At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward we’re proud to be recognized as a Great Place to Work by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA.
As Security Analyst, you will be responsible for monitoring, triaging, and investigating security alerts and events to support the timely identification and escalation of potential security incidents. You will work closely with the SOC team to protect the organization by following established playbooks, procedures, and escalation processes. You will be accountable for validating security alerts, conducting initial investigations, documenting findings, and ensuring that security incidents are escalated appropriately while contributing to continuous improvements in monitoring and operational effectiveness.
Reporting to the Senior Manager, Service Operations, you will be part of the Security Operations Center (SOC), responsible for monitoring the organization's security posture, identifying threats, investigating suspicious activity, and supporting the broader Cyber Defense function.
WHAT YOU WILL DO
- Monitor security alerts and events across SIEM, EDR/XDR, cloud, identity, email, and other security monitoring platforms.
- Perform initial alert triage and determine whether activity is malicious, benign, or a false positive.
- Investigate low- to medium-severity security alerts and gather relevant evidence to support response and escalation activities.
- Execute approved SOC playbooks, standard operating procedures (SOPs), and investigation workflows.
- Create, maintain, and update investigation tickets with clear documentation, timelines, evidence, and actions taken.
- Escalate complex, high-risk, or suspicious cases to Senior Security Analysts, SOC SMEs, or the Incident Response team as required.
- Participate in shift handovers and operational reporting to maintain investigation continuity and situational awareness.
- Support vulnerability monitoring, compliance activities, and security operational tasks when required.
- Contribute to knowledge base updates, process improvements, and SOC operational maturity initiatives.
- Maintain high standards of accuracy, professionalism, and confidentiality when handling security investigations and sensitive information.
Desired Candidate Profile
You have 1-3 years of experience in Security Operations or a related cybersecurity role.
You have experience investigating security alerts using EDR/XDR solutions such as Microsoft Defender, Cortex XDR, or CrowdStrike Falcon.
You have experience using IT service management or ticketing platforms, such as ServiceNow, to document, track, and escalate security investigations.
You possess a fundamental understanding of SIEM technologies, preferably Elastic or Splunk.
You have basic knowledge of Windows, Linux, Active Directory, Azure/Entra ID, and networking concepts.
You understand common cyber threats and attack techniques, including phishing, malware, brute-force attempts, suspicious authentication activity, and endpoint-based detections.
You can analyze and correlate security events from multiple data sources to support investigations and alert validation.
You have a foundational understanding of detection rules, correlation logic, and monitoring use cases across SIEM and EDR/XDR platforms.
You possess strong analytical, organizational, documentation, and communication skills with strong attention to detail.
You hold a Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or a related field, and at least one industry-recognized cybersecurity certification such as Security+, GSEC, CySA+, SC-200, AZ-900, or SC-900.
NICE-TO-HAVE
- Participation in cybersecurity training programs, Capture the Flag (CTF) competitions, cyber labs, or other hands-on learning activities.
- Exposure to cloud security monitoring within Microsoft Azure, Microsoft 365, or AWS environments.
- Familiarity with the MITRE ATT&CK framework and its application to security monitoring and threat investigations.
في SITA، نعمل على حفظ حركة المطارات، وضمان سير الرحلات الجوية بسلاسة، وفتح الحدود. تقنياتنا في مجال التكنولوجيا والاتصالات تمكّن نجاح صناعة السفر الجوي العالمي. ستجدنا في 95% من المطارات الدولية، ونعمل بشكل وثيق مع أكثر من 2,500 عميل في مجالات النقل والحكومة. كل شراكة تجلب تحديات فريدة، ونحن نزدهر بتقديم حلول جديدة وتكنولوجيا متقدمة للحفاظ على سير العمليات كالمعتاد. نحن لا نتحرك بالعالم فحسب، بل نفخر بأن نُعتبر مكان عمل رائع من قبل موظفينا وبأننا معتمدون في معظم مواقعنا المتنامية. هنا، نشعر بالتمكين والدعم والإلهام للنمو. هل أنت مستعد لأن تحب وظيفتك؟ تبدأ المغامرة من هنا، معك، في SITA.
بصفتك محلل أمني، ستكون مسؤولاً عن مراقبة، فرز، والتحقيق في التنبيهات والأحداث الأمنية لدعم التعرف المبكر والتصعيد المحتمل للحوادث الأمنية. ستعمل عن كثب مع فريق SOC لحماية المؤسسة باتباع كتب اللعب والإجراءات والتصعيد المعتمدة. ستكون مسؤولاً عن التحقق من صحة التنبيهات الأمنية، إجراء التحقيقات الأولية، توثيق النتائج، والتأكد من تصعيد الحوادث الأمنية بشكل مناسب مع المساهمة في التحسين المستمر في المراقبة والفعالية التشغيلية.
تقريرك إلى مدير الخدمات التشغيلية الأول، ستكون جزءاً من مركز عمليات الأمن (SOC)، المسؤول عن مراقبة الوضع الأمني للمؤسسة، تحديد التهديدات، التحقيق في الأنشطة المشبوهة، ودعم وظيفة الدفاع السيبراني الأوسع.
WHAT YOU WILL DO
- مراقبة التنبيهات والأحداث الأمنية عبر SIEM وEDR/XDR والسحابة والهوية والبريد الإلكتروني ومنصات المراقبة الأمنية الأخرى.
- إجراء فرز التنبيه الأول وتحديد ما إذا كان النشاط خبيثاً أم بنداً أم إيجابياً كاذباً.
- التحقيق في التنبيهات الأمنية من الدرجة المنخفضة إلى المتوسطة وجمع الأدلة ذات الصلة لدعم الاستجابة وأنشطة التصعيد.
- تنفيذ كتب تشغيل SOC المعتمدة وإجراءات التشغيل القياسية (SOPs) وتدفقات التحقيق.
- إنشاء وصيانة وتحديث تذاكر التحقيق مع توثيق واضح وجداول زمنية وأدلة وإجراءات اتخذت.
- تصعيد الحالات المعقدة عالية المخاطر أو المشبوهة إلى محللي الأمن الكبار، خبراء SOC، أو فريق الاستجابة للحوادث عند الحاجة.
- المشاركة في تسليم المناوبات والتقارير التشغيلية للحفاظ على استمرارية التحقيق والوعي بالوضع.
- دعم مراقبة الثغرات والأنشطة الامتثالية والمهام التشغيلية الأمنية عند الطلب.
- المساهمة في تحديثات قاعدة المعرفة، وتحسين العمليات، ومبادرات نضج تشغيل SOC.
- المحافظة على معايير عالية من الدقة والاحترافية والخصوصية عند التعامل مع التحقيقات الأمنية والمعلومات الحساسة.
Desired Candidate Profile
لديك خبرة من 1 إلى 3 سنوات في عمليات الأمن أو دور أمني سيبراني ذي صلة.
لديك خبرة في التحقيق في التنبيهات الأمنية باستخدام حلول EDR/XDR مثل Microsoft Defender وCortex XDR أو CrowdStrike Falcon.
لديك خبرة في استخدام منصات إدارة خدمات تكنولوجيا المعلومات أو أنظمة التذاكر مثل ServiceNow لتوثيق وتتبع وتصعيد التحقيقات الأمنية.
لديك فهم أساسي لتقنيات SIEM، ويفضل Elastic أو Splunk.
لديك معرفة أساسية بنظم Windows وLinux وActive Directory وAzure/Entra ID ومفاهيم الشبكات.
تفهم تهديدات سيبرانية وتقنيات هجوم شائعة، بما في ذلك الاصطياد الاحتيالي (Phishing) والبرمجيات الخبيثة ومحاولات قوة字، ونشاط مصادقة مريب، وكشف على الطرف النهائي.
يمكنك تحليل وربط أحداث الأمن من مصادر بيانات متعددة لدعم التحقيقات والتحقق من التنبيهات.
لديك فهم أساسي لقواعد الكشف ومنطق الترابط وحالات المراقبة عبر منصات SIEM وEDR/XDR.
تمتلك مهارات تحليلية وتنظيمية وتوثيق واتصال قوية مع اهتمام قوي بالتفاصيل.
تحمل شهادة جامعية في تكنولوجيا المعلومات، الأمن السيبراني، علوم الكمبيوتر، أو مجال ذي صلة، وعلى الأقل شهادة أمن سيبراني معترف بها في الصناعة مثل Security+، GSEC، CySA+، SC-200، AZ-900، أو SC-900.
NICE-TO-HAVE
- المشاركة في برامج تدريب الأمن السيبراني، مسابقات Capture the Flag (CTF)، مختبرات سيبرانية، أو أنشطة تعلم عملية أخرى.
- تعرض لمراقبة أمان السحابة في بيئات Microsoft Azure أو Microsoft 365 أو AWS.
- إلمام بإطار MITRE ATT&CK وتطبيقه في مراقبة الأمن والتحقيق في التهديدات.