On-site
SITA -
Egypt , Cairo
--
SITA

Job Details

At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward we’re proud to be recognized as a Great Place to Work by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA.

As Security Analyst, you will be responsible for monitoring, triaging, and investigating security alerts and events to support the timely identification and escalation of potential security incidents. You will work closely with the SOC team to protect the organization by following established playbooks, procedures, and escalation processes. You will be accountable for validating security alerts, conducting initial investigations, documenting findings, and ensuring that security incidents are escalated appropriately while contributing to continuous improvements in monitoring and operational effectiveness.

Reporting to the Senior Manager, Service Operations, you will be part of the Security Operations Center (SOC), responsible for monitoring the organization's security posture, identifying threats, investigating suspicious activity, and supporting the broader Cyber Defense function.

WHAT YOU WILL DO

  • Monitor security alerts and events across SIEM, EDR/XDR, cloud, identity, email, and other security monitoring platforms.
  • Perform initial alert triage and determine whether activity is malicious, benign, or a false positive.
  • Investigate low- to medium-severity security alerts and gather relevant evidence to support response and escalation activities.
  • Execute approved SOC playbooks, standard operating procedures (SOPs), and investigation workflows.
  • Create, maintain, and update investigation tickets with clear documentation, timelines, evidence, and actions taken.
  • Escalate complex, high-risk, or suspicious cases to Senior Security Analysts, SOC SMEs, or the Incident Response team as required.
  • Participate in shift handovers and operational reporting to maintain investigation continuity and situational awareness.
  • Support vulnerability monitoring, compliance activities, and security operational tasks when required.
  • Contribute to knowledge base updates, process improvements, and SOC operational maturity initiatives.
  • Maintain high standards of accuracy, professionalism, and confidentiality when handling security investigations and sensitive information.

Desired Candidate Profile

You have 1-3 years of experience in Security Operations or a related cybersecurity role.

You have experience investigating security alerts using EDR/XDR solutions such as Microsoft Defender, Cortex XDR, or CrowdStrike Falcon.

You have experience using IT service management or ticketing platforms, such as ServiceNow, to document, track, and escalate security investigations.

You possess a fundamental understanding of SIEM technologies, preferably Elastic or Splunk.

You have basic knowledge of Windows, Linux, Active Directory, Azure/Entra ID, and networking concepts.

You understand common cyber threats and attack techniques, including phishing, malware, brute-force attempts, suspicious authentication activity, and endpoint-based detections.

You can analyze and correlate security events from multiple data sources to support investigations and alert validation.

You have a foundational understanding of detection rules, correlation logic, and monitoring use cases across SIEM and EDR/XDR platforms.

You possess strong analytical, organizational, documentation, and communication skills with strong attention to detail.

You hold a Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or a related field, and at least one industry-recognized cybersecurity certification such as Security+, GSEC, CySA+, SC-200, AZ-900, or SC-900.

NICE-TO-HAVE

  • Participation in cybersecurity training programs, Capture the Flag (CTF) competitions, cyber labs, or other hands-on learning activities.
  • Exposure to cloud security monitoring within Microsoft Azure, Microsoft 365, or AWS environments.
  • Familiarity with the MITRE ATT&CK framework and its application to security monitoring and threat investigations.

Similar Jobs

About SITA
Egypt, Cairo
Information Technology and Services