Deloitte Innovation Hub | Cyber Security | SecOps Detection Senior Engineer, Cairo, Egypt
Connect to your career at Deloitte
Deloitte, established globally in 1845, is the world’s largest and leading professional services firm, providing Audit & Assurance, Tax & Legal, Consulting, and related services to public and private clients spanning multiple industries. Present in more than 150 countries, Deloitte is distinct in its ability to help clients solve their most complex problems, from strategy to implementation.
Deloitte Innovation Hub (DIH) is a strategic initiative to support our ambition to become the leading business transformation partner of choice for our clients and to expand and scale our delivery footprint across EMEA. With access to a scaled, diverse, highly skilled, motivated, and engaged workforce, DIH is delivering complex technical solutions for clients’ most complex business problems, across portfolios that include ‘Strategy & Transactions’, ‘Customer’, ‘Engineering, AI & Data’, ‘Enterprise, Technology & Performance’ and ‘Cyber’. DIH is aiming to become the destination for top talents in Egypt for a long, exciting career.
We invest in outstanding people of diverse talents and backgrounds and empower them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we. Our organization has grown in scale and diversity, providing services across the region, with our shared culture remaining the same. We aim to help clients realize their ambitions, make a positive difference in society, and maximize the success of our people. This drive fuels the commitment and humanity that run deep through our every action.
Connect to your opportunity
Responsible for configuring, maintaining, and supporting CSOC platforms, tools, and logging infrastructure ensuring all systems are fully operational and secure. Manage the development, customization, and tuning of security content, including use cases, rules, and playbooks, to effectively detect and respond to cyber threats, ensuring detection logic and automation workflows align with CSOC priorities and cyber threat intelligence.
- Designing and building CSOC technologies such as SIEM, SOAR, EDR, and other platforms.
- Design and develop security content for SIEM, SOAR, and EDR.
- Configure and maintain SIEM, SOAR, EDR, and other CSOC platforms.
- Build and manage logging infrastructure to ensure full telemetry coverage.
- Manage log source onboarding, parsing, normalization, data ingestion pipelines, and enrichment activities.
- Develop, test, and fine-tune detection rules, correlation logic, and alert conditions.
- Map and report detection coverage against frameworks (e.g., MITRE ATT&CK).
- Propose new detection ideas based on threat research and attack simulations.
- Build SOAR playbooks and automation scripts for alert enrichment and incident response.
- Translate threat intelligence, red team findings, and vulnerability data into use cases.
- Perform false-positive analysis and rule optimization to improve fidelity.
- Maintain a content repository with versioning, documentation, and lifecycle status.
- Work with threat monitoring and DFIR teams to validate use case effectiveness.
- Maintain system documentation, configuration baselines, and maintenance records.
- Monitor health and availability of all logging pipelines and tools.
- Conduct root-cause analysis of tool outages or data loss.
Connect to your skills and professional experience
- Bachelor’s degree in Computer Engineering, Computer Science, Information Technology, or a related field.
- 3–6 years of experience in Cybersecurity Operations (CSOC), Detection Engineering, or Detection Content Development.
- Strong understanding of SOC architecture, security technologies, and log management, including ingestion, parsing, enrichment, correlation, and storage best practices.
- Hands-on experience with the design and implementation of SIEM/SOAR platforms, such as Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or similar.
- Solid knowledge of network infrastructure, Linux/Windows administration, and system monitoring, with expertise in security telemetry (firewall, EDR, proxy, and other log sources).
- Proficiency in query and scripting languages (e.g., KQL, SPL, Sigma) for automation, detection tuning, and source validation.
- Familiarity with SOAR automation and orchestration tools (e.g., Cortex XSOAR, Sentinel Logic Apps, or Phantom) and experience designing scalable, reusable detection content.
- In-depth understanding of threat detection concepts, attacker behaviors, and MITRE ATT&CK mapping, including content gap analysis and threat model alignment.
- Strong analytical and troubleshooting skills with the ability to ensure high availability and reliability of security tooling.
- Knowledge of AI/ML concepts and their application in cybersecurity for detection and automation use cases.
- Good communication and coordination skills, with the ability to collaborate effectively across teams such as Threat Monitoring, CTI, and DFIR.
- Strong documentation and version control discipline (e.g., Git, Confluence) and attention to detection accuracy and operational impact.
- Understanding of data integrity, retention policies, and relevant regulatory/compliance standards.
- Relevant certifications in SIEM/SOAR/EDR platforms (e.g., Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or equivalent) are preferred.
Connect to your service line – Technology and Transformation
Distinctive thinking, deep expertise, and collaborative working. That’s what connects us. That’s what makes us Deloitte. If you want to help solve some of the biggest challenges around, join us. Together, we’ll make an impact that matters.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to several audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints. This can mean that you and your immediate family members are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm. The recruitment team will provide further detail as you progress through the recruitment process.
Connect to your industry
“What attracted me to Deloitte were the endless opportunities and the collective experience of other like-minded individuals. Deloitte’s clients include many of the world’s largest organizations; I wanted to be part of a team that made a difference that I could be proud of.” – Dan, T&T.
Connect with your colleagues
Location: Cairo, Egypt
Your work, your way: We call our hybrid working vision Deloitte Works. And it does. We trust you to make the right choices around where, when, and how you work. You’ll be able to make decisions about how you work best, to be collaborative, learn from colleagues, share your experiences, build the relationships that will fuel your career, and prioritize your wellbeing. Having great conversations with your team and your leadership paves the way for great collaborative ways of working.
Our commitment to you
Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
We want you. The true you. Your own strengths, perspective, and personality. So, we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.
Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead.
Connect to your next step!
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see. You’ll be free to bring your true self to work every day. And you’ll never stop growing, whatever your level.
مركز الابتكار من جي دي مورغان Deloitte | الأمن السيبراني | مهندس اكتشاف SecOps أول، القاهرة، مصر
تواصل مع مسيرتك المهنية في Deloitte
تُعد Deloitte مؤسسة خدمات مهنية رائدة عالميًا تأسست في 1845، وهي أكبر شركة خدمات مهنية على مستوى العالم تقدم خدمات التدقيق والضمان، والضرائب والقانون، والاستشارات، والخدمات ذات الصلة للعملاء الحكوميين والشركات عبر صناعات متعددة. متواجدة في أكثر من 150 دولة، وتبرز Deloitte في قدرتها على مساعدة العملاء في حل أكثر مشاكلهم تعقيدًا، من الاستراتيجية حتى التنفيذ.
مركز Deloitte للابتكار (DIH) هو مبادرة استراتيجية لدعم طموحنا في أن نصبح الشريك الرائد في transformation الأعمال المختار لعملائنا ولتوسيع ونطاق حضورنا في التوصيل عبر أوروبا والشرق الأوسط وأفريقيا. مع الوصول إلى فريق عمل متنوع وكبير ومتحفز ومنخرط، يقوم DIH بتقديم حلول تقنية معقدة لمشاكل أعمال عملائنا الأكثر تعقيدًا، عبر محافظ تشمل ’الاستراتيجية والمعاملات‘، ’العملاء‘، ’الهندسة، الذكاء الاصطناعي والبيانات‘، ’المؤسسة، التقنية والأداء‘ و ’الأمن السيبراني‘. يهدف DIH إلى أن يكون الوجهة للمواهب الكبرى في مصر لمسار مهني طويل ومثير.
نستثمر في أشخاص مميزين من مواهب وخلفيات متنوعة ونمكنهم من إنجاز أكثر مما يمكنهم في أماكن أخرى. عملنا يجمع بين النصيحة مع العمل والنزاهة. نؤمن بأن عندما تكون عملائنا والمجتمع أقوى، نكون أقوى أيضًا. نمت مؤسستنا وتنوعها، مع تقديم الخدمات على مستوى المنطقة، وتبقى ثقافتنا المشتركة كما هي. نهدف إلى مساعدة العملاء على تحقيق طموحاتهم وإحداث فرق إيجابي في المجتمع، وتحقيق أقصى درجات النجاح لأناسنا. هذا الدافع يلهم الالتزام والإنسانية التي تتغلغل في كل إجراء من أفعالنا.
تواصل مع فرصة عملك
المسؤول عن تكوين، وصيانة، ودعم منصات CSOC، وأدواتها وبنية الت logging للتأكد من تشغيل جميع الأنظمة بأمان وفعالية. إدارة تطوير وتخصيص وتحسين محتوى الأمن، بما في ذلك حالات الاستخدام، القواعد، وdlplaybooks، لاكتشاف الاستغلال الإلكتروني والرد عليه بشكل فعال، مع التأكد من توافق منطق الكشف وتدفقات التشغيل الآلي مع أولويات CSOC والاستخبارات الخاصة بالتهديدات.
- تصميم وبناء تقنيات CSOC مثل SIEM وSOAR وEDR وغيرها من المنصات.
- تصميم وتطوير محتوى أمني لـ SIEM وSOAR وEDR.
- تكوين وصيانة SIEM وSOAR وEDR وغيرها من منصات CSOC.
- بناء وإدارة بنية تسجيل البيانات لضمان تغطية كاملة للبيانات الحيوية.
- إدارة استيراد مصادر السجلات، والتحليل، والتطبيع، وتدفقات استخراج البيانات، وأنشطة الإثراء.
- تطوير واختبار وتحسين قواعد الكشف ومنطق الترابط وشروط التنبيه.
- رسم تغطية الكشف وتقديم تقارير عنها مقابل الأطر (مثل MITRE ATT&CK).
- اقتراح أفكار كشف جديدة بناءً على أبحاث التهديدات والتجارب الهجومية.
- بناء playbooks لـ SOAR وبرامج أتمتة لتحسين التنبيه والاستجابة للحوادث.
- ترجمة معلومات التهديد والنتائج من فرق الاختبارات والبيانات إلى حالات استخدام.
- إجراء تحليل الإيجابية الكاذبة وتحسين القواعد لتحسين الدقة.
- الحفاظ على مستودع محتوى مع الإصدار والتوثيق وحالة دورة الحياة.
- العمل مع فرق مراقبة التهديدات وDFIR للتحقق من فاعلية حالة الاستخدام.
- المحافظة على وثائق النظام وقواعد التهيئة وسجلات الصيانة.
- مراقبة صحة وتوافر جميع أنابيب التسجيل والأدوات.
- إجراء تحليل السبب الجذري لعطل الأدوات أو فقدان البيانات.
تواصل مع مهاراتك وخبرتك المهنية
- درجة البكالوريوس في هندسة الحاسوب، علوم الحاسب، تكنولوجيا المعلومات، أو مجال ذو صلة.
- 3–6 سنوات خبرة في عمليات الأمن السيبراني (CSOC)، هندسة الكشف، أو تطوير محتوى الكشف.
- فهم قوي لهندسة SOC، تقنيات الأمان، وإدارة السجلات، بما في ذلك الاستيعاب، التحليل، الإثراء، الترابط، وممارسات التخزين.
- خبرة عملية في تصميم وتنفيذ منصات SIEM/SOAR، مثل Splunk، ELK، LogRhythm، Microsoft Sentinel، Palo Alto XSIAM، أو ما يشابه.
- معرفة قوية بالبنية التحتية للشبكات، إدارة Linux/Windows، ومراقبة الأنظمة، مع خبرة في تتبع الأمان (الجدار الناري، EDR، الوكيل، ومصادر السجل الأخرى).
- إتقان لغات الاستعلام والت scripting (مثل KQL، SPL، Sigma) للأتمتة والتعديل في الكشف والتحقق من المصدر.
- إلمام بأدوات SOAR للأتمتة والتنسيق (مثل Cortex XSOAR، Sentinel Logic Apps، أو Phantom) وخبرة في تصميم محتوى كشف قابل لإعادة الاستخدام وقابل للتوسع.
- فهم عميق لمفاهيم اكتشاف التهديدات، وسلوك المهاجم، وتطابق MITRE ATT&CK، بما في ذلك تحليل فجوات المحتوى وتوافق نموذج التهديد.
- مهارات تحليلية ومهارات حل المشكلات قوية مع القدرة على ضمان توافر وأمان أدوات الأمن.
- معرفة بمفاهيم AI/ML وتطبيقها في الأمن السيبراني لحالات الكشف والأتمتة.
- مهارات اتصال وتنسيق جيدة، مع القدرة على العمل بشكل فعال عبر فرق مثل مراقبة التهديدات، CTI، وDFIR.
- انضباط قوي في التوثيق والتحكم في الإصدار (Git، Confluence) والانتباه لدقة الكشف والتأثير التشغيلي.
- فهم لسلامة البيانات، سياسات الاحتفاظ، والمعايير التنظيمية/الامتثال ذات الصلة.
- شهادات ذات صلة بمنصات SIEM/SOAR/EDR (مثل Splunk، ELK، LogRhythm، Microsoft Sentinel، Palo Alto XSIAM، أو ما يعادلها) مفضلة.
تواصل مع خط الخدمة - التكنولوجيا والتحول
التفكير المميز، الخبرة العميقة، والعمل التعاوني. هذا ما يربطنا. هذا ما يجعلنا Deloitte. إذا كنت تريد المساعدة في حل بعض أكبر التحديات من حولك، انضم إلينا. معًا، سنصنع تأثيرًا ذا معنى.
الاستقلالية الشخصية
التنظيم والضوابط هي ممارسة قياسية في صناعتنا، ود Deloitte ليست استثناءً. توفر هذه الضوابط حماية قانونية مهمة لك وللشركة. نحن خاضعون لعدة لوائح تدقيق، أحدها يفرض أن يلتزم بعض الزملاء بقيود استقلال شخصية محددة. هذا قد يعني أنك وأفراد أسرتك المباشرين لا يجوز لكم امتلاك مصالح مالية معينة (أسهم، صناديق، سندات، إلخ) مع عملاء التدقيق في الشركة. سيقدم فريق التوظيف تفاصيل إضافية أثناء تقدمك في عملية التوظيف.
تواصل مع صناعتك
“ما جذبني إلى Deloitte هو الفرص اللامحدودة والتجربة الجماعية لأشخاص ذوي تفكير مماثل. عملاء Deloitte يشملون العديد من أكبر المنظمات في العالم؛ أردت أن أكون جزءًا من فريق يصنع فرقًا أستطيع أن أفتخر به.” – دان، T&T.
تواصل مع زملائك
الموقع: القاهرة، مصر
عملك، بطريقتك: نطلق على رؤيتنا للعمل الهجين Deloitte Works. وهي تفعل. نثق فيك لاختيار الطريقة التي تعمل بها، ومتى وأين. ستتمكن من اتخاذ قرارات حول كيفية عملك بشكل أفضل، ليكون تعاونك، وتعلمك من زملائك، ومشاركة تجاربك، وبناء العلاقات التي ستدعم مسيرتك المهنية، وإعطاء الأولوية لرفاهيتك. وجود حوارات رائعة مع فريقك وقيادتك يمهد الطريق لطرق عمل تعاونية رائعة.
التزامنا تجاهك
إحداث التأثير يتجاوز مجرد ما نفعله: إنه السبب في وجودنا. لذلك نعمل جاهدين لخلق بيئة يمكنك فيها تجربة هدف تؤمن به، الحرية كي تكون أنت، والقدرة على أن تصل إلى أبعد مما كنت تعتقد سابقًا.
نريدك. أنت الحقيقي. قوتك الخاصة ووجهة نظرك وشخصيتك. لذا، نحن نزرع ثقافة يشعر فيها الجميع بأنهم ينتمون، ويدعمون ويُسمعون، وتتاح لهم القدرة على تقديم إسهام شخصي قيم. يمكنك التأكد من أننا سنأخذ رفاهيتك على محمل الجد أيضًا. لأنه فقط عندما تكون مرتاحًا وفي أقصى عطائك يمكنك أن تصنع نوع الأثر الذي نسعى إليه نحن وأنتم.
خبرتك هي قدرتنا، لذا سنتأكد من أنها لا تتوقف عن النمو أبدًا. سواء من خلال العمل المعقد الذي تقوم به، أو الأشخاص الذين تتعاون معهم، ستتعلم كل يوم. من خلال التطوير على مستوى عالمي، ستكتسب مهارات تقنية وشخصية لا تقدر بثمن. مهما كان مستواك، ستتعلم كيف تقود.
تواصل مع خطوتك التالية!
مسار وظيفي في Deloitte هو فرصة للتطور في أي اتجاه تختاره. انضم إلينا وستختبر هدفًا يمكنك الإيمان به وتأثيرًا يمكنك رؤيته. ستكون حرًا لإحضار ذاتك الحقيقية إلى العمل كل يوم. ولن تتوقف عن النمو، مهما كان مستواك.