وصف الوظيفة
الأدوار والمسؤوليات
المحلل SOC - المستوى 2 مسؤول عن المراقبة الأمنية المتقدمة، التحقيق في الحوادث، تحليل التهديدات، وعمليات هندسة الكشف ضمن مركز عمليات الأمن لشركة ZainTECH (SOC). يلعب الدور دور نقطة التصعيد الأساسية للحوادث الأمنية التي حُدِّدت من قبل محللي المستوى L1 ويؤدي دوراً حاسماً في التحقق من التهديدات، وإجراء التحقيقات، ودعم أنشطة الاستجابة للحوادث عبر بيئات المؤسسات والحكومات والبنية التحتية الحيوية.
المسؤوليات:
- المراقبة الأمنية والتحقيق في الحوادث
- التحقيق في الحوادث الأمنية التي تصعيدها محللو SOC من المستوى L1 وتحليلها.
- التحقق من أحداث الأمن وتحديد النطاق والتأثير والحدة ومخاطر الأعمال.
- إجراء ترابط وتحليل متقدم للسجلات والتنبيهات ونشاط الشبكة والبيانات الطرفية ومعلومات التهديد.
- إجراء تحليل سبب الحادث وتحديد مؤشرات الاختراق (IOCs).
- دعم احتواء الحوادث وتطهيرها والتعافي منها.
- تصعيد الحوادث التي تتطلب تحقيقاً متخصصاً أو دعم الاستجابة للحوادث.
- الكشف عن التهديدات والصيد عن التهديدات
- إجراء أنشطة صيد التهديدات بشكل استباقي لتحديد نشاط ضار قد يتجاوز الضوابط الآلية.
- استخدام مصادر معلومات التهديدات لتحديد التهديدات الناشئة وتكتيكات المهاجمين.
- تحليل أنماط الهجوم والمؤشرات والسلوكيات المرتبطة بالبرمجيات الخبيثة، وبرامج الفدية، والتهديدات من الداخل، والتهديدات المستمرة المتقدمة (APTs).
- تحديد الفرص لتحسين تغطية الكشف عبر البيئات المراقبة.
- SIEM وهندسة الكشف
- تطوير وت tuning وتحديث حالات استخدام SIEM وقواعد الترابط.
- دعم إنشاء وصيانة منطق الكشف ولوحات القيادة والتقارير والتنبيهات وتدفقات العمل للمراقبة
- تقليل الإيجابيات الكاذبة من خلال الضبط وتحسين القواعد.
- دعم إدراج وتكامل مصادر السجلات الجديدة.
- إدارة الحوادث والإبلاغ
- الحفاظ على سجلات الحوادث ووثائق التحقيق بالتفصيل.
- إعداد التحليل الفني وتقارير الحوادث.
- دعم المقاييس التشغيلية والتقارير ومراجعات الخدمة.
- التأكد من امتثال أنشطة معالجة الحوادث للإجراءات المتبعة وSLA المعتمدة.
- القيادة الفنية ونقل المعرفة
- توفير الإرشاد والتوجيه لمحللي SOC من المستوى L1.
- دعم تطوير المحللين من خلال التدريب ومشاركة المعرفة الفنية.
- المشاركة في مبادرات التحسين المستمر وبرامج نضوج SOC.
- المساهمة في تطوير العمليات والدليل والإجراءات.
الملف المرشح المطلوب
- درجة البكالوريوس أو دبلوم متوسط (الحد الأدنى) من مؤسسة معترف بها.
- خبرة لا تقل عن سنتين في الأمن السيبراني المدارة / عمليات SOC على مستوى التحقيق.
- على الأقل شهادة SOC معتمدة من NCSC مثل (CSA، GSOC، GIAC، GCIA، CTIA) أو شهادة مماثلة في نفس المجال معتمدة من قبل NCSC.
- خبرة قوية في تحقيق SIEM وتطوير قواعد الكشف وتحليل السجلات والشبكة وضبط حالات الاستخدام.
Job Description
Roles & Responsibilities
The SOC Analyst - Tier 2 is responsible for advanced security monitoring, incident investigation, threat analysis, and detection engineering activities within ZainTECH s Security Operations Center (SOC). The role serves as the primary escalation point for security incidents identified by L1 analysts and plays a critical role in validating threats, conducting investigations, and supporting incident response activities across enterprise, government, and critical infrastructure environments.
Responsibilities:
- Security Monitoring & Incident Investigation
- Investigate and analyze security incidents escalated by SOC L1 analysts.
- Validate security events and determine scope, impact, severity, and business risk.
- Perform advanced correlation and analysis of logs, alerts, network activity, endpoint telemetry, and threat intelligence.
- Conduct root cause analysis of security incidents and identify indicators of compromise (IOCs).
- Support incident containment, eradication, and recovery activities.
- Escalate incidents requiring specialized investigation or incident response support.
- Threat Detection & Threat Hunting
- Perform proactive threat hunting activities to identify malicious activity that may bypass automated controls.
- Utilize threat intelligence sources to identify emerging threats and attacker tactics.
- Analyze attack patterns, indicators, and behaviors associated with Malware ,Ransomware ,Insider threats ,Advanced Persistent Threats (APTs)
- Identify opportunities to improve detection coverage across monitored environments.
- SIEM & Detection Engineering
- Develop, tune, and optimize SIEM use cases and correlation rules.
- Support creation and maintenance of Detection logic , Dashboards ,Reports ,Alerts and Monitoring workflows
- Reduce false positives through tuning and rule optimization.
- Support onboarding and integration of new log sources.
- Incident Management & Reporting
- Maintain detailed incident records and investigation documentation.
- Prepare technical analysis and incident reports.
- Support operational metrics, reporting, and service reviews.
- Ensure incident handling activities comply with established procedures and SLAs.
- Technical Leadership & Knowledge Transfer
- Provide guidance and mentoring to L1 SOC Analysts.
- Support analyst development through coaching and technical knowledge sharing.
- Participate in continuous improvement initiatives and SOC maturity programs.
- Contribute to process, playbook, and procedure development.
Desired Candidate Profile
- Bachelor's degree or intermediate diploma (minimum) from a recognised institution.
- Minimum 2 years experience in managed cybersecurity / SOC operations at an investigative level.
- At least one valid NCSC-approved SOC certification like (CSA, GSOC, GIAC, GCIA,CTIA) or another equivalent certification in the same field that is approved by the NCSC.
- Strong SIEM investigation, detection-rule development, log and network analysis, and use-case tuning.