Cyber Security Engineer Jobs in Jordan
3726 Jobs Found
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>The Incident Response Analyst is responsible for investigating, containing, eradicating, and supporting the recovery of cybersecurity incidents across customer and enterprise environments. The role plays a critical part in minimizing business impact from cyber threats by coordinating response activities, performing technical investigations, and supporting the continuous improvement of incident response capabilities. The role collaborates closely with Security Operations, Threat Intelligence, Digital Forensics, and customer IT teams to identify attack vectors, contain threats, and strengthen organizational resilience against future incidents. Responsibilities: Incident Investigation & Response Respond to security incidents within defined SLAs and escalation procedures. Perform detailed investigations to determine Nature of the attack, Scope of compromise, Impacted systems, Attack vectors and Potential business impact Analyze indicators of compromise (IOCs) and attacker activity. Identify containment, eradication, and recovery actions required to mitigate incidents. Coordinate incident response activities with internal and customer stakeholders. Threat Analysis & Root Cause Investigation Conduct in-depth analysis of security incidents and suspicious activities. Identify vulnerabilities, attack techniques, and security gaps contributing to incidents. Perform root cause analysis to determine how incidents occurred and identify preventive controls. Analyze attacker tactics, techniques, and procedures (TTPs) using industry frameworks such as MITRE ATT&CK. Incident Coordination & Escalation Manage incident response activities across multiple technical teams. Escalate incidents requiring Digital Forensics support, Specialized technical expertise and Malware analysis Coordinate communication between technical teams, management, and customer stakeholders. Support crisis management activities during major incidents. Documentation & Reporting Prepare detailed incident reports documenting Findings, Impact assessments, Root cause analysis and Remediation recommendations Maintain investigation records and evidence documentation. Support development of executive-level incident summaries and post-incident reviews. Process Improvement & Readiness Support the development and enhancement of Incident response playbooks, Response procedures and Investigation methodologies Participate in tabletop exercises and incident simulations. Identify opportunities to improve response effectiveness and operational readiness.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>Bachelor's degree or intermediate diploma (minimum) from a recognised institution. Minimum 3 years experience in cybersecurity / information security, including 1 or more years in incident response. At least one valid NCSC-approved IR certification like (ECIH, CCIM, Blue Team Level 2) or another equivalent certification in the same field that is approved by the NCSC. Practical skills in log analysis, endpoint and network investigation, malware triage, and use of IR tooling. Exposure to SIEM/SOAR and EDR platforms is preferable. Experience in an MSSP or SOC environment is preferable.</p><p></p></section>
<p><h4>Description</h4>
<p>The incident response analyst is responsible for investigating, containing, eradicating, and supporting the recovery of cybersecurity incidents across customer and enterprise environments. The role plays a critical part in minimizing business impact from cyber threats by coordinating response activities, performing technical investigations, and supporting the continuous improvement of incident response capabilities.</p>
<p>The role collaborates closely with security operations, threat intelligence, digital forensics, and customer IT teams to identify attack vectors, contain threats, and strengthen organizational resilience against future incidents.</p>
<h4>Responsibilities</h4>
<h4>Incident investigation & response</h4>
<ul>
<li>Respond to security incidents within defined SLAs and escalation procedures.</li>
<li>Perform detailed investigations to determine nature of the attack, scope of compromise, impacted systems, attack vectors, and potential business impact.</li>
<li>Analyze indicators of compromise (IOCs) and attacker activity.</li>
<li>Identify containment, eradication, and recovery actions required to mitigate incidents.</li>
<li>Coordinate incident response activities with internal and customer stakeholders.</li>
</ul>
<h4>Threat analysis & root cause investigation</h4>
<ul>
<li>Conduct in-depth analysis of security incidents and suspicious activities.</li>
<li>Identify vulnerabilities, attack techniques, and security gaps contributing to incidents.</li>
<li>Perform root cause analysis to determine how incidents occurred and identify preventive controls.</li>
<li>Analyze attacker tactics, techniques, and procedures (TTPs) using industry frameworks such as MITRE ATT&CK.</li>
</ul>
<h4>Incident coordination & escalation</h4>
<ul>
<li>Manage incident response activities across multiple technical teams.</li>
<li>Escalate incidents requiring digital forensics support, specialized technical expertise, and malware analysis.</li>
<li>Coordinate communication between technical teams, management, and customer stakeholders.</li>
<li>Support crisis management activities during major incidents.</li>
</ul>
<h4>Documentation & reporting</h4>
<ul>
<li>Prepare detailed incident reports documenting findings, impact assessments, root cause analysis, and remediation recommendations.</li>
<li>Maintain investigation records and evidence documentation.</li>
<li>Support development of executive-level incident summaries and post-incident reviews.</li>
</ul>
<h4>Process improvement & readiness</h4>
<ul>
<li>Support the development and enhancement of incident response playbooks, response procedures, and investigation methodologies.</li>
<li>Participate in tabletop exercises and incident simulations.</li>
<li>Identify opportunities to improve response effectiveness and operational readiness.</li>
</ul>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behaviour across everything we do - from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma (minimum) from a recognised institution.</li>
<li>Minimum 3 years experience in cybersecurity / information security, including 1 or more years in incident response.</li>
<li>At least one valid NCSC-approved IR certification like ECIH, CCIM, Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Practical skills in log analysis, endpoint and network investigation, malware triage, and use of IR tooling.</li>
<li>Exposure to SIEM/SOAR and EDR platforms is preferable.</li>
<li>Experience in an MSSP or SOC environment is preferable.</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The SOC analyst - tier 1 is responsible for providing 24x7 security monitoring, alert triage, event analysis, and incident escalation services within ZainTECH’s managed security operations center (SOC). As the first line of defense against cybersecurity threats, the role continuously monitors customer environments, validates security events, and ensures potential security incidents are identified, classified, documented, and escalated in accordance with established procedures and service level agreements.</p>
<h4>Responsibilities:</h4>
<p><strong>Security monitoring & event analysis</strong></p>
<ul>
<li>Provide continuous 24x7 monitoring of customer and enterprise security environments through shift-based operations.</li>
<li>Monitor and analyze security events generated from SIEM platforms, IDS/IPS solutions, endpoint detection & response (EDR) tools, firewalls, email security gateways, web security solutions, and cloud security platforms.</li>
<li>Review and assess security alerts to determine whether activity represents a legitimate security threat or a false positive.</li>
<li>Perform initial event validation, classification, and prioritization based on severity, risk, and potential business impact.</li>
<li>Identify suspicious behavior, indicators of compromise (IOCs), and anomalous activities requiring further investigation.</li>
</ul>
<p><strong>Incident triage & escalation</strong></p>
<ul>
<li>Perform first-level analysis and triage of security alerts and events.</li>
<li>Create and manage incident tickets within approved incident management platforms.</li>
<li>Categorize incidents based on severity, impact, urgency, and threat classification.</li>
<li>Escalate validated incidents to SOC analyst - tier 2 teams in accordance with approved escalation procedures.</li>
<li>Ensure escalations include complete and accurate investigation details to support efficient handover and further analysis.</li>
<li>Maintain incident tracking and ensure timely updates throughout the incident lifecycle.</li>
</ul>
<p><strong>SIEM operations & security monitoring</strong></p>
<ul>
<li>Utilize SIEM platforms to monitor security events, review alerts, execute predefined searches and queries, support basic investigations.</li>
<li>Support operational activities including alert validation, monitoring dashboard review, log analysis, and security event correlation.</li>
<li>Assist with identifying false positives and escalating tuning recommendations where required.</li>
<li>Support the overall effectiveness and reliability of monitoring operations.</li>
</ul>
<p><strong>Documentation & reporting</strong></p>
<ul>
<li>Maintain accurate records of investigations, observations, and escalation activities.</li>
<li>Document security incidents and monitoring activities in accordance with operational procedures.</li>
<li>Participate in shift handovers and ensure continuity of investigations between teams.</li>
<li>Support operational reporting and SOC performance metrics activities.</li>
</ul>
<p><strong>Governance, compliance & operational excellence</strong></p>
<ul>
<li>Follow approved SOC procedures, playbooks, and operational standards.</li>
<li>Ensure compliance with internal security policies, customer contractual obligations, and NCSC Jordan licensing requirements.</li>
<li>Handle customer information with strict confidentiality and professionalism.</li>
<li>Participate in training, simulation exercises, and continuous improvement initiatives.</li>
<li>Maintain awareness of emerging cybersecurity threats and attack techniques.</li>
</ul>
<h4>Our culture & code of conduct:</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma from a recognised institution.</li>
<li>At least 6 months of practical cybersecurity experience.</li>
<li>At least one valid NCSC-approved SOC certification like CSA, GSOC, GCIA, CTIA, Blue Team Level 1, or Cisco CyberOps Associate, or another internationally recognised, equivalent certification in the same field that is approved by the NCSC.</li>
<li>Familiarity with SIEM consoles, alert triage, and SOC monitoring workflow; willingness to work rotating shifts.</li>
<li>Foundational networking and operating-system knowledge is preferable.</li>
<li>Prior internship or junior SOC experience is preferable.</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The digital forensics analyst is responsible for conducting forensic investigations, evidence acquisition, preservation, analysis, and reporting activities in support of cybersecurity incidents, legal investigations, regulatory requirements, and internal security matters. The role plays a critical part in identifying the source, scope, and impact of cyber incidents while ensuring the integrity and admissibility of digital evidence.</p>
<p>The role works closely with incident response teams, security operations, legal stakeholders, and customer representatives to investigate cyber incidents, collect forensic evidence, and provide technical findings that support decision-making, remediation, and potential legal proceedings.</p>
<h4>Responsibilities</h4>
<p><strong>Digital evidence acquisition & preservation</strong><br>
Perform forensic acquisition of digital evidence from workstations, servers, mobile devices, virtual environments, cloud platforms, and removable media.<br>
Ensure proper chain of custody procedures are followed throughout investigations.<br>
Preserve evidence integrity using approved forensic methodologies and tools.<br>
Conduct live and dead-box forensic acquisitions.<br>
Maintain forensic evidence repositories and documentation.</p>
<p><strong>Forensic investigation & analysis</strong><br>
Analyze digital evidence to identify unauthorized access, data theft, insider threats, malware activity, data destruction attempts, and policy violations.<br>
Examine file systems, registry artifacts, event logs, browser artifacts, user activity records, and network evidence.<br>
Conduct timeline analysis and event reconstruction activities.<br>
Support attribution efforts and attack path analysis where applicable.</p>
<p><strong>Reporting & documentation</strong><br>
Prepare detailed forensic reports documenting the methodology, findings, evidence collected, and conclusions.<br>
Present findings to technical and non-technical stakeholders.<br>
Maintain investigation records in accordance with regulatory and legal requirements.<br>
Support expert witness preparation activities where required.</p>
<p><strong>Research & continuous improvement</strong><br>
Maintain awareness of emerging attack techniques, anti-forensics methodologies, and digital investigation trends.<br>
Support the development of investigation procedures, forensic methodologies, and evidence handling standards.<br>
Participate in technical training and capability development initiatives.</p>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do—from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma (minimum) from a recognised institution.</li>
<li>Minimum 2 years experience in cybersecurity, including at least 2 completed digital forensic investigations.</li>
<li>At least one valid NCSC-approved forensics certification like GCFE, GCFA, CHFI, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Hands-on use of forensic tools and sound evidence-handling practice.</li>
<li>Exposure to mobile and cloud forensics is preferable.</li>
<li>Experience in an MSSP, lab, or law-enforcement forensic environment is preferable.</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The Specialist Network Engineer - Cisco Security is responsible for designing, implementing, and supporting enterprise network security solutions with a primary focus on Cisco Identity Services Engine (ISE) and Cisco Firepower technologies (FTD & FMC). The role involves managing network access control (NAC), authentication services, firewall policies, VPN solutions, and advanced threat protection to ensure secure and reliable enterprise infrastructure operations. The engineer works closely with network, infrastructure, and security teams to deploy and optimize security controls across wired, wireless, and remote access environments. Key responsibilities include configuring Cisco ISE for authentication, authorization, posture assessment, and device profiling, as well as administering Cisco Firepower firewalls, IPS, AMP, and URL filtering features.</p>
<p>The role also includes monitoring security infrastructure, troubleshooting complex network security issues, performing system upgrades, and responding to security incidents. Additionally, the engineer is responsible for maintaining security documentation, enforcing organizational security standards, and contributing to continuous improvement initiatives to strengthen the company’s overall security posture. The ideal candidate should possess strong hands-on experience with Cisco security technologies, enterprise networking concepts, and security best practices.</p>
<h4>Responsibilities</h4>
<ul>
<li><strong>Cisco ISE (Identity Services Engine) Administration</strong>
<ul>
<li>Design, deploy, and maintain Cisco ISE solutions for Network Access Control (NAC)</li>
<li>Configure and manage AAA services using:
<ul>
<li>802.1X</li>
<li>MAB</li>
<li>TACACS+</li>
</ul>
</li>
<li>Manage and support:
<ul>
<li>Guest access portals</li>
<li>BYOD onboarding</li>
<li>Posture assessment policies</li>
</ul>
</li>
<li>Integrate Cisco ISE with Active Directory and identity management systems</li>
<li>Troubleshoot authentication and authorization issues across wired and wireless environments</li>
<li>Define and enforce access control policies based on user roles, device profiling, and security posture</li>
</ul>
</li>
<li><strong>Cisco Firepower (FTD & FMC) Management</strong>
<ul>
<li>Manage Cisco Firepower (FTD & FMC) environments</li>
<li>Firewall policies</li>
<li>Site-to-site and remote access VPNs</li>
<li>Monitor security features like IPS, AMP, URL filtering</li>
<li>Perform upgrades, patching, and security monitoring</li>
</ul>
</li>
<li><strong>Security Operations</strong>
<ul>
<li>Monitor and troubleshoot network security issues</li>
<li>Support incident response and root cause analysis</li>
<li>Ensure infrastructure availability and compliance</li>
</ul>
</li>
<li><strong>Documentation & Continuous Improvement</strong>
<ul>
<li>Maintain documentation of security configurations, policies, and operational procedures</li>
<li>Contribute to the development of network security standards and best practices</li>
<li>Identify opportunities to improve security posture, operational efficiency, and infrastructure resilience</li>
</ul>
</li>
</ul>
<h4>Requirements</h4>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent experience</li>
<li>3–5+ years of experience in network security or security engineering roles</li>
<li>Hands-on experience with Cisco ISE and Cisco Firepower (FTD & FMC) technologies</li>
<li>Experience supporting enterprise-scale network security environments and NAC solutions</li>
<li>Strong understanding of TCP/IP networking, VLANs, routing, switching, and security architectures</li>
<li>Experience with VPN technologies, firewall policy management, and security monitoring/log analysis</li>
<li>Knowledge of enterprise security best practices, access control frameworks, and incident troubleshooting</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The Specialist Network Engineer - Cisco Security is responsible for designing, implementing, and supporting enterprise network security solutions with a primary focus on Cisco Identity Services Engine (ISE) and Cisco Firepower technologies (FTD & FMC). The role involves managing network access control (NAC), authentication services, firewall policies, VPN solutions, and advanced threat protection to ensure secure and reliable enterprise infrastructure operations. The engineer works closely with network, infrastructure, and security teams to deploy and optimize security controls across wired, wireless, and remote access environments. Key responsibilities include configuring Cisco ISE for authentication, authorization, posture assessment, and device profiling, as well as administering Cisco Firepower firewalls, IPS, AMP, and URL filtering features.</p>
<p>The role also includes monitoring security infrastructure, troubleshooting complex network security issues, performing system upgrades, and responding to security incidents. Additionally, the engineer is responsible for maintaining security documentation, enforcing organizational security standards, and contributing to continuous improvement initiatives to strengthen the company’s overall security posture. The ideal candidate should possess strong hands-on experience with Cisco security technologies, enterprise networking concepts, and security best practices.</p>
<h4>Responsibilities</h4>
<ul>
<li><strong>Cisco ISE (Identity Services Engine) Administration</strong>
<ul>
<li>Design, deploy, and maintain Cisco ISE solutions for Network Access Control (NAC)</li>
<li>Configure and manage AAA services using:
<ul>
<li>802.1X</li>
<li>MAB</li>
<li>TACACS+</li>
</ul>
</li>
<li>Manage and support:
<ul>
<li>Guest access portals</li>
<li>BYOD onboarding</li>
<li>Posture assessment policies</li>
</ul>
</li>
<li>Integrate Cisco ISE with Active Directory and identity management systems</li>
<li>Troubleshoot authentication and authorization issues across wired and wireless environments</li>
<li>Define and enforce access control policies based on user roles, device profiling, and security posture</li>
</ul>
</li>
<li><strong>Cisco Firepower (FTD & FMC) Management</strong>
<ul>
<li>Manage Cisco Firepower (FTD & FMC) environments</li>
<li>Firewall policies</li>
<li>Site-to-site and remote access VPNs</li>
<li>Monitor security features like IPS, AMP, URL filtering</li>
<li>Perform upgrades, patching, and security monitoring</li>
</ul>
</li>
<li><strong>Security Operations</strong>
<ul>
<li>Monitor and troubleshoot network security issues</li>
<li>Support incident response and root cause analysis</li>
<li>Ensure infrastructure availability and compliance</li>
</ul>
</li>
<li><strong>Documentation & Continuous Improvement</strong>
<ul>
<li>Maintain documentation of security configurations, policies, and operational procedures</li>
<li>Contribute to the development of network security standards and best practices</li>
<li>Identify opportunities to improve security posture, operational efficiency, and infrastructure resilience</li>
</ul>
</li>
</ul>
<h4>Requirements</h4>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent experience</li>
<li>3–5+ years of experience in network security or security engineering roles</li>
<li>Hands-on experience with Cisco ISE and Cisco Firepower (FTD & FMC) technologies</li>
<li>Experience supporting enterprise-scale network security environments and NAC solutions</li>
<li>Strong understanding of TCP/IP networking, VLANs, routing, switching, and security architectures</li>
<li>Experience with VPN technologies, firewall policy management, and security monitoring/log analysis</li>
<li>Knowledge of enterprise security best practices, access control frameworks, and incident troubleshooting</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The Network Engineer - Cisco Security is responsible for designing, implementing, and supporting enterprise network security solutions with a primary focus on Cisco Identity Services Engine (ISE) and Cisco Firepower technologies (FTD & FMC). The role involves managing network access control (NAC), authentication services, firewall policies, VPN solutions, and advanced threat protection to ensure secure and reliable enterprise infrastructure operations. The engineer works closely with network, infrastructure, and security teams to deploy and optimize security controls across wired, wireless, and remote access environments. Key responsibilities include configuring Cisco ISE for authentication, authorization, posture assessment, and device profiling, as well as administering Cisco Firepower firewalls, IPS, AMP, and URL filtering features.</p>
<p>The role also includes monitoring security infrastructure, troubleshooting complex network security issues, performing system upgrades, and responding to security incidents. Additionally, the engineer is responsible for maintaining security documentation, enforcing organizational security standards, and contributing to continuous improvement initiatives to strengthen the company’s overall security posture. The ideal candidate should possess strong hands-on experience with Cisco security technologies, enterprise networking concepts, and security best practices.</p>
<h4>Responsibilities:</h4>
<ul>
<li><strong>Cisco ISE (Identity Services Engine) Administration</strong></li>
<li>Design, deploy, and maintain Cisco ISE solutions for Network Access Control (NAC)</li>
<li>Configure and manage AAA services using:
<ul>
<li>802.1X</li>
<li>MAB</li>
<li>TACACS+</li>
</ul>
</li>
<li>Manage and support:
<ul>
<li>Guest access portals</li>
<li>BYOD onboarding</li>
<li>Posture assessment policies</li>
</ul>
</li>
<li>Integrate Cisco ISE with Active Directory and identity management systems</li>
<li>Troubleshoot authentication and authorization issues across wired and wireless environments</li>
<li>Define and enforce access control policies based on user roles, device profiling, and security posture</li>
<li><strong>Cisco Firepower (FTD & FMC) Management</strong></li>
<li>Manage Cisco Firepower (FTD & FMC) environments</li>
<li>Firewall policies</li>
<li>Site-to-site & remote access VPNs</li>
<li>Monitor security features like IPS, AMP, URL filtering</li>
<li>Perform upgrades, patching, and security monitoring</li>
<li><strong>Security Operations</strong></li>
<li>Monitor and troubleshoot network security issues</li>
<li>Support incident response and root cause analysis</li>
<li>Ensure infrastructure availability and compliance</li>
<li><strong>Documentation & Continuous Improvement</strong></li>
<li>Maintain documentation of security configurations, policies, and operational procedures</li>
<li>Contribute to the development of network security standards and best practices</li>
<li>Identify opportunities to improve security posture, operational efficiency, and infrastructure resilience</li>
</ul>
<h4>Requirements</h4>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent experience</li>
<li>3–5+ years of experience in network security or security engineering roles</li>
<li>Hands-on experience with Cisco ISE and Cisco Firepower (FTD & FMC) technologies</li>
<li>Experience supporting enterprise-scale network security environments and NAC solutions</li>
<li>Strong understanding of TCP/IP networking, VLANs, routing, switching, and security architectures</li>
<li>Experience with VPN technologies, firewall policy management, and security monitoring/log analysis</li>
<li>Knowledge of enterprise security best practices, access control frameworks, and incident troubleshooting</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The Network Engineer - Cisco Security is responsible for designing, implementing, and supporting enterprise network security solutions with a primary focus on Cisco Identity Services Engine (ISE) and Cisco Firepower technologies (FTD & FMC). The role involves managing network access control (NAC), authentication services, firewall policies, VPN solutions, and advanced threat protection to ensure secure and reliable enterprise infrastructure operations. The engineer works closely with network, infrastructure, and security teams to deploy and optimize security controls across wired, wireless, and remote access environments. Key responsibilities include configuring Cisco ISE for authentication, authorization, posture assessment, and device profiling, as well as administering Cisco Firepower firewalls, IPS, AMP, and URL filtering features.</p>
<p>The role also includes monitoring security infrastructure, troubleshooting complex network security issues, performing system upgrades, and responding to security incidents. Additionally, the engineer is responsible for maintaining security documentation, enforcing organizational security standards, and contributing to continuous improvement initiatives to strengthen the company’s overall security posture. The ideal candidate should possess strong hands-on experience with Cisco security technologies, enterprise networking concepts, and security best practices.</p>
<h4>Responsibilities:</h4>
<ul>
<li><strong>Cisco ISE (Identity Services Engine) Administration</strong></li>
<li>Design, deploy, and maintain Cisco ISE solutions for Network Access Control (NAC)</li>
<li>Configure and manage AAA services using:
<ul>
<li>802.1X</li>
<li>MAB</li>
<li>TACACS+</li>
</ul>
</li>
<li>Manage and support:
<ul>
<li>Guest access portals</li>
<li>BYOD onboarding</li>
<li>Posture assessment policies</li>
</ul>
</li>
<li>Integrate Cisco ISE with Active Directory and identity management systems</li>
<li>Troubleshoot authentication and authorization issues across wired and wireless environments</li>
<li>Define and enforce access control policies based on user roles, device profiling, and security posture</li>
<li><strong>Cisco Firepower (FTD & FMC) Management</strong></li>
<li>Manage Cisco Firepower (FTD & FMC) environments</li>
<li>Firewall policies</li>
<li>Site-to-site & remote access VPNs</li>
<li>Monitor security features like IPS, AMP, URL filtering</li>
<li>Perform upgrades, patching, and security monitoring</li>
<li><strong>Security Operations</strong></li>
<li>Monitor and troubleshoot network security issues</li>
<li>Support incident response and root cause analysis</li>
<li>Ensure infrastructure availability and compliance</li>
<li><strong>Documentation & Continuous Improvement</strong></li>
<li>Maintain documentation of security configurations, policies, and operational procedures</li>
<li>Contribute to the development of network security standards and best practices</li>
<li>Identify opportunities to improve security posture, operational efficiency, and infrastructure resilience</li>
</ul>
<h4>Requirements</h4>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent experience</li>
<li>3–5+ years of experience in network security or security engineering roles</li>
<li>Hands-on experience with Cisco ISE and Cisco Firepower (FTD & FMC) technologies</li>
<li>Experience supporting enterprise-scale network security environments and NAC solutions</li>
<li>Strong understanding of TCP/IP networking, VLANs, routing, switching, and security architectures</li>
<li>Experience with VPN technologies, firewall policy management, and security monitoring/log analysis</li>
<li>Knowledge of enterprise security best practices, access control frameworks, and incident troubleshooting</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The penetration testing team leader is responsible for leading ZainTECH’s licensed penetration testing capability within the cybersecurity advisory services practice. The role oversees the delivery of offensive security engagements across enterprise, government, and critical infrastructure customers throughout the MENA region, ensuring all testing activities are performed in accordance with industry best practices, recognized testing methodologies, and NCSC Jordan licensing requirements. The role combines hands-on technical leadership with team management, customer engagement, and service governance responsibilities.</p>
<p>Also responsible for managing penetration testing engagements, developing offensive security capabilities, assuring quality of deliverables, and strengthening customer security postures through actionable remediation guidance.</p>
<h4>Responsibilities</h4>
<p><strong>Penetration testing engagement leadership</strong><br>
Lead and manage penetration testing engagements across infrastructure, web, wireless, and applications to a recognized methodology.<br>
Define engagement scope, objectives, testing methodology, and rules of engagement.<br>
Ensure all testing activities are conducted safely and within approved customer authorizations.<br>
Manage engagement timelines, resources, and delivery quality.<br>
Act as the primary technical lead throughout the penetration testing lifecycle.</p>
<p><strong>Offensive security delivery</strong><br>
Perform advanced penetration testing activities using both manual and automated testing techniques.<br>
Identify, validate, and demonstrate security vulnerabilities and attack paths.<br>
Assess exploitability, business impact, and risk exposure associated with identified findings.<br>
Conduct vulnerability assessments, penetration testing, security validation exercises, configuration reviews, and red team-style activities where applicable.<br>
Support retesting activities following remediation efforts.</p>
<p><strong>Quality assurance & technical review</strong><br>
Review and validate penetration testing findings prior to customer delivery.<br>
Ensure reports are technically accurate, risk-rated appropriately, actionable and business-focused, and aligned with industry standards.<br>
Review attack chains and exploitation methodologies to ensure consistency and quality.<br>
Maintain testing methodologies aligned with OWASP Testing Guide, PTES, OSSTMM, NIST guidance, and industry best practices.</p>
<p><strong>Customer engagement & advisory services</strong><br>
Present technical findings and executive summaries to customer stakeholders.<br>
Conduct remediation workshops and technical review sessions.<br>
Support customers in understanding security risks, threat exposure, and recommended remediation activities.<br>
Provide strategic guidance on improving overall security posture.<br>
Support presales activities, customer workshops, and cybersecurity assessments where required.</p>
<p><strong>Team leadership & capability development</strong><br>
Lead, mentor, and develop penetration testers within the cybersecurity practice.<br>
Conduct technical coaching, skills development programs, knowledge-sharing sessions, and offensive security training initiatives.<br>
Support recruitment, onboarding, and capability development activities.<br>
Ensure team certifications remain current and aligned with NCSC requirements.<br>
Drive continuous improvement across offensive security methodologies and tooling.</p>
<p><strong>Governance, compliance & service development</strong><br>
Ensure compliance with NCSC Jordan licensing requirements, internal security policies, customer contractual obligations, and regulatory requirements.<br>
Enforce secure testing practices, confidentiality requirements, and evidence handling procedures.<br>
Support service development initiatives to expand ZainTECH’s offensive security capabilities.<br>
Maintain operational documentation, testing standards, and quality assurance processes.<br>
Coordinate reporting and compliance activities required by NCSC and other regulatory stakeholders.</p>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree (minimum) in information technology or a related field.</li>
<li>Minimum 5 years experience in cybersecurity, including at least 5 completed penetration testing projects.</li>
<li>At least one valid NCSC-approved penetration testing certification like CPENT, CEPT, OSCE, LPT, CPT, GPEN, or another internationally recognized, equivalent certification in the same field that is approved by the NCSC.</li>
<li>Deep, hands-on offensive skills across network, web, wireless, and application testing, and command of recognized methodologies (OWASP, PTES, OSSTMM).</li>
<li>Leadership: proven ability to lead a testing team and present to client executives.</li>
<li>Advanced degree in cybersecurity or a related discipline is preferable.</li>
<li>Advanced credentials such as OSCE, CPENT, LPT, or GPEN are preferable.</li>
<li>Experience in red teaming or an MSSP/consultancy offensive practice is preferable.</li>
</ul></p><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>A platform you can believe in: Immersive One is the leading cyber resilience solution across the globe.</strong></p><br><p><strong>Showcase the value of the Immersive One platform and secure the technical win alongside a team of the brightest minds in cybersecurity. At Immersive, we’re uniquely positioned to future-proof organizations against any cyber challenge. If that excites you, read on!!</strong></p><br><p>Immersive is the cyber proving ground for the AI enterprise. Through Immersive One, organizations can test whether people, AI-enabled workflows, cyber security teams, agents, and leaders can perform securely under realistic pressure, then turn that performance into evidence they can use to improve, benchmark, and report readiness.</p><br><p>Trusted by 30%+ of the Fortune 100 and ranked #1 in the Forrester Wave™ 2026, Immersive helps organizations prove AI can be adopted safely, teams can develop and defend at AI speed, leaders can lead through crisis, and AI agents can be validated before they are trusted in live workflows</p><br><p><strong>https://www.immersivelabs.com/why-immersive-labs</strong></p><br><p>We help the world’s biggest brands like Citi, Pfizer, Humana, and HSBC, protect their revenues and brand reputations.</p><br><p><br>Immersive was founded in 2017, from a cargo container in Bristol, UK we’ve grown to over 300 employees globally, announced funding of more than $180 million and been voted a Best place to work on multiple occasions!</p><br><p><u>https://www.immersivelabs.com/company/our-story</u></p><br><p><em>“The speed at which Immersive Labs produces technical content is hugely impressive, and this turnaround has helped get our teams ahead of the curve, giving them hands-on experience with serious vulnerabilities, in a secure environment, as soon as they emerge.”</em></p><br><p>Head of Global Cybersecurity Operations, HSBC</p><br><p><br><strong>Solutions Consultant - Jordan <br></strong>We’re looking for an experienced cybersecurity professional with a number of years experience across the entire customer lifecycle - from pre-sales to post-sales and professional services - to join our growing Customer Experience team as a <strong>Solutions Consultant </strong>based in Jordan covering the METNA & APAC region. </p><br><p>The <strong>Scale Team</strong> at Immersive is a high-velocity engine that serves a large volume of customers and prospects through a fast, repeatable, digitally-led motion. As a Solution Consultant on the Scale Team, you'll own technical pre-sales and the first two months of onboarding across many accounts, and deliver one-to-many enablement that gets customers to value quickly and supports their migration to the Immersive One Core platform.</p><br><p>This is a role for someone who's energised by breadth, pace, and impact at scale — who'd rather run a sharp, repeatable motion across many customers than immerse deeply in a single account. You'll work as part of the Scale Team alongside our Inside Sales Reps and Customer Operations, turning qualified opportunities into demos, trials, onboardings, and adoption — fast!</p><br><strong>What You'll Do</strong><strong>Pre-sales demos and trials</strong><ul><li><p>Deliver product demonstrations built on the qualification Sales has completed, tailored quickly to the prospect's use case</p><br></li><li><p>Rank solution fit (Green / Yellow / Red / NA) to steer where Sales invests their time</p><br></li><li><p>Set up and run in-platform free trials, with one or two coaching sessions to guide prospects through the key features — proving value live, without bespoke success plans or post-POV reports</p><br></li><li><p>Answer technical questions and flag obvious blockers early</p><br></li><li><p>Maintain strong working knowledge of the Immersive platform and competitor technologies</p><br></li></ul><strong>Onboard new customers (first 60 days)</strong><ul><li><p>Run kick-off sessions and deliver a contained onboarding within a strict two-month window across a small number of meetings</p><br></li><li><p>Provide light-touch integration guidance — point customers to documentation and standard connectors, and route deeper technical needs to Support</p><br></li><li><p>Run month-one and month-two check-in and coaching sessions, with the digital academy as the core enablement engine</p><br></li></ul><strong>Drive adoption and migration at scale</strong><ul><li><p>Deliver one-to-many activities — webinars, workshops, and Cyber Digital Bootcamps — to drive adoption and value across the customer base</p><br></li><li><p>Support the phased migration of Standard customers to Immersive One Core, contributing to repeatable enablement content and self-serve resources</p><br></li><li><p>Re-engage on expansion when a signal appears, running the same light demo / trial-coaching motion for the expansion scope</p><br></li></ul><strong>Across everything</strong><ul><li><p>Partner closely with Inside Sales Reps and Customer Operations to keep the motion efficient</p><br></li><li><p>Serve as the voice of the customer to our product, content, and engineering teams to influence innovation</p><br></li><li><p>Stay informed of evolving threats, AI, trends, and new technologies</p><br></li></ul><strong>Sounds good? We’d love to hear from you if you have proven experience in the following areas, but don’t worry if you don’t hit each one exactly, although experience working within cybersecurity is essential:</strong><ul><li><p>2+ years in sales engineering, solutions consulting, technical onboarding, or a technical customer-facing role — ideally in a SaaS or cybersecurity environment</p><br></li><li><p>Comfortable working at high volume and pace, running repeatable motions across many accounts and keeping engagements within tight time boxes</p><br></li><li><p>You're a confident presenter to both technical and non-technical audiences, including one-to-many formats such as webinars and bootcamps</p><br></li><li><p>Able to qualify and prioritise quickly, and to communicate technical concepts in a clear, jargon-free way</p><br></li><li><p>Proficiency in IT fundamentals (computer hardware/software, databases, networking, security, and software development)</p><br></li><li><p>Knowledge of information security concepts, domains, compliance, and standards</p><br></li></ul><ul><li><p>Experience delivering onboarding, enablement, or one-to-many sessions at scale</p><br></li><li><p>Familiarity with product-led growth (PLG) or digitally-led customer motions</p><br></li><li><p>Hands-on experience with Windows & Linux operating systems, security tools (IDS, firewalls, anti-malware, SIEM), and public cloud environments would be useful but not essential</p><br><p><strong>Immersive’s growth has been fuelled by our values that underpin everything we do, here's how they relate to this role:</strong></p><br></li><li><p><strong>Driven</strong> - We push the boundaries of innovation, acting swiftly to achieve ambitious outcomes. Our drive embodies a culture of ambition, where challenges are stepping stones to excellence.</p><br></li><li><p><strong>Inclusive</strong> - Our strength lies in diversity, fostering a culture where every individual contributes to our collective strength. We champion open dialogue and empathy, ensuring a collaborative, inclusive workplace.</p><br></li><li><p><strong>Customer Centric</strong> - We seek to develop deep relationships with our customers to help them achieve their business outcomes. We exceed our customers and partners expectations by crafting products, services and experience that surprise, delight and ensuring they feel valued and supported every day.</p><br></li><li><p><strong>One Team - </strong>We are a talented global team working together to achieve our vision. Central to our ethos, resilience means adapting and thriving in adversity. It guides our innovation, ensuring we and our clients are prepared for the future.</p><br></li></ul><p>If you would like to read more about what you can expect from our recruitment process, you can visit our dedicated <u>interview process</u> page.</p><br><p><strong><br>As well as an inclusive, supportive place for you to be you. We offer an extensive range of benefits so you can do your very best work:</strong></p><br><ul><li><p>Time off, flexible and remote working so you can work when is best for you, includes 25 days annual leave + 2 volunteering days and birthday half day</p><br></li><li><p>Look after your family and yourself with enhanced parental leave, mindfulness groups, critical illness cover,</p><br></li><li><p>Career and learning development through the platform and our ‘Learn Anything’ fund</p><br></li><li><p>Share in the companies success with share options, sales incentives and Recognition & Rewards for doing great work and living our values and behaviours</p><br></li><li><p>Informal or formal flexible working options, e.g. flexible start and finish times, reduced hours, job share, remote working</p><br></li><li><p>We’re a sociable, tight-knit team with monthly socials, and sports clubs. Our socials have included everything from pottery painting and paper mask making, to movie nights and escape rooms</p><br></li><li><p>While this is a remote position, we do all meet in our EMEA HQ on a bi annual basis and regularly in person in region.</p><br></li></ul><p>Find out more about life at Immersive <u>https://careers.immersivelabs.com</u></p><br><p><strong>Cyber threats wait for no one and neither should you. Apply now!</strong></p><br><p><strong><br>If you would like to read more about what you can expect from our recruitment process, you can visit our dedicated interview process page.</strong></p><br> </div>
<p><h4>Description</h4>
<p>The incident response analyst is responsible for investigating, containing, eradicating, and supporting the recovery of cybersecurity incidents across customer and enterprise environments. The role plays a critical part in minimizing business impact from cyber threats by coordinating response activities, performing technical investigations, and supporting the continuous improvement of incident response capabilities.</p>
<p>The role collaborates closely with security operations, threat intelligence, digital forensics, and customer IT teams to identify attack vectors, contain threats, and strengthen organizational resilience against future incidents.</p>
<h4>Responsibilities</h4>
<h4>Incident investigation & response</h4>
<ul>
<li>Respond to security incidents within defined SLAs and escalation procedures.</li>
<li>Perform detailed investigations to determine nature of the attack, scope of compromise, impacted systems, attack vectors, and potential business impact.</li>
<li>Analyze indicators of compromise (IOCs) and attacker activity.</li>
<li>Identify containment, eradication, and recovery actions required to mitigate incidents.</li>
<li>Coordinate incident response activities with internal and customer stakeholders.</li>
</ul>
<h4>Threat analysis & root cause investigation</h4>
<ul>
<li>Conduct in-depth analysis of security incidents and suspicious activities.</li>
<li>Identify vulnerabilities, attack techniques, and security gaps contributing to incidents.</li>
<li>Perform root cause analysis to determine how incidents occurred and identify preventive controls.</li>
<li>Analyze attacker tactics, techniques, and procedures (TTPs) using industry frameworks such as MITRE ATT&CK.</li>
</ul>
<h4>Incident coordination & escalation</h4>
<ul>
<li>Manage incident response activities across multiple technical teams.</li>
<li>Escalate incidents requiring digital forensics support, specialized technical expertise, and malware analysis.</li>
<li>Coordinate communication between technical teams, management, and customer stakeholders.</li>
<li>Support crisis management activities during major incidents.</li>
</ul>
<h4>Documentation & reporting</h4>
<ul>
<li>Prepare detailed incident reports documenting findings, impact assessments, root cause analysis, and remediation recommendations.</li>
<li>Maintain investigation records and evidence documentation.</li>
<li>Support development of executive-level incident summaries and post-incident reviews.</li>
</ul>
<h4>Process improvement & readiness</h4>
<ul>
<li>Support the development and enhancement of incident response playbooks, response procedures, and investigation methodologies.</li>
<li>Participate in tabletop exercises and incident simulations.</li>
<li>Identify opportunities to improve response effectiveness and operational readiness.</li>
</ul>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behaviour across everything we do - from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma (minimum) from a recognised institution.</li>
<li>Minimum 3 years experience in cybersecurity / information security, including 1 or more years in incident response.</li>
<li>At least one valid NCSC-approved IR certification like ECIH, CCIM, Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Practical skills in log analysis, endpoint and network investigation, malware triage, and use of IR tooling.</li>
<li>Exposure to SIEM/SOAR and EDR platforms is preferable.</li>
<li>Experience in an MSSP or SOC environment is preferable.</li>
</ul></p><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>The Incident Response Analyst is responsible for investigating, containing, eradicating, and supporting the recovery of cybersecurity incidents across customer and enterprise environments.<br> The role plays a critical part in minimizing business impact from cyber threats by coordinating response activities, performing technical investigations, and supporting the continuous improvement of incident response capabilities.<br> The role collaborates closely with Security Operations, Threat Intelligence, Digital Forensics, and customer IT teams to identify attack vectors, contain threats, and strengthen organizational resilience against future incidents.<br> Responsibilities: Incident Investigation & Response Respond to security incidents within defined SLAs and escalation procedures.<br> Perform detailed investigations to determine Nature of the attack, Scope of compromise, Impacted systems, Attack vectors and Potential business impact Analyze indicators of compromise (IOCs) and attacker activity.<br> Identify containment, eradication, and recovery actions required to mitigate incidents.<br> Coordinate incident response activities with internal and customer stakeholders.<br> Threat Analysis & Root Cause Investigation Conduct in-depth analysis of security incidents and suspicious activities.<br> Identify vulnerabilities, attack techniques, and security gaps contributing to incidents.<br> Perform root cause analysis to determine how incidents occurred and identify preventive controls.<br> Analyze attacker tactics, techniques, and procedures (TTPs) using industry frameworks such as MITRE ATT&CK.<br> Incident Coordination & Escalation Manage incident response activities across multiple technical teams.<br> Escalate incidents requiring Digital Forensics support, Specialized technical expertise and Malware analysis Coordinate communication between technical teams, management, and customer stakeholders.<br> Support crisis management activities during major incidents.<br> Documentation & Reporting Prepare detailed incident reports documenting Findings, Impact assessments, Root cause analysis and Remediation recommendations Maintain investigation records and evidence documentation.<br> Support development of executive-level incident summaries and post-incident reviews.<br> Process Improvement & Readiness Support the development and enhancement of Incident response playbooks, Response procedures and Investigation methodologies Participate in tabletop exercises and incident simulations.<br> Identify opportunities to improve response effectiveness and operational readiness.<br> Our Culture & Code of Conduct: At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity.<br> We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence.<br> All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behaviour across everything we do — from how we work with each other to how we engage with clients and partners globally.<br> Bachelor's degree or intermediate diploma (minimum) from a recognised institution.<br> Minimum 3 years experience in cybersecurity / information security, including 1 or more years in incident response.<br> At least one valid NCSC-approved IR certification like (ECIH, CCIM, Blue Team Level 2) or another equivalent certification in the same field that is approved by the NCSC.<br> Practical skills in log analysis, endpoint and network investigation, malware triage, and use of IR tooling.<br> Exposure to SIEM/SOAR and EDR platforms is preferable.<br> Experience in an MSSP or SOC environment is preferable.<br></span> </div>
<p><h4>Description</h4>
<p>The incident response team leader is responsible for leading cybersecurity incident response activities, managing complex investigations, and overseeing the delivery of incident response services across customer and enterprise environments. The role provides technical leadership, operational oversight, and strategic direction for incident response engagements while ensuring effective coordination of resources during security incidents.</p>
<p>This role serves as the primary escalation point for major cybersecurity incidents and plays a key role in strengthening incident response readiness, improving operational maturity, and ensuring compliance with NCSC licensing requirements.</p>
<h4>Responsibilities</h4>
<p><strong>Incident response leadership</strong><br>
Lead cybersecurity incident response engagements from identification through recovery.<br>
Direct technical response teams during major security incidents, ransomware attacks, and data breaches.<br>
Coordinate containment, eradication, recovery, and remediation activities.<br>
Act as the primary incident commander during major incidents.</p>
<p><strong>Advanced incident investigation</strong><br>
Oversee complex investigations involving malware outbreaks, insider threats, targeted attacks, and data exfiltration incidents.<br>
Validate investigation findings and response recommendations.<br>
Provide technical leadership during high-severity incidents.<br>
Support digital forensics activities where required.</p>
<p><strong>Team management & development</strong><br>
Lead, mentor, and develop incident response analysts.<br>
Conduct technical coaching, performance management, skills development initiatives, and incident response readiness activities.<br>
Support recruitment and onboarding of new team members.<br>
Drive continuous capability development across the incident response function.</p>
<p><strong>Governance & stakeholder management</strong><br>
Serve as the primary customer-facing lead during major incidents.<br>
Provide executive briefings and incident status updates.<br>
Support regulatory, compliance, and reporting obligations.<br>
Ensure adherence to incident response policies, service level agreements, and NCSC operational requirements.</p>
<p><strong>Program development & continuous improvement</strong><br>
Develop and maintain incident response frameworks, playbooks, runbooks, and response procedures.<br>
Lead tabletop exercises and simulation activities.<br>
Conduct post-incident reviews and lessons learned sessions.<br>
Drive improvements to organizational cyber resilience and response capabilities.</p>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do—from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree (minimum) in information technology or a related field.</li>
<li>Minimum 5 years in cybersecurity/information security, including 3 or more years specifically in incident response.</li>
<li>At least one valid NCSC-approved IR certification like ECIH, CCIM, Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Technical command: hands-on expertise in incident triage, forensics-aware investigation, containment, and recovery across endpoint, network, and cloud.</li>
<li>Leadership: proven ability to lead an analyst team under pressure and communicate clearly with clients and the NCSC.</li>
<li>Advanced degree in cybersecurity or a related discipline is preferable.</li>
<li>Additional credentials such as GCIH, GCFA, or vendor EDR/SOAR are preferable.</li>
<li>Experience in an MSSP, telco-affiliated SOC, or national CERT/CSIRT environment is preferable.</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The incident response team leader is responsible for leading cybersecurity incident response activities, managing complex investigations, and overseeing the delivery of incident response services across customer and enterprise environments. The role provides technical leadership, operational oversight, and strategic direction for incident response engagements while ensuring effective coordination of resources during security incidents.</p>
<p>This role serves as the primary escalation point for major cybersecurity incidents and plays a key role in strengthening incident response readiness, improving operational maturity, and ensuring compliance with NCSC licensing requirements.</p>
<h4>Responsibilities</h4>
<p><strong>Incident response leadership</strong><br>
Lead cybersecurity incident response engagements from identification through recovery.<br>
Direct technical response teams during major security incidents, ransomware attacks, and data breaches.<br>
Coordinate containment, eradication, recovery, and remediation activities.<br>
Act as the primary incident commander during major incidents.</p>
<p><strong>Advanced incident investigation</strong><br>
Oversee complex investigations involving malware outbreaks, insider threats, targeted attacks, and data exfiltration incidents.<br>
Validate investigation findings and response recommendations.<br>
Provide technical leadership during high-severity incidents.<br>
Support digital forensics activities where required.</p>
<p><strong>Team management & development</strong><br>
Lead, mentor, and develop incident response analysts.<br>
Conduct technical coaching, performance management, skills development initiatives, and incident response readiness activities.<br>
Support recruitment and onboarding of new team members.<br>
Drive continuous capability development across the incident response function.</p>
<p><strong>Governance & stakeholder management</strong><br>
Serve as the primary customer-facing lead during major incidents.<br>
Provide executive briefings and incident status updates.<br>
Support regulatory, compliance, and reporting obligations.<br>
Ensure adherence to incident response policies, service level agreements, and NCSC operational requirements.</p>
<p><strong>Program development & continuous improvement</strong><br>
Develop and maintain incident response frameworks, playbooks, runbooks, and response procedures.<br>
Lead tabletop exercises and simulation activities.<br>
Conduct post-incident reviews and lessons learned sessions.<br>
Drive improvements to organizational cyber resilience and response capabilities.</p>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do—from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree (minimum) in information technology or a related field.</li>
<li>Minimum 5 years in cybersecurity/information security, including 3 or more years specifically in incident response.</li>
<li>At least one valid NCSC-approved IR certification like ECIH, CCIM, Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Technical command: hands-on expertise in incident triage, forensics-aware investigation, containment, and recovery across endpoint, network, and cloud.</li>
<li>Leadership: proven ability to lead an analyst team under pressure and communicate clearly with clients and the NCSC.</li>
<li>Advanced degree in cybersecurity or a related discipline is preferable.</li>
<li>Additional credentials such as GCIH, GCFA, or vendor EDR/SOAR are preferable.</li>
<li>Experience in an MSSP, telco-affiliated SOC, or national CERT/CSIRT environment is preferable.</li>
</ul></p><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>The Incident Response Team Leader is responsible for leading cybersecurity incident response activities, managing complex investigations, and overseeing the delivery of incident response services across customer and enterprise environments.<br> The role provides technical leadership, operational oversight, and strategic direction for incident response engagements while ensuring effective coordination of resources during security incidents.<br> This role serves as the primary escalation point for major cybersecurity incidents and plays a key role in strengthening incident response readiness, improving operational maturity, and ensuring compliance with NCSC licensing requirements.<br> Responsibilities: Incident Response Leadership Lead cybersecurity incident response engagements from identification through recovery.<br> Direct technical response teams during Major security incidents, Ransomware attacks and Data breaches Coordinate containment, eradication, recovery, and remediation activities.<br> Act as the primary incident commander during major incidents.<br> Advanced Incident Investigation Oversee complex investigations involving Malware outbreaks, Insider threats, Targeted attacks and Data exfiltration incidents Validate investigation findings and response recommendations.<br> Provide technical leadership during high-severity incidents.<br> Support digital forensics activities where required.<br> Team Management & Development Lead, mentor, and develop Incident Response Analysts.<br> Conduct Technical coaching, Performance management, Skills development initiatives and Incident response readiness activities Support recruitment and onboarding of new team members.<br> Drive continuous capability development across the incident response function.<br> Governance & Stakeholder Management Serve as the primary customer-facing lead during major incidents.<br> Provide executive briefings and incident status updates.<br> Support regulatory, compliance, and reporting obligations.<br> Ensure adherence to Incident response policies, Service level agreements and NCSC operational requirements Program Development & Continuous Improvement Develop and maintain Incident response frameworks, Playbooks, Runbooks and Response procedures Lead tabletop exercises and simulation activities.<br> Conduct post-incident reviews and lessons learned sessions.<br> Drive improvements to organizational cyber resilience and response capabilities.<br> Our Culture & Code of Conduct: At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity.<br> We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence.<br> All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.<br> Bachelor's degree (minimum) in information technology or a related field.<br> Minimum 5 years in cybersecurity / information security, including 3 or more years specifically in incident response.<br> At least one valid NCSC-approved IR certification like (ECIH , CCIM, or Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.<br> Technical command.<br> Hands-on expertise in incident triage, forensics-aware investigation, containment, and recovery across endpoint, network, and cloud.<br> Leadership.<br> Proven ability to lead an analyst team under pressure and communicate clearly with clients and the NCSC.<br> Advanced degree in cybersecurity or a related discipline is preferable.<br> Additional credentials such as GCIH, GCFA, or vendor EDR/SOAR is preferable.<br> Experience in an MSSP, telco-affiliated SOC, or national CERT/CSIRT environment is preferable.<br></span> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>The Penetration Testing Team Leader is responsible for leading ZainTECH’s licensed penetration testing capability within the Cybersecurity Advisory Services practice.<br> The role oversees the delivery of offensive security engagements across enterprise, government, and critical infrastructure customers throughout the MENA region, ensuring all testing activities are performed in accordance with industry best practices, recognized testing methodologies, and NCSC Jordan licensing requirements.<br> The role combines hands-on technical leadership with team management, customer engagement, and service governance responsibilities.<br> Also responsible for managing penetration testing engagements, developing offensive security capabilities, assuring quality of deliverables, and strengthening customer security postures through actionable remediation guidance.<br> Responsibilities: Penetration Testing Engagement Leadership Lead and manage penetration testing engagements across infrastructure, web, wireless and applications to a recognized methodology.<br> Define engagement scope, objectives, testing methodology, and rules of engagement.<br> Ensure all testing activities are conducted safely and within approved customer authorizations.<br> Manage engagement timelines, resources, and delivery quality.<br> Act as the primary technical lead throughout the penetration testing lifecycle.<br> Offensive Security Delivery Perform advanced penetration testing activities using both manual and automated testing techniques.<br> Identify, validate, and demonstrate security vulnerabilities and attack paths.<br> Assess exploitability, business impact, and risk exposure associated with identified findings.<br> Conduct Vulnerability assessments, Penetration testing, Security validation exercises, Configuration reviews and Red Team-style activities where applicable Support retesting activities following remediation efforts.<br> Quality Assurance & Technical Review Review and validate penetration testing findings prior to customer delivery.<br> Ensure reports are Technically accurate, Risk-rated appropriately, Actionable and business-focused and Aligned with industry standards Review attack chains and exploitation methodologies to ensure consistency and quality.<br> Maintain testing methodologies aligned with OWASP Testing Guide, PTES, OSSTMM, NIST guidance and Industry best practices Customer Engagement & Advisory Services Present technical findings and executive summaries to customer stakeholders.<br> Conduct remediation workshops and technical review sessions.<br> Support customers in understanding Security risks, Threat exposure and Recommended remediation activities Provide strategic guidance on improving overall security posture.<br> Support presales activities, customer workshops, and cybersecurity assessments where required.<br> Team Leadership & Capability Development Lead, mentor, and develop penetration testers within the Cybersecurity Practice.<br> Conduct Technical coaching, Skills development programs, Knowledge-sharing sessions and Offensive security training initiatives Support recruitment, onboarding, and capability development activities.<br> Ensure team certifications remain current and aligned with NCSC requirements.<br> Drive continuous improvement across offensive security methodologies and tooling.<br> Governance, Compliance & Service Development Ensure compliance with NCSC Jordan licensing requirements, Internal security policies, Customer contractual obligations and Regulatory requirements Enforce secure testing practices, confidentiality requirements, and evidence handling procedures.<br> Support service development initiatives to expand ZainTECH’s offensive security capabilities.<br> Maintain operational documentation, testing standards, and quality assurance processes.<br> Coordinate reporting and compliance activities required by NCSC and other regulatory stakeholders.<br> Our Culture & Code of Conduct: At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity.<br> We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence.<br> All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.<br> Bachelor's degree (minimum) in information technology or a related field.<br> Minimum 5 years experience in cybersecurity, including at least 5 completed penetration testing projects.<br> At least one valid NCSC-approved penetration testing certification like (CPENT, CEPT, OSCE, LPT, CPT, GPEN), or another internationally recognized, equivalent certification in the same field that is approved by the NCSC and published on its official website.<br>. Deep, hands-on offensive skills across network, web, wireless, and application testing, and command of recognized methodologies (OWASP, PTES, OSSTMM).<br> Leadership.<br> Proven ability to lead a testing team and present to client executives.<br> Advanced degree in cybersecurity or a related discipline is preferable.<br> Advanced credentials such as OSCE, CPENT, LPT, or GPEN is preferable.<br> Experience in red teaming or an MSSP/consultancy offensive practice is preferable.<br></span> </div>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Overview Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and 16,000 people work alongside our clients, here and abroad, to tackle their most complex challenges with integrity, respect, responsibility, and professionalism. The SharePoint Administrator/Developer will provide enterprise-level SharePoint administration, development, and customer support to military and civilian users. This role requires expertise in SharePoint infrastructure design, deployment, customization, and maintenance to ensure optimal system performance and user experience. The administrator will be responsible for gathering business requirements, designing tailored SharePoint solutions, and implementing best practices for collaboration, document management, automation, and security. This position demands strong skills in SharePoint Online, SharePoint 2019, Power Platform (Power Automate, Power Apps, Power BI), and Microsoft 365 integration to enhance operational efficiency. The candidate will work closely with stakeholders to analyze business needs, develop scalable solutions, and ensure compliance with enterprise security policies and military standards. Program: OMDAC-SWACA This position offers company-paid housing and transportation, a completion bonus and tuition reimbursement program! You must satisfy all host country requirements to legally work in the host country to include but not limited to the ability to obtain and maintain a host nation visa and host nation driver s license in order to be qualified for this position.</p>
<p>Responsibilities</p>
<ul>
<li>Administer and configure Microsoft SharePoint 2019 and SharePoint Online at an enterprise level.</li>
<li>Manage SharePoint Enterprise Search, including index configurations and scheduling.</li>
<li>Plan, install, and maintain service packs, hotfixes, updates, and patches in a multi-server SharePoint environment during off-peak hours.</li>
<li>Utilize tools such as Event Viewer, ULS logs, Power BI, and Microsoft Graph API for troubleshooting and performance monitoring.</li>
<li>Implement Microsoft 365 integration, including Teams, OneDrive, and Power Platform (Power Apps, Power Automate, and Power BI).</li>
<li>Develop and maintain high-level technical and engineering documentation.</li>
<li>Act as the SharePoint subject matter expert, providing training and end-user support.</li>
<li>Demonstrate expertise in modern web development technologies, including SPFx (SharePoint Framework), React, TypeScript, PnP (Patterns and Practices), and the Client-Side Object Model (CSOM).</li>
<li>Customize SharePoint Online and SharePoint 2019 sites using modern design templates, JSON formatting, and adaptive cards.</li>
<li>Develop, automate, and manage workflows using Power Automate (Flow) and Microsoft Forms.</li>
<li>Ensure compliance with Zero Trust Security models, Microsoft Security & Compliance Center policies, and Information Assurance (IA) standards.</li>
<li>Apply Security Technical Implementation Guidelines (STIGs) for governance and security.</li>
<li>Troubleshoot site-related issues, manage user permissions, and assist with site creation and configuration.</li>
<li>Automate SharePoint administration tasks using PowerShell and Microsoft Graph API.</li>
<li>Assist database administrators with configuring and monitoring SQL Server databases supporting.</li>
<li>Performs other duties and assignments as required.</li>
</ul>
<p>Qualifications</p>
<ul>
<li>Security Clearance: Requires an active Secret Clearance</li>
<li>Education / Certifications: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience. Associate Degree or equivalent experience preferably in Computer Science or MIS, IS, Engineering or related field. This position requires candidates to adhere to DoD 8570.01. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline certifications cannot also be used as a Computing Environment (CE) certification. The authorized certifications for this job title are listed as follows: BASELINE: Cisco: CCNA: Certified Network Associate - Security Cisco: CCNP: Certified Network Professional - Security CompTIA: CASP+ ce: Advanced Security Practitioner CompTIA: Security+ ce CompTIA: SecurityX ce GIAC: GCED: Certified Enterprise Defender GIAC: GCIH: Certified Incident Handler GIAC: GICSP: Industrial Cyber Security Professional GIAC: GSEC: Security Essentials ISC2: CISSP ( or Associate ): Certified Information Systems Security Professional COMPUTING ENVIRONMENT (CE): Microsoft: 365 Certified: Enterprise Administrator Expert Microsoft: Certified: Azure Database Administrator Associate Microsoft: Certified: Azure Security Engineer Associate Microsoft: Certified: Azure Solutions Architect Expert Microsoft: MCA: Certified Architect (Any) Microsoft: MCITP: Database Administrator 2008 Microsoft: MCITP: Database Developer 2008 Microsoft: MCITP: Enterprise Administrator Microsoft: MCITP: SharePoint Administrator 2010 (Technical III for SharePoint Admin only) Microsoft: MCSA: Certified Solutions Associate: SQL Server 2012 Microsoft: MCSA: SQL 2016 Database Admin Microsoft: MCSA: SQL 2016 Database BI Development Microsoft: MCSA: SQL 2016 Database Dev Microsoft: MCSA: Windows Server 2008/2012/2016 Microsoft: MCSD: Microsoft Certified Solutions Developer (Any) Microsoft: MCSE: Core Infrastructure Microsoft: MCSE: Data Management and Analytics Microsoft: MCSE: Productivity Solutions Expert</li>
</ul></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul>
<li>Security Clearance: Requires an active Secret Clearance</li>
<li>Education / Certifications: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience. Associate Degree or equivalent experience preferably in Computer Science or MIS, IS, Engineering or related field. This position requires candidates to adhere to DoD 8570.01. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline certifications cannot also be used as a Computing Environment (CE) certification. The authorized certifications for this job title are listed as follows: BASELINE: Cisco: CCNA: Certified Network Associate - Security Cisco: CCNP: Certified Network Professional - Security CompTIA: CASP+ ce: Advanced Security Practitioner CompTIA: Security+ ce CompTIA: SecurityX ce GIAC: GCED: Certified Enterprise Defender GIAC: GCIH: Certified Incident Handler GIAC: GICSP: Industrial Cyber Security Professional GIAC: GSEC: Security Essentials ISC2: CISSP ( or Associate ): Certified Information Systems Security Professional COMPUTING ENVIRONMENT (CE): Microsoft: 365 Certified: Enterprise Administrator Expert Microsoft: Certified: Azure Database Administrator Associate Microsoft: Certified: Azure Security Engineer Associate Microsoft: Certified: Azure Solutions Architect Expert Microsoft: MCA: Certified Architect (Any) Microsoft: MCITP: Database Administrator 2008 Microsoft: MCITP: Database Developer 2008 Microsoft: MCITP: Enterprise Administrator Microsoft: MCITP: SharePoint Administrator 2010 (Technical III for SharePoint Admin only) Microsoft: MCSA: Certified Solutions Associate: SQL Server 2012 Microsoft: MCSA: SQL 2016 Database Admin Microsoft: MCSA: SQL 2016 Database BI Development Microsoft: MCSA: SQL 2016 Database Dev Microsoft: MCSA: Windows Server 2008/2012/2016 Microsoft: MCSD: Microsoft Certified Solutions Developer (Any) Microsoft: MCSE: Core Infrastructure Microsoft: MCSE: Data Management and Analytics Microsoft: MCSE: Productivity Solutions Expert</li>
<li>Experience: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience. At least five years of hands-on experience with Windows Server administration and Active Directory management, with a strong understanding of security principles, access controls, and compliance best practices in an enterprise environment. Expert proficiency in web design and development, including HTML5, CSS3, JavaScript, and modern SharePoint Framework (SPFx), React, and TypeScript. Proven ability to develop, deploy, and manage SharePoint web parts, lists, libraries, and workflows while designing, maintaining, and administering SharePoint portals. Strong documentation skills with the ability to create technical documentation, user guides, and training materials, along with the capability to interact with key stakeholders, gather business requirements, and translate them into effective SharePoint solutions. Experience working with Infrastructure, Web Servers (IIS), SharePoint Administration, and Microsoft 365 integration, as well as knowledge of Power Platform (Power Automate, Power Apps, Power BI) for workflow automation and business process optimization. Experience with a customer service-oriented company.</li>
<li>Skills & Technology Used: Ability to Administer and configure Microsoft SharePoint 2019 and SharePoint Online at an enterprise level. Manage SharePoint Enterprise Search, including index configurations and scheduling. Ability to Plan, install, and maintain service packs, hotfixes, updates, and patches in a multi-server SharePoint environment during off-peak hours. Ability to Utilize tools such as Event Viewer, ULS logs, Power BI, and Microsoft Graph API for troubleshooting and performance monitoring. Ability to Implement Microsoft 365 integration, including Teams, OneDrive, and Power Platform (Power Apps, Power Automate, and Power BI). Develop and maintain high-level technical and engineering documentation. Act as the SharePoint subject matter expert, providing training and end-user support. Demonstrate expertise in modern web development technologies, including SPFx (SharePoint Framework), React, TypeScript, PnP (Patterns and Practices), and the Client-Side Object Model (CSOM).Demonstrate expertise in modern web development technologies, including: SPFx (SharePoint Framework) React TypeScript PnP (Patterns and Practices) Client-Side Object Model (CSOM)</li>
</ul><p></p></section>
<p><h4>Description</h4>
<p>The SOC analyst - tier 1 is responsible for providing 24x7 security monitoring, alert triage, event analysis, and incident escalation services within ZainTECH’s managed security operations center (SOC). As the first line of defense against cybersecurity threats, the role continuously monitors customer environments, validates security events, and ensures potential security incidents are identified, classified, documented, and escalated in accordance with established procedures and service level agreements.</p>
<h4>Responsibilities:</h4>
<p><strong>Security monitoring & event analysis</strong></p>
<ul>
<li>Provide continuous 24x7 monitoring of customer and enterprise security environments through shift-based operations.</li>
<li>Monitor and analyze security events generated from SIEM platforms, IDS/IPS solutions, endpoint detection & response (EDR) tools, firewalls, email security gateways, web security solutions, and cloud security platforms.</li>
<li>Review and assess security alerts to determine whether activity represents a legitimate security threat or a false positive.</li>
<li>Perform initial event validation, classification, and prioritization based on severity, risk, and potential business impact.</li>
<li>Identify suspicious behavior, indicators of compromise (IOCs), and anomalous activities requiring further investigation.</li>
</ul>
<p><strong>Incident triage & escalation</strong></p>
<ul>
<li>Perform first-level analysis and triage of security alerts and events.</li>
<li>Create and manage incident tickets within approved incident management platforms.</li>
<li>Categorize incidents based on severity, impact, urgency, and threat classification.</li>
<li>Escalate validated incidents to SOC analyst - tier 2 teams in accordance with approved escalation procedures.</li>
<li>Ensure escalations include complete and accurate investigation details to support efficient handover and further analysis.</li>
<li>Maintain incident tracking and ensure timely updates throughout the incident lifecycle.</li>
</ul>
<p><strong>SIEM operations & security monitoring</strong></p>
<ul>
<li>Utilize SIEM platforms to monitor security events, review alerts, execute predefined searches and queries, support basic investigations.</li>
<li>Support operational activities including alert validation, monitoring dashboard review, log analysis, and security event correlation.</li>
<li>Assist with identifying false positives and escalating tuning recommendations where required.</li>
<li>Support the overall effectiveness and reliability of monitoring operations.</li>
</ul>
<p><strong>Documentation & reporting</strong></p>
<ul>
<li>Maintain accurate records of investigations, observations, and escalation activities.</li>
<li>Document security incidents and monitoring activities in accordance with operational procedures.</li>
<li>Participate in shift handovers and ensure continuity of investigations between teams.</li>
<li>Support operational reporting and SOC performance metrics activities.</li>
</ul>
<p><strong>Governance, compliance & operational excellence</strong></p>
<ul>
<li>Follow approved SOC procedures, playbooks, and operational standards.</li>
<li>Ensure compliance with internal security policies, customer contractual obligations, and NCSC Jordan licensing requirements.</li>
<li>Handle customer information with strict confidentiality and professionalism.</li>
<li>Participate in training, simulation exercises, and continuous improvement initiatives.</li>
<li>Maintain awareness of emerging cybersecurity threats and attack techniques.</li>
</ul>
<h4>Our culture & code of conduct:</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma from a recognised institution.</li>
<li>At least 6 months of practical cybersecurity experience.</li>
<li>At least one valid NCSC-approved SOC certification like CSA, GSOC, GCIA, CTIA, Blue Team Level 1, or Cisco CyberOps Associate, or another internationally recognised, equivalent certification in the same field that is approved by the NCSC.</li>
<li>Familiarity with SIEM consoles, alert triage, and SOC monitoring workflow; willingness to work rotating shifts.</li>
<li>Foundational networking and operating-system knowledge is preferable.</li>
<li>Prior internship or junior SOC experience is preferable.</li>
</ul></p><p></p>
<p><h4>Description</h4>
<p>The digital forensics analyst is responsible for conducting forensic investigations, evidence acquisition, preservation, analysis, and reporting activities in support of cybersecurity incidents, legal investigations, regulatory requirements, and internal security matters. The role plays a critical part in identifying the source, scope, and impact of cyber incidents while ensuring the integrity and admissibility of digital evidence.</p>
<p>The role works closely with incident response teams, security operations, legal stakeholders, and customer representatives to investigate cyber incidents, collect forensic evidence, and provide technical findings that support decision-making, remediation, and potential legal proceedings.</p>
<h4>Responsibilities</h4>
<p><strong>Digital evidence acquisition & preservation</strong><br>
Perform forensic acquisition of digital evidence from workstations, servers, mobile devices, virtual environments, cloud platforms, and removable media.<br>
Ensure proper chain of custody procedures are followed throughout investigations.<br>
Preserve evidence integrity using approved forensic methodologies and tools.<br>
Conduct live and dead-box forensic acquisitions.<br>
Maintain forensic evidence repositories and documentation.</p>
<p><strong>Forensic investigation & analysis</strong><br>
Analyze digital evidence to identify unauthorized access, data theft, insider threats, malware activity, data destruction attempts, and policy violations.<br>
Examine file systems, registry artifacts, event logs, browser artifacts, user activity records, and network evidence.<br>
Conduct timeline analysis and event reconstruction activities.<br>
Support attribution efforts and attack path analysis where applicable.</p>
<p><strong>Reporting & documentation</strong><br>
Prepare detailed forensic reports documenting the methodology, findings, evidence collected, and conclusions.<br>
Present findings to technical and non-technical stakeholders.<br>
Maintain investigation records in accordance with regulatory and legal requirements.<br>
Support expert witness preparation activities where required.</p>
<p><strong>Research & continuous improvement</strong><br>
Maintain awareness of emerging attack techniques, anti-forensics methodologies, and digital investigation trends.<br>
Support the development of investigation procedures, forensic methodologies, and evidence handling standards.<br>
Participate in technical training and capability development initiatives.</p>
<h4>Our culture & code of conduct</h4>
<p>At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do—from how we work with each other to how we engage with clients and partners globally.</p>
<h4>Requirements</h4>
<ul>
<li>Bachelor's degree or intermediate diploma (minimum) from a recognised institution.</li>
<li>Minimum 2 years experience in cybersecurity, including at least 2 completed digital forensic investigations.</li>
<li>At least one valid NCSC-approved forensics certification like GCFE, GCFA, CHFI, or another equivalent certification in the same field that is approved by the NCSC.</li>
<li>Hands-on use of forensic tools and sound evidence-handling practice.</li>
<li>Exposure to mobile and cloud forensics is preferable.</li>
<li>Experience in an MSSP, lab, or law-enforcement forensic environment is preferable.</li>
</ul></p><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Job Summary: We are seeking an experienced SIEM Deployment Engineer to lead or support the deployment, configuration, and optimization of Splunk or SIEM solutions across enterprise environments.<br> The ideal candidate will possess strong technical knowledge in security operations, log management, and compliance, along with hands-on experience in implementing for clients.<br> Key Responsibilities: Lead end-to-end deployment of Splunk or SIEM platform, including planning, architecture design, installation, configuration, and tuning.<br> Integrate log sources from various platforms (Windows, Linux, firewalls, routers, endpoint protection, etc.<br>). Develop custom parsers and log normalization rules.<br> Build correlation rules, alerts, dashboards, and reports based on customer requirements.<br> Conduct use case development, threat detection tuning, and optimization of false positives.<br> Collaborate with SOC teams to ensure effective threat monitoring and incident detection.<br> Document implementation procedures, configuration guides, and troubleshooting steps.<br> Provide knowledge transfer and training to internal teams or clients.<br> Ensure compliance with industry standards (e.<br>g., NCA ECC, SAMA CSF, ISO 27001).<br> Required Skills and Qualifications: Bachelor’s degree in Computer Science, Cybersecurity, or related field.<br> 8-10 years of experience in Splunk or SIEM deployment and cybersecurity.<br> Proven experience with LogRhythm SIEM deployment in enterprise environments.<br> Strong understanding of log analysis, incident response, and threat detection.<br> Familiarity with log source integration: Windows Event Logs, Syslog, NetFlow, etc.<br> Scripting experience (PowerShell, Python, etc.<br>) is a plus.<br> Knowledge of cybersecurity frameworks (MITRE ATT&CK, NIST, etc.<br>) is an advantage.<br> LogRhythm certifications (e.<br>g., LogRhythm Deployment Fundamentals, LogRhythm Analyst) are a strong plus.<br></span> </div>