SOC Development Lead
sirar by stc- Posted 4 hours ago
- Be among the first 10 applicants
Job Description
About the Company
Advanced technology and cybersecurity company (sirar) established by stc, the region's ICT and digital services provider, sirar by stc is a cutting-edge cybersecurity provider that empowers organization to take control of their cyber capabilities and digital environments. As experts in business security and privacy. We offer a comprehensive range of solutions that help you to operate online safely, securely, and efficiently.
Responsibilities:
- Accountable for end-to-end delivery of SOC Development services across all customers, ensuring alignment with MSSP service scope and SLAs.
- Own the lifecycle of SIEM platforms, including onboarding, parsing, normalization, use case development, and reporting.
- Ensure the availability, performance, and integrity of SIEM infrastructure and associated integrations.
- Drive detection engineering maturity, ensuring continuous improvement in use case effectiveness and MITRE ATT&CK coverage.
- Ensure all deliverables meet compliance requirements (e.g., NCA ECC) and audit readiness standards.
- Act as the primary escalation point for all SOC Development-related issues impacting service delivery.
- Ensure alignment between SOC Development outputs and SOC Monitoring needs to enhance detection and response quality.
Academic Qualification:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- Master's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline is preferred.
Professional Certifications:
- Certified Information Systems Security Professional (CISSP)
- SEC699: Purple Team Tactics – Adversary Emulation for Breach Prevention & Detection
- Certified Information Systems Auditor (CISA)
- Splunk Enterprise Security (ES) Certified Admin
- Splunk Certified Developer
- Splunk Enterprise Certified Architect
- Match for Administrators 102
- ThreatStream for Administrators 102
- Integrator 7.1 – Fundamentals
Years of Experience:
- Minimum of 5 years of relevant experience.
Skills:
- Advanced proficiency in stakeholder engagement and consultation with management on cybersecurity challenges and strategic requirements.
- Advanced proficiency in end-to-end implementation and configuration of SIEM and TIP solutions, specifically Splunk and Anomali.
- Advanced proficiency in SIEM and TIP architecture design.
- Advanced knowledge of Splunk and Anomali platforms.
- Advanced proficiency in cybersecurity incident handling and response.
- Advanced proficiency in MSSP content development.
- Advanced knowledge of the latest cybersecurity threat campaigns and attack trends.
- Advanced knowledge of log source integration and onboarding.
- Advanced knowledge of Events of Interest (EoI).
- Advanced proficiency in security content development.
- Advanced proficiency in dashboard development and visualization.
- Advanced proficiency in use case development and tuning.
- Advanced knowledge of the MITRE ATT&CK Framework.
Important Notice for Candidates:
By submitting your application, you confirm that you have read and understood sirar's Candidate Privacy Notice and agree to the processing of your personal data in accordance with it.
