Sobre este puesto de SOC Engineer (Managed SOC) en ZainTECH
The SOC Engineer is responsible for the design, implementation, configuration, and continuous optimization of ZainTECH's Security Operations Centre (SOC) technology platforms, ensuring secure, scalable, and resilient security monitoring services for enterprise and government customers across the MENA region.
This is a hands-on engineering role focused on designing and maintaining Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and supporting security technologies. The role owns the end-to-end lifecycle of security monitoring capabilities - from onboarding new log sources and developing detection content to automating operational workflows and continuously enhancing SOC performance - while ensuring solutions align with customer requirements, cybersecurity best practices, and operational standards.
Responsibilities:
SIEM & Security Platform Engineering
- Design, implement, configure, and maintain enterprise SIEM and SOAR platforms supporting ZainTECH's Managed Security Services portfolio.
- Deploy and maintain highly available, scalable, and secure SOC infrastructure across customer environments.
- Manage platform upgrades, patching, configuration management, and lifecycle activities to ensure platform stability and performance.
- Ensure SOC technologies remain aligned with operational, security, and customer requirements.
Detection Engineering & Security Content
- Develop, maintain, and optimise SIEM detection content, including correlation rules, dashboards, reports, alerts, watchlists, and use cases.
- Improve detection capabilities by analysing emerging threats, attack techniques, and operational trends.
- Reduce false positives through continuous tuning and refinement of detection logic.
- Map detection capabilities to recognised cybersecurity frameworks such as MITRE ATT&CK.
Platform Integration & Automation
- Integrate security technologies, cloud platforms, infrastructure, and third-party solutions into the SIEM ecosystem.
- Develop custom parsers, connectors, and data ingestion mechanisms to support new customer environments.
- Design and implement SOAR playbooks to automate investigation, enrichment, notification, and response activities.
- Optimise data collection, normalisation, and event processing to improve operational efficiency.
Operational Support & Continuous Improvement
- Provide technical support to SOC Analysts during security investigations and major incident response activities.
- Troubleshoot platform issues and perform root cause analysis to maintain service availability.
- Produce technical documentation, implementation guides, and operational runbooks.
- Identify opportunities to improve SOC maturity through automation, process optimisation, and engineering best practices.
- Collaborate with Cybersecurity Consulting, Incident Response, Product Management, and Delivery teams to continuously enhance Managed Security Services.
Our Culture & Code of Conduct:
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- 3-5 years of hands-on experience designing, implementing, and administering SIEM platforms within enterprise or Managed Security Services environments.
- Strong experience with one or more SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, ArcSight, LogRhythm, or Elastic Security.
- Experience integrating multiple security technologies, including EDR, firewalls, IDS/IPS, cloud security platforms, identity platforms, and threat intelligence feeds.
- Working knowledge of Windows, Linux, networking, scripting, APIs, and automation technologies.
- Experience implementing SOAR platforms and security automation workflows.
- Knowledge of MITRE ATT&CK, threat intelligence integration, and detection engineering principles.
- Experience supporting enterprise cloud environments including Microsoft Azure, AWS, or Google Cloud Platform.
- Experience working within a Managed Security Services Provider (MSSP) environment.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security +, CEH or any relevant certification preferred