel، Splunk Enterprise Security، IBM QRadar، ArcSight، LogRhythm، أو Elastic Security.
- خبرة في دمج تقنيات أمان متعددة، بما في ذلك EDR، الجدران النارية، IDS/IPS، منصات أمان السحابة، منصات الهوية، وتغذيات معلومات التهديد.
- معرفة عملية بنظامي Windows وLinux وشبكات البرمجيات والبرمجة وواجهات برمجة التطبيقات وتقنيات الأتمتة.
- خبرة في تنفيذ منصات SOAR وتدفقات عمل الأتمتة الأمنية.
- معرفة بـ MITRE ATT&CK وتكامل معلومات التهديد ومبادئ هندسة الكشف.
- خبرة في دعم بيئات السحابة المؤسسية بما في ذلك Microsoft Azure وAWS أو Google Cloud Platform.
- خبرة في العمل ضمن مزود خدمات أمنية مدارة (MSSP).
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الكمبيوتر، تقنية المعلومات، الهندسة، أو مجال ذو صلة.
- يفضل وجود شهادة Security+ أو CEH أو أي شهادة ذات صلة.