وصف الوظيفة
تبحث شركة Envision Employment Solutions حالياً عن مهندس سيبراني أمني أول (UCF) لإحدى شركائنا، شركة عالمية رائدة في الاستشارات والتحول الرقمي والخدمات الهندسية والتقنية!
حول: نحن نسعى لتوظيف مهندس سيبراني أمني أول (UCF) ذو خبرة للانضمام إلى فريقنا ولعب دور رئيسي في تعزيز قدرات اكتشاف التهديدات.
في هذا الدور، ستقوم بتصميم وتطوير وتحسين محتوى الاكتشاف الذي يمكّن مركز عمليات الأمن (SOC) من تحديد والاستجابة للتهديدات السيبرانية المت evolving.
بالعمل عن كثب مع فرق معلومات التهديد، الصيد التهديدي، وSOC، ستبني وتحافظ على قواعد اكتشاف عالية الجودة، تعزّز تغطية الاكتشاف، وتحسن باستمرار دقة وفعالية مراقبة الأمان عبر المؤسسة.
المسؤوليات: هندسة الاكتشاف تصميم وتطوير وصيانة قواعد الاكتشاف، التوقيعات، وأدلّة التشغيل.
بناء، اختبار، نشر وتحسين منطق الاكتشاف ضمن مصنع حالات الاستخدام (UCF).
التحقق من قدرات الاكتشاف ضد التهديدات الناشئة وتقنيات الهجوم.
ضبط محتوى الاكتشاف باستمرار لتحسين الدقة وتقليل الإيجابيات الكاذبة.
عمليات الأمن نشر وصيانة قدرات الاكتشاف عبر بنية SOC في المؤسسة.
تحليل وترابط أحداث الأمان من مصادر بيانات متعددة.
دعم تحديد وتحقيق في الأنشطة المشبوهة أو الخبيثة.
التعاون مع فرق SOC لتحسين تغطية الاكتشاف والكفاءة التشغيلية.
التوثيق والتحسين المستمر الحفاظ على التوثيق الفني لقواعد الاكتشاف والعمليات والإجراءات التشغيلية.
دعم مبادرات التحسين المستمر من خلال تحديد الفجوات وتقديم تحسينات مقترحة.
البقاء على اطلاع بالتهديدات الناشئة وتقنيات المهاجم وأفضل ممارسات الاكتشاف.
درجة البكالوريوس في علوم الكمبيوتر، الأمن السيبراني، تكنولوجيا المعلومات، أو مجال ذو صلة (مفضل) خبرة من 6-10 سنوات على الأقل في عمليات الأمن السيبراني، هندسة الاكتشاف، أو بيئات SOC خبرة مثبتة في تطوير وإدارة قواعد الاكتشاف ضمن منصات SIEM (مثلاً، Splunk) فهم عميق لتقنيات الأمن السيبراني، مناهج اكتشاف التهديدات، وعمليات الأمن الممتازة في التواصل، العلاقات الشخصية، ومهارات حل المشكلات الطلاقة في اللغة الإنجليزية مكتوبة والمنطوقة مهارات تحليلية وتقارير قوية الكفاءة في أدوات وتقنيات أمان مختلفة، بما في ذلك SIEM (Splunk)، منصات SOAR، لغات البرمجة (Python, PowerShell, Bash)، وخطوط CI/CD
Job description
Envision Employment Solutions is currently looking for a Senior Cybersecurity Engineer (UCF) for one of our partners, a global leader in consulting, digital transformation, technology and engineering services!
About: We are seeking an experienced Senior Cybersecurity Engineer (UCF) to join our team and play a key role in strengthening our threat detection capabilities.
In this role, you will design, develop, and optimize detection content that enables the Security Operations Center (SOC) to identify and respond to evolving cyber threats.
Working closely with Threat Intelligence, Threat Hunting, and SOC teams, you will build and maintain high-quality detection rules, enhance detection coverage, and continuously improve the accuracy and effectiveness of security monitoring across the organization.
Responsibilities: Detection Engineering Design, develop, and maintain detection rules, signatures, and playbooks.
Build, test, deploy, and optimize detection logic within the Use Case Factory (UCF).
Validate detection capabilities against emerging threats and attack techniques.
Continuously tune detection content to improve accuracy and reduce false positives.
Security Operations Deploy and maintain detection capabilities across the organization's SOC infrastructure.
Analyze and correlate security events from multiple data sources.
Support the identification and investigation of suspicious or malicious activities.
Collaborate with SOC teams to improve detection coverage and operational effectiveness.
Documentation & Continuous Improvement Maintain technical documentation for detection rules, processes, and operational procedures.
Support continuous improvement initiatives by identifying gaps and recommending enhancements.
Stay informed on emerging threats, attacker techniques, and detection best practices.
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (preferred) Minimum 6-10 years of experience in cybersecurity operations, detection engineering, or SOC environments Proven experience in developing and managing detection rules within SIEM platforms (e.
g., Splunk) In-depth understanding of cybersecurity technologies, threat detection methodologies, and security operations Excellent communication, interpersonal, and problem-solving skills Fluency in written and spoken English Strong analytical and reporting skills Proficiency in various security tools and technologies, including SIEM (Splunk), SOAR platforms, scripting languages (Python, PowerShell, Bash), and CI/CD pipelines