SOC Analyst
# SOC Analyst **INFRA ASSURE** · Doha · `On-site` 🕒 **Статус:** *Опубликовано: 2 дня назад* · *Источник: Indeed* --- ### About the Role About the Role: We are actively seeking a highly skilled Tier 3 SOC Analyst to join our team onsite in Qatar. In this critical role, you will act as the highest level of technical escalation within our Security Operations Center. You will be responsible for tackling complex cyber threats, leading full-lifecycle incident response, proactively hunting for advanced adversaries, and driving detection engineering initiatives. The ideal candidate is a seasoned cybersecurity expert with deep hands-on experience in enterprise SOC environments, possessing strong command over modern SIEM, EDR/XDR, and SOAR technologies. Core Responsibilities: Incident Escalation & Leadership: Serve as the final technical escalation point for high-severity and complex security alerts. Full-Lifecycle Incident Response: Drive investigations from initial detection through containment, eradication, recovery, and post-incident review. Advanced Threat Hunting: Proactively sweep endpoint, network, identity, and cloud environments for hidden threats, mapping findings directly to the MITRE ATT&CK framework. Deep Dive Investigations: Analyze sophisticated attacks, including ransomware, privilege escalation, lateral movement, data exfiltration, and malware. Detection Engineering: Continuously develop, fine-tune, and optimize SIEM correlation rules, custom use cases, and alert logic to eliminate detection blind spots. Automation & Playbooks: Build and maintain comprehensive SOPs, runbooks, and IR playbooks while championing security automation (SOAR) initiatives. Cross-Functional Collaboration: Partner with Infrastructure, Cloud, IAM, and Network teams during critical incidents to ensure rapid mitigation. Mentorship: Elevate the entire SOC by providing technical guidance, training, and support to Tier 1 and Tier 2 analysts. Required Qualifications & Technical Skills: Experience: 8+ years of dedicated cybersecurity experience, heavily focused on SOC operations, incident response, and threat hunting. SIEM Expertise: Deep hands-on experience with top-tier SIEM platforms (e.g., Microsoft Sentinel, Splunk ES, IBM QRadar, or Google Chronicle). EDR/XDR & SOAR: Proven track record utilizing platforms like CrowdStrike, Microsoft Defender XDR, or SentinelOne, alongside SOAR orchestration. Core Fundamentals: Advanced understanding of Windows/Linux OS, Active Directory, network security (TCP/IP, firewalls, proxies, IDS/IPS), and Cloud architectures (Azure, AWS, GCP). Scripting: Proficiency in writing scripts for automation (Python, PowerShell, or Bash). Mandatory Certifications: Candidates must hold at least one active SANS/GIAC certification. Acceptable certifications include: GCIH, GCFA, GCIA, GNFA, GCFE, GCTI, GSOC, or GSEC. Preferred Qualifications: Additional industry-recognized certifications (CISSP, CCSP, OSCP, SC-200/SC-100). Prior experience working in massive enterprise, government, critical infrastructure, or MSSP environments. Familiarity with standard compliance frameworks (NIST, ISO 27001, CIS). Candidate Profile Requirements: Location: Must be willing and able to relocate to Qatar and work 100% onsite. Background Preference: Candidates with significant professional work experience in European markets are highly preferred. Communication: Exceptional written and verbal English skills, capable of translating complex technical forensics into clear stakeholder reports. Flexibility: Willingness to participate in shift work or on-call rotations when critical incidents arise. Experience: SOC: 8 years (Preferred) Location: Doha (Preferred) Work Location: In person
Наблюдалась 2026-09-21, впервые 2026-09-19, источник — Indeed.