WHAT YOU'LL DO
Leadership
Lead the Cairo CTI & Hunting Team - Mentor and develop Cairo-based Threat Intelligence Analysts and Threat Hunters, set team targets and objectives aligned with our SOC strategy, and foster professional growth.
Operational Coordination - Ensure seamless shift handoffs between Cairo, Singapore and Montreal to maintain continuous global coverage.
Stakeholder Communication - Serve as the primary Cairo subject matter expert liaison to CSIRT leadership, reporting significant findings, hunt outcomes, and intelligence products to senior management.
Quality Assurance - Review and approve intelligence products and hunt reports produced by the Cairo team before dissemination.
Threat Intelligence (Hands-On)
Intelligence Program Execution - Oversee the full intelligence lifecycle: collection requirements (PIRs), gathering, analysis, production, dissemination, and feedback.
Strategic & Operational Intelligence - Produce and oversee high-quality finished intelligence products including Threat Landscape Reports, Threat Actor Profiles, Flash Alerts, and executive briefings with a focus on MEA regional threats.
Source Management - Manage relationships with intelligence sources including Recorded Future, Mandiant, Aviation-ISAC, government CERTs, and regional law enforcement.
Dark Web Operations - Oversee dark web monitoring and credential exposure investigations, ensuring timely escalation and remediation coordination.
Threat Hunting (Hands-On)
Hunt Strategy & Methodology - Develop and maintain threat hunting hypotheses, tactics, techniques, and procedures. Lead the team in proactive, hypothesis-driven hunts aligned with MITRE ATT&CK during the MEA time zone.
Detection Engineering Oversight - Ensure hunt findings are translated into updated SOC use cases, detection rules, and SIEM content to continuously improve automated defenses.
Adversary Emulation Coordination - Coordinate purple team and attack simulations exercises, validate detection coverage, and drive remediation of identified gaps.
Incident Response Integration - Lead the Cairo team's support during major security incidents, providing both intelligence context and forensic hunting capabilities to MEA CSIRT Incident responders.
ABOUT YOUR SKILLS
Education & Professional Qualifications
Bachelor's Degree in Cybersecurity, Computer Science, Information Security, Intelligence Studies, or equivalent. Master's degree is a plus.
At least one recognized certification such as: GCTI, GCIH, GCFA, GREM, OSCP, CEH, CISM, or CISSP.
Experience
5+ years of experience in cyber threat intelligence, threat hunting, or incident response, with at least 2 years in a lead or supervision type of role.
Demonstrated experience mentoring a team of security analysts or hunters.
Hands-on expertise with SIEM (Elastic), EDR/XDR (CrowdStrike Falcon, Cortex XDR), and Threat Intelligence Platforms (Recorded Future, MISP, OpenCTI).
Hands-on expertise with SOAR/XSOAR for automation of intelligence and hunting workflows.
Technical Skills
Advanced proficiency in log analysis, forensics, and threat hunting across endpoint, network, cloud, and identity telemetry.
Strong scripting skills in Python, PowerShell, KQL/EQL for hunting queries, automation, and data processing.
Deep understanding of OSINT collection, dark web intelligence, and malware analysis (static/dynamic).
Knowledge of intelligence sharing frameworks (STIX/TAXII, TLP) and industry collaboration models.
Functional Skills
Skill Expected Level
Team Leadership L3 L4
Threat Intelligence Analysis L4
Master Threat Hunting Techniques L3 L4
Detection Engineering L3
Practitioner Incident Management L3
Practitioner Communication & Stakeholder Management L4
Master Problem Solving L4
Master
Soft Skills
Proven leadership - ability to inspire and mentor team peers
Exceptional written and verbal communication able to produce executive-level briefings and translate technical findings for non-technical audiences.
Strategic thinker with an operational mindset balancing long-term program development with day-to-day tactical execution.
Strong cross-cultural awareness and ability to collaborate across global time zones.
NICE-TO-HAVE
Fluency in Arabic strongly preferred for regional OSINT, MEA threat landscape, and local stakeholder engagement.
Experience in the aviation sector.
Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
Prior experience standing up or scaling a regional security team.
WHAT WE OFFER
Flex Week Work from home up to 2 days/week (subject to team's needs)
Flex Location Take up to 30 days a year to work from any location in the world
Employee Wellbeing EAP for you and your dependents 24/7, 365 days/year
Professional Development LinkedIn Learning, SANS training, and industry certifications
Competitive Benefits Competitive benefits aligned with your local market
SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.
Salary / Compensation Note Hidden (-999)
Desired Candidate Profile
- Bachelor's Degree in Cybersecurity, Computer Science, Information Security, Intelligence Studies, or equivalent. Master's degree is a plus.
- At least one recognized certification such as: GCTI, GCIH, GCFA, GREM, OSCP, CEH, CISM, or CISSP.
- 5+ years of experience in cyber threat intelligence, threat hunting, or incident response, with at least 2 years in a lead or supervision type of role.
- Demonstrated experience mentoring a team of security analysts or hunters.
- Hands-on expertise with SIEM (Elastic), EDR/XDR (CrowdStrike Falcon, Cortex XDR), and Threat Intelligence Platforms (Recorded Future, MISP, OpenCTI).
- Hands-on expertise with SOAR/XSOAR for automation of intelligence and hunting workflows.
- Advanced proficiency in log analysis, forensics, and threat hunting across endpoint, network, cloud, and identity telemetry.
- Strong scripting skills in Python, PowerShell, KQL/EQL for hunting queries, automation, and data processing.
- Deep understanding of OSINT collection, dark web intelligence, and malware analysis (static/dynamic).
- Knowledge of intelligence sharing frameworks (STIX/TAXII, TLP) and industry collaboration models.
- Proven leadership - ability to inspire and mentor team peers
- Exceptional written and verbal communication able to produce executive-level briefings and translate technical findings for non-technical audiences.
- Strategic thinker with an operational mindset balancing long-term program development with day-to-day tactical execution.
- Strong cross-cultural awareness and ability to collaborate across global time zones.
- Fluency in Arabic strongly preferred for regional OSINT, MEA threat landscape, and local stakeholder engagement.
- Experience in the aviation sector.
- Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
- Prior experience standing up or scaling a regional security team.
مَا سَتَفْعَلُهُ
القيادة
قيادة فريق Cairo CTI & Hunting - توجيه وتطوير محللي استخبارات التهديد والصيادين في القاهرة، وتحديد أهداف الفريق ومواءمتها مع استراتيجيتنا لـ SOC، وتطوير المهنيين.
التنسيق التشغيلي - ضمان سلاسة تحويل المناوبات بين القاهرة، سنغافورة ومونتريال للحفاظ على التغطية العالمية المستمرة.
التواصل مع الجهات المعنية - أن تكون حلقة الاتصال الأساسية للمادة المعرفية في القاهرة مع قيادة CSIRT، وتقديم النتائج الهامة، ونتائج الصيد، والمنتجات الاستخبارية إلى الإدارة العليا.
ضمان الجودة - مراجعة واعتماد منتجات الاستخبار والصيادين التي ينتجها فريق القاهرة قبل النشر.
الاستخبارات التهديدية (عملي)
تنفيذ برنامج الاستخبارات - الإشراف على دورة حياة الاستخبارات كاملة: متطلبات الجمع (PIRs)، والتجميع، والتحليل، والإنتاج، والنشر، والتغذية الراجعة.
الاستخبارات الاستراتيجية والتشغيلية - إنتاج ومراجعة منتجات استخبارية نهائية عالية الجودة بما في ذلك تقارير مشهد التهديدات، وملفات الجهات الفاعلة في التهديد، والتنبيهات الفلاشية، وإحاطات تنفيذية مع تركيز على تهديدات منطقة MEA.
إدارة المصادر - إدارة العلاقات مع مصادر الاستخبارات بما في ذلك Recorded Future، وMandiant، وAviation-ISAC، وشركات CERT الحكومية، و law enforcement الإقليمية.
عمليات الويب المظلم - الإشراف على مراقبة الويب المظلم والتحقيقات في كشف الاعتمادات، والتأكد من التصعيد والتنسيق للإجراءات التصحيحية في الوقت المناسب.
الصيد التهديدي (عملي)
استراتيجية الصيد ومنهجيتها - وضع وخطّ صدر فرضيات الصيد التهديدي، والتكتيكات، والتقنيات، والإجراءات. قيادة الفريق في صيد استباقي قائم على الفرضية متوافق مع MITRE ATT&CK خلال منطقة زمن MEA.
الإشراف على هندسة الكشف - التأكد من ترجمة نتائج الصيد إلى حالات استخدام SOC محدثة، وقواعد كشف، ومحتوى SIEM لتحسين الدفاعات المؤتمتة باستمرار.
تنسيق محاكاة الخصم - تنسيق تدريبات الفريق البنفسجي وتقييمات المحاكاة، والتحقق من تغطية الكشف، ودفع إجراءات التصحيح للفجوات المحددة.
التكامل مع الاستجابة للحوادث - قيادة دعم فريق القاهرة أثناء الحوادث الأمنية الكبيرة، مع توفير السياق الاستخباراتي وقدرات الصيد الجنائي للمحققين في MEA CSIRT.
حول مهاراتك
التعليم والمؤهلات المهنية
درجة البكالوريوس في الأمن السيبراني، علوم الحاسب، أمان المعلومات، دراسات الاستخبار، أو ما يعادلها. درجة الماجستير تعتبر ميزة.
شهادة معترف بها مثل: GCTI، GCIH، GCFA، GREM، OSCP، CEH، CISM، أو CISSP.
الخبرة
5+ سنوات خبرة في استخبارات تهديدات الإنترنت، صيد التهديدات، أو الاستجابة للحوادث، مع ما لا يقل عن سنتين في دور قيادي أو إشرافي.
خبرة مثبتة في توجيه فريق من محللي الأمن أو الصيادين.
خبرة عملية في SIEM (Elastic)، EDR/XDR (CrowdStrike Falcon، Cortex XDR)، ومنصات استخبار التهديد (Recorded Future، MISP، OpenCTI).
خبرة عملية في SOAR/XSOAR لأتمتة سير عمل الاستخبار والصيد.
المهارات التقنية
إتقان متقدم لتحليل السجلات، الطب الشرعي، والصيد التهديدي عبر نقاط النهاية، الشبكة، السحابة، وبيانات الهوية.
مهارات برمجة قوية في Python، PowerShell، KQL/EQL لأسئلة الصيد، الأتمتة، ومعالجة البيانات.
فهم عميق لتجميع OSINT، استخبارات الويب المظلم، وتحليل البرامج الضارة (ثابت/ديناميكي).
معرفة بإطارات مشاركة الاستخبارات (STIX/TAXII، TLP) ونماذج التعاون الصناعي.
المهارات الوظيفية
المهارة المستوى المتوقع
قيادة الفريق L3 L4
تحليل استخبارات التهديد L4
إتقان تقنيات الصيد المتقدمة L3 L4
هندسة الكشف L3
إدارة الحوادث العملية L3
التواصل وإدارة أصحاب المصلحة L4
إتقان حل المشكلات L4
Master
المهارات الناعمة
قيادة مثبتة - القدرة على إلهام وMentor أعضاء الفريق
اتصال مكتوب وشفهي استثنائي قادر على إعداد إحاطات تنفيذية وترجمة النتائج التقنية للجمهور غير التقني.
مفكر استراتيجي بموقف تشغيلي يوازن بين تطوير البرنامج على المدى الطويل والتنفيذ التكتيكي اليومي.
وعي عابر للثقافات قوي وقدرة على التعاون عبر فروق زمنية عالمية.
مفضل وجودها
إتقان العربية يفضّل بشدة للـ OSINT الإقليمي، مشهد التهديد MEA، والتواصل مع الجهات المعنية محلياً.
خبرة في قطاع الطيران.
الاطلاع على أدوات محاكاة التفشي والهجوم (BAS) مثل AttackIQ.
خبرة سابقة في تأسيس أو توسيع فريق أمني إقليمي.
ما نقدمه
أسبوع مرن: العمل من المنزل حتى يومين/الأسبوع (حسب احتياجات الفريق)
الموقع المرن: حتى 30 يوماً في السنة للعمل من أي مكان في العالم
رفاهية الموظف: EAP لك ولعائلتك على مدار الساعة طوال أيام السنة
التطوير المهني: LinkedIn Learning، تدريب SANS، وشهادات صناعية
المزايا التنافسية: مزايا تتوافق مع سوقك المحلي
SITA هي جهة توظيف تُتيح فرص متساوية. نُقيّم قوة مجتمع متنوع. دعمًا لبرنامج المساواة الوظيفية، نشجع المرأة، والأشخاص الأصليين، والأفراد المنتمين إلى أقليات مرئية، و/أو ذوي الإعاقات على التقديم وتعريف أنفسهم خلال عملية التقديم.
ملاحظة الراتب / التعويض مخفي (-999)
الملف المرغوب لدى المرشح
- درجة البكالوريوس في الأمن السيبراني، علوم الكمبيوتر، أمان المعلومات، دراسات الاستخبار، أو ما يعادلها. درجة الماجستير ميزة.
- شهادة معترف بها مثل: GCTI، GCIH، GCFA، GREM، OSCP، CEH، CISM، أو CISSP.
- 5+ سنوات خبرة في استخبارات تهديدات الإنترنت، صيد التهديد، أو الاستجابة للحوادث، مع ما لا يقل عن سنتين كقائد أو مسئول إشرافي.
- خبرة مثبتة في توجيه فريق من محللي الأمن أو الصيادين.
- خبرة عملية في SIEM (Elastic)، EDR/XDR (CrowdStrike Falcon، Cortex XDR)، ومنصات استخبار التهديد (Recorded Future، MISP، OpenCTI).
- خبرة عملية في SOAR/XSOAR لأتمتة سير عمل الاستخبار والصيد.
- إتقان متقدم لتحليل السجلات، الطب الشرعي، والصيد التهديدي عبر نقاط النهاية والشبكة والسحابة والهوية.
- مهارات برمجة قوية في Python، PowerShell، KQL/EQL لأسئلة الصيد، الأتمتة، ومعالجة البيانات.
- فهم عميق لجمع OSINT، استخبارات الويب المظلم، وتحليل البرامج الضارة (ثابت/ديناميكي).
- معرفة بإطارات مشاركة الاستخبارات (STIX/TAXII، TLP) ونماذج التعاون الصناعي.
- قيادة مثبتة - القدرة على إلهام وMentor أعضاء الفريق
- اتصال مكتوب وشفهي استثنائي قادر على إعداد إحاطات تنفيذية وترجمة النتائج التقنية للجمهور غير التقني.
- مفكر استراتيجي بموقف تشغيلي يوازن بين تطوير البرنامج على المدى الطويل والتنفيذ التكتيكي اليومي.
- وعي عابر للثقافات قوي وقدرة على التعاون عبر فروق زمنية عالمية.
- إتقان العربية يفضّل بشدة للـ OSINT الإقليمي، مشهد التهديد MEA، والتواصل مع الجهات المعنية محلياً.
- خبرة في قطاع الطيران.
- الاطلاع على أدوات محاكاة التفشي والهجوم (BAS) مثل AttackIQ.
- خبرة سابقة في تأسيس أو توسيع فريق أمني إقليمي.