drjobs Soc Engineer العربية

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Jobs by Experience drjobs

Not Mentionedyears

Job Location drjobs

Cairo - Egypt

Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Nationality

Any Nationality

Gender

N/A

Vacancy

1 Vacancy

Job Description


1. Ensure that all log sources are reporting to the SIEM platform in order to maintain the availability of the logs.
2. Ensure all the integrated assets are reporting to their relevant solution (such as Data Activity Monitor, File Integrity Monitor, Firewall Monitor, SOAR, or TIP)
3. Monitor the log sources to make sure the log sources are sending proper logs that are used to identify incidents for reporting, detecting incidents and/or contextual data by designing and creating dashboards & periodical reports to ensure that all the integrations are functional and in healthy posture.
4. Implement and fine tune use cases over different SOC technologies (including but not limited to SIEM) as required by Security Intel team to identify incidents.
5. Implement Runbooks & automations for detection and response over SOAR platform.
6. Maintain & enhance TIP technology according to Threat Intel team operation requirements.
7. Integrate new commercial and non-commercial Threat Intel feeds with the TIP solution to enhance SOC detections, identifications, investigation and response.
8. Recommend, develop and release new integrations to maximize the benefits and efficiencies from a SOAR platform.
9. Generate reports as required by SOC management teams to be presented to the management to be used in further data analysis.
10. Work with IT systems owners to establish SIEM & SOAR technologies integrations to meet the strategic goals of identifying security incidents by defining Use Cases.
11. Deployment and Development of customized and non-customized SIEM connectors for supported and unsupported SOC log sources, and modify configuration files to achieve the full integrations with different log sources.
12. Develop scripts (Java, Python, Bash) whenever required for automating SOAR responses and SIEM log collection.
13. Fine tune collected log events to minimize false positive alerts.
14. Prepare reports to ensure compliance with the SOC requirements from regulatory and security perspectives.
15. Ensure effective records of log resources and SOC relevant platforms, to maintain the integrity and availability of all evidences used for incident response
16. Manage the continuous improvement of systems engineering processes and activities to enhance the efficiency and effectiveness of reporting and alerting.
17. Research, analyse and understand log sources utilized for the purpose of security monitoring, particularly security and networking devices (such as firewalls, routers, anti-virus products, proxies, EDR, operating systems, etc…), in order to increase effectiveness of the log correlation.
18. Provide technical inputs to management during proof-of-concept reviews for new security products to ensure alignment with the set policies and guidelines.
19. Provide technical guidance to the Security teams and/or the lines of business during investigations or incident response in order to help in the investigation and root cause analysis.

Employment Type

Full-time

Department / Functional Area

Engineering

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.