هدف الدور: أخصائي أول SOC مسؤول عن تحليل البيانات الأمنية المتقدمة للحوادث، والتحقيق المعقد في الحوادث، وتحسين مستمر لقدرات الكشف والاستجابة في SOC. يعمل كخبير فني من المستوى الثالث ومدير فني، يقدم التوجيه للمحللين المبتدئين، يطور حالات استخدام متقدمة، ويضمن أن آليات الكشف وتدفقات العمل المرتبطة بالحوادث مهيأة للدقة والسرعة والمرونة. كما يتCollaborates مع فرق استخبارات التهديد وإدارة الثغرات لبناء موقف دفاعي استباقي عبر جميع البيئات التي تتم مراقبتها.
المسؤوليات
القيادة الاستراتيجية والتقنية
- قيادة تحقيقات حوادث متقدمة عبر عدة مجالات أمنية بما في ذلك الشبكة ونقاط النهاية والتطبيقات والبيئات السحابية.
- إجراء تحليل جذر السبب (RCA) بشكل معمق ودعم الاستجابة للحوادث الكبرى والتحقيقات الجنائية كجزء من التصعيد من المستوى 3.
- تصميم وتحسين منطق الكشف وقواعد الترابط ضمن منصات SIEM وSOAR وEDR.
- تطوير كتب تشغيل الأتمتة لتبسيط أنشطة الفرز والاحتواء، مما يقلل من MTTR وMTTD.
- إجراء صيد التهديدات بشكل استباقي استناداً إلى تقارير استخباراتية والتحليلات السلوكية واكتشاف الانحرافات.
- التنسيق مع مصادر استخبارات التهديد الداخلية والخارجية لوضع السياق على التنبيهات وتحسين نضج الكشف.
- التحقق من تكامل وتضمين موجزات التهديد وضمان إثراء التنبيهات في SOC بإشارات سياقية (IOCs، TTPs، حملات التهديد).
الحوكمة وإدارة العمليات
- الحفاظ على تحسين كتب تشغيل SOC ومصفوفات التصعيد ومواد المعرفة.
- ضمان توافق عمليات SOC مع أطر مثل MITRE ATT&CK وNIST CSF وISO 27035.
- إجراء مراجعات ما بعد الحوادث وورش العمل المستفادة مع أصحاب المصلحة لتعزيز التحسين المستمر.
- دعم الامتثال ومتطلبات التدقيق من خلال جمع الأدلة والتقارير بشكل صحيح.
- المشاركة في تمارين الطاولة الداخلية وضمان جاهزية بروتوكولات استجابة الحوادث.
التعاون وإدارة أصحاب المصلحة
- تقديم الدعم الاستشاري الفني أثناء تصعيدات العملاء أو المراجعات التنفيذية.
- تطوير وتقديم تقارير أسبوعية/شهرية عن أداء SOC واتجاهات التهديدات للإدارة.
- دعم إدخال عملاء جدد إلى خدمات SOC، بما في ذلك إعداد مصادر التسجيل والموصلات ومنطق الترابط.
تطوير الأشخاص والمعرفة
- إرشاد محللي SOC (المستوى-1 والمستوى-2) في تقنيات تحليلية وتحقيقية متقدمة.
- عقد جلسات تبادل معرفة داخلية حول التهديدات الجديدة والثغرات وتقنيات الهجوم الناشئة.
- المساهمة في إنشاء مواد تدريب SOC وتقييمات تقنية.
- دعم مبادرات بناء القدرات من خلال التوصية بخطط الشهادات وتطوير المهارات.
الملف المرغوب فيه للمرشح
- درجة البكالوريوس في تكنولوجيا المعلومات أو الأمن السيبراني أو تخصص ذي صلة.
- يفضل شهادات GCIA، GCIH، CEH، CHFI، CompTIA CySA+، أو SANS Threat Hunting.
- الحد الأدنى 5-7 سنوات في عمليات SOC أو استجابة للحوادث، مع خبرة لا تقل عن سنتين في تحليل Tier-3 أو الأدلة الجنائية المتقدمة.
- المهارات: إدارة SOC، استجابة للتهديد، حوكمة، تقارير العملاء، قيادة الفريق، وإدارة الخدمة.
- نوع الكفاءة: مستوى الكفاءة
- القيادة-Tech Leadership: متقدم
- السلوك - التفكير التحليلي: متقدم
- السلوك - التعاون: متقدم
- الجوهر: النزاهة والمسؤولية: متقدم
- الجوهر: التميز التشغيلي: متقدم
- التقني: الكشف عن التهديد والصيد: متقدم
- التقني: الاختبارات الجنائية والتحليل RCA: متقدم
- التقني: إدارة SIEM/SOAR متقدمة
ROLE OBJECTIVE Senior Specialist SOC is responsible for advanced security event analysis, complex incident investigation, and continuous improvement of SOC detection and response capabilities. Acting as a Tier-3 analyst and technical SME, the role provides guidance to junior analysts, develops advanced use cases, and ensures that all detection mechanisms and incident workflows are optimized for accuracy, speed, and resilience. The incumbent also collaborates with threat intelligence and vulnerability management teams to build a proactive defense posture across all monitored environments.
RESPONSIBILITIES
Strategic and Technical Leadership
- Lead advanced incident investigations across multiple security domains including network, endpoint, application, and cloud environments.
- Perform in-depth root cause analysis (RCA) and support major incident response and forensics as part of L3 escalation.
- Design and optimize detection logic and correlation rules within SIEM, SOAR, and EDR platforms.
- Develop automation playbooks to streamline triage and containment activities, reducing MTTD and MTTR.
- Conduct proactive threat hunting based on intelligence reports, behavioral analytics, and anomaly detection.
- Coordinate with internal and external threat intelligence sources to contextualize alerts and enhance detection maturity.
- Validate and integrate threat feeds and ensure enrichment of SOC alerting with contextual indicators (IOCs, TTPs, threat campaigns).
Governance and Process Management
- Maintain and enhance SOC playbooks, escalation matrices, and knowledge base documentation.
- Ensure SOC processes align with frameworks such as MITRE ATT&CK, NIST CSF, and ISO 27035.
- Conduct post-incident reviews and lessons-learned workshops with stakeholders to drive continuous improvement.
- Support compliance and audit requirements through proper evidence collection and reporting.
- Participate in internal tabletop exercises and ensure readiness of incident response protocols.
Collaboration and Stakeholder Management
- Provide technical advisory support during customer escalations or executive reviews.
- Develop and deliver weekly/monthly SOC performance and threat trend reports to management.
- Support onboarding of new customers into SOC services, including configuration of log sources, connectors, and correlation logic.
People and Knowledge Development
- Mentor SOC Analysts (Tier-1 and Tier-2) in advanced analytical and investigative techniques.
- Conduct internal knowledge-sharing sessions on new threats, vulnerabilities, and emerging attack techniques.
- Contribute to the creation of SOC training materials and technical assessments.
- Support capacity building initiatives by recommending certification and skill development plans.
Desired Candidate Profile
- Bachelor s degree in Information Technology, Cybersecurity, or related discipline.
- GCIA, GCIH, CEH, CHFI, CompTIA CySA+, or SANS Threat Hunting certifications preferred.
- Minimum 5 7 years in SOC operations or incident response, with at least 2 years in Tier-3 analysis or advanced forensics.
- Skills SOC management, threat response, governance, customer reporting, team leadership, and service management.
- Competency Type Competency Proficiency level
- Leadership Technical Leadership Advanced
- Behavioural Analytical Thinking Advanced
- Behavioural Collaboration Advanced
- Core Integrity & Accountability Advanced
- Core Operational Excellence Advanced
- Technical Threat Detection & Hunting Advanced
- Technical Forensics & RCA Advanced
- Technical SIEM/SOAR management Advanced