Job Summary
We are looking for a Senior Cybersecurity Operations & Incident Response Engineer to strengthen our cybersecurity capabilities across Security Operations, Incident Response, Threat Hunting, Detection Engineering, Endpoint, Network, Cloud, and Identity Security.
The role will be responsible for monitoring and investigating cybersecurity events, leading complex incident investigations, improving security detections and controls, conducting threat-hunting activities, and supporting vulnerability management and security operations across enterprise environments.
The ideal candidate will have strong hands-on experience with SIEM, EDR/XDR, DLP, vulnerability management, WAF, IAM, cloud security, incident response, and threat hunting, with the ability to act as a senior technical escalation point and mentor junior cybersecurity team members.
Key Responsibilities
Security Operations & Detection Engineering
- Monitor and analyze security events generated by SIEM, EDR/XDR, DLP, firewalls, IDS/IPS, WAF, email security, cloud security, IAM, applications, databases, and other security platforms.
- Investigate security alerts, validate incidents, perform initial analysis, and support containment and remediation activities.
- Develop and improve SIEM queries, detection rules, alerts, dashboards, and security monitoring use cases.
- Analyze security events across endpoints, networks, identities, applications, databases, and cloud environments.
- Identify monitoring and detection gaps and recommend additional log sources, telemetry, integrations, and security controls.
- Map security detections and attacker behaviors to the MITRE ATT&CK framework.
- Act as a senior technical escalation point for complex alerts, suspicious activities, and cybersecurity investigations.
- Maintain accurate documentation of investigations, findings, evidence, affected assets, and remediation activities.
Incident Response & Threat Hunting
- Lead technical investigations involving malware, phishing, compromised accounts, unauthorized access, insider threats, data leakage, and network intrusions.
- Determine incident scope, business impact, attack vectors, affected systems, compromised identities, exposed information, and required containment actions.
- Analyze endpoint telemetry, authentication events, email headers, network traffic, DNS activity, proxy logs, firewall logs, VPN logs, cloud audit logs, application logs, and operating-system events.
- Develop incident timelines and perform root-cause analysis to determine attacker and defender activities.
- Conduct proactive threat hunting to identify indicators of compromise, abnormal behavior, suspicious patterns, and activities that may not trigger automated alerts.
- Participate in Purple Team, breach-simulation, and attack-simulation activities to validate detection and response capabilities.
- Prepare technical incident reports and conduct post-incident reviews to improve security controls, detections, configurations, and response procedures.
Endpoint, Network, Cloud & Identity Security
- Operate and support EDR/XDR and endpoint-security technologies.
- Investigate suspicious processes, command-line activity, file creation, registry changes, persistence techniques, malicious scripts, unauthorized software, and suspicious outbound connections.
- Investigate unusual network traffic, unauthorized remote access, lateral movement, command-and-control communication, and potential data exfiltration.
- Identify insecure cloud configurations, excessive permissions, exposed services, suspicious cloud activities, and security monitoring gaps.
- Support identity-security monitoring across IAM, MFA, SSO, PAM, and privileged-access environments.
- Support vulnerability assessments covering servers, endpoints, network devices, cloud environments, databases, business applications, and externally exposed systems.
- Support penetration-testing activities and implement additional detections or defensive controls based on identified findings.
Security Automation & Technical Leadership
- Maintain incident-response playbooks, technical runbooks, investigation procedures, escalation guidelines, and detection documentation.
- Support security automation using scripting and automation technologies.
- Evaluate new cybersecurity technologies from an operational, technical, and defensive-security perspective.
- Mentor junior cybersecurity team members in alert analysis, threat hunting, incident investigation, log analysis, evidence handling, and security-tool usage.
- Coordinate cybersecurity activities with Infrastructure, Network, Cloud, DevOps, Development, Application, and business teams.
- Collaborate with third-party security providers and vendors during technical implementations, investigations, and security assessments.
Reporting, Risk & Compliance
- Develop and maintain cybersecurity dashboards and KPIs covering alert volumes, false-positive rates, incident trends, detection coverage, response times, vulnerabilities, and remediation progress.
- Prepare periodic reports covering cybersecurity alerts, incidents, vulnerabilities, threat-hunting activities, control performance, and remediation status.
- Support audits, risk assessments, compliance activities, and security reviews by providing technical evidence and cybersecurity expertise.
- Identify security risks and compliance gaps and recommend appropriate corrective actions.
Requirements
Education & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related technical field.
- Minimum 5 years of hands-on experience in cybersecurity, security operations, incident response, or defensive security engineering.
- Minimum 3 years of direct experience in SOC operations, Blue Team activities, incident response, detection engineering, threat hunting, or cybersecurity investigations.
- Proven experience investigating and responding to incidents involving malware, phishing, compromised accounts, unauthorized access, and data-security events.
- Hands-on experience with SIEM, EDR/XDR, DLP, ZTNA, vulnerability management, WAF, IAM, and security-monitoring solutions.
- Experience developing and improving SIEM queries, detection rules, dashboards, alerts, and monitoring use cases.
- Experience analyzing security events across endpoints, networks, identity platforms, applications, and cloud environments.
- Experience developing incident-response playbooks, investigation procedures, technical documentation, or security automation.
- Experience supporting vulnerability assessments, security reviews, and technical remediation activities.
- Experience mentoring or providing technical guidance to junior cybersecurity professionals is preferred.
- Experience in retail, e-commerce, financial services, or technology environments is preferred.
Certifications
Candidates with relevant professional certifications are preferred, including:
- Offensive Security SOC-200 OSDA or equivalent.
- Blue Team Level 1 (BTL1) or Blue Team Level 2 (BTL2).
- GIAC certifications related to incident response, intrusion analysis, or digital forensics.
- AWS or equivalent cloud-security certifications.
- Vendor-specific certifications related to SIEM, EDR/XDR, DLP, ZTNA, MDM, WAF, or other security technologies.
Technical Skills
- Enterprise SIEM and centralized security-monitoring platforms.
- EDR/XDR and endpoint-security solutions.
- Network security technologies including firewalls, IDS/IPS, VPN, proxies, DNS security, and WAF.
- Vulnerability-management tools such as Nessus, Qualys, Rapid7, or equivalent.
- DLP, email security, phishing analysis, and data-protection solutions.
- Cloud security monitoring, cloud logging, and identity-security solutions.
- IAM, MFA, SSO, PAM, and privileged-access monitoring.
- Security automation and scripting using Python, PowerShell, Bash, or similar languages.
- SIEM query languages, log-analysis techniques, and incident-management platforms.
- Windows and Linux security investigation tools.
- Strong understanding of MITRE ATT&CK, attacker techniques, threat intelligence, and cybersecurity frameworks.
Skills & Competencies
- Strong knowledge of cybersecurity operations, SOC processes, and incident-response methodologies.
- Strong understanding of network-security concepts including TCP/IP, DNS, HTTP/HTTPS, TLS, VPNs, and firewalls.
- Strong analytical, troubleshooting, and problem-solving skills.
- Ability to investigate security incidents and determine their impact and severity.
- Strong threat-hunting and detection-engineering capabilities.
- Ability to prioritize multiple alerts and investigations based on risk and business impact.
- Strong technical documentation and reporting skills.
- Excellent communication and stakeholder-management skills.
- Ability to provide technical guidance and mentor junior team members.
- Proactive mindset with a strong commitment to continuous learning and staying current with evolving cybersecurity threats.
- Fluent in English and Arabic.