وصف الوظيفة
Envision Employment Solutions حاليًا يبحث عن مدير SOC لأحد شركائنا، بنك رقمي رائد!
ملخص الوظيفة
يقود مدير SOC مركز عمليات الأمن في البنك، لضمان الكشف والاستجابة والاحتواء والتعافي من حوادث الأمن السيبراني بشكل فعال. تتحمل هذه الدورية مراقبة الأمن على مدار 24/7، والاستجابة للحوادث، وتحليل التهديدات، والتنسيق مع أصحاب المصلحة خلال الحوادث السيبرانية الكبرى، وتكون مركزية لتعزيز مرونة البنك السيبرانية الإجمالية.
المسؤوليات
- قيادة وتنسيق دورة حياة الاستجابة للحوادث السيبرانية بدءًا من التع identification إلى الاحتواء، الاستئصال، والتعافي، والمراجعة بعد الحادث.
- الإشراف على المراقبة الأمنية على مدار 24/7 وأنشطة التعامل مع الحوادث، مع ضمان الالتزام بإجراءات الاستجابة المحددة ومسارات التصعيد وSLA المعتمدة.
- تطوير وصيانة وتحسين أطر الاستجابة للحوادث، وكتب اللعب، والعمليات، وتمارين الجاهزية (مثل تمارين الطاولة، والمحاكاة).
- الإشراف على معلومات التهديد، والصيد التهديدي، والتحقيقات الأمنية لتحديد التهديدات الناشئة بشكل استباقي وتقليل مخاطر المؤسسة.
- التصرف كنقطة تصعيد رئيسية خلال الحوادث السيبرانية الكبرى، بالتنسيق مع الجهات الداخلية والإدارة العليا والفرق المعنية.
- تقديم تقارير الحوادث في الوقت المناسب، وتحليل السبب الجذري، وتوصيات التصحيح للقيادة والجهات التنظيمية عند الطلب.
- إدارة وتوجيه محللي SOC، وضمان تغطية وردية مناسبة، وتطوير المهارات، والاستعداد التشغيلي.
- ضمان أن أدوات SOC (SIEM، SOAR، EDR، منصات معلومات التهديد) مُحسّنة وتُستخدم بفعالية.
- ضمان توافق عمليات SOC مع المتطلبات التنظيمية والامتثال المطبقة على قطاع الخدمات المصرفية.
Job description
Envision Employment Solutions is currently looking for a SOC Manager for one of our partners, a leading Digital Bank!
Job Summary
The SOC Manager leads the Bank's Security Operations Center (SOC), ensuring effective detection, response, containment, and recovery from cybersecurity incidents. This role owns 24/7 security monitoring, incident response, threat analysis, and stakeholder coordination during major cyber incidents, and is central to strengthening the Bank's overall cyber resilience.
Responsibilities
- Lead and coordinate the end-to-end cybersecurity incident response lifecycle, including identification, containment, eradication, recovery, and post-incident review.
- Oversee 24/7 security monitoring and incident handling activities, ensuring adherence to defined response procedures, escalation paths, and SLAs.
- Develop, maintain, and continuously improve incident response frameworks, playbooks, processes, and readiness exercises (e.g., tabletop exercises, simulations).
- Oversee threat intelligence, threat hunting, and security investigations to proactively identify emerging threats and reduce organizational risk.
- Act as the primary escalation point during major cyber incidents, coordinating with internal stakeholders, senior management, and relevant teams.
- Provide timely incident reporting, root cause analysis, and remediation recommendations to leadership and regulatory bodies as required.
- Manage and mentor SOC analysts, ensuring appropriate shift coverage, skill development, and operational readiness.
- Ensure SOC tooling (SIEM, SOAR, EDR, threat intelligence platforms) is optimized and effectively utilized.
- Ensure SOC operations align with regulatory and compliance requirements applicable to the banking sector.