Middle Security Operations Center Engineer L2

Middle

Tech Support

B2/C1 English, technical degree or equivalent experience, 2–4 years in SOC/incident response, Windows/Linux and networking knowledge, MITRE ATT&CK, SIEM and EDR/XDR experience, strong analytical skills, shift flexibility, scripting, cloud security and SOAR/TIP knowledge.

Middle Security Operations Center Engineer L2

Middle Security Operations Center Engineer L2

Middle

Tech Support

We are looking for a Middle SOC Engineer (L1/L2) to join our team and provide advanced security monitoring, threat detection, and incident response for an enterprise client within a B2B environment. This role focuses on deep security triage, active incident investigation, and coordination of threat containment for international clients in English.

The position requires working in a 3-shift rotation (8 hours per shift) based on Cairo time:

  • Morning Shift: 08:00 AM – 04:00 PM

  • Evening Shift: 04:00 PM – 12:00 AM (Midnight)

  • Night Shift: 12:00 AM – 08:00 AM

Key Responsibilities

  • Perform real-time security monitoring, deep-dive analysis, and triage (L1/L2) of security alerts escalated from multiple sources (SIEM, EDR, firewalls, and system logs).

  • Log, track, and manage complex security incidents through ticketing systems, driving them to resolution or coordinating escalations.

  • Analyze network traffic (PCAP), system logs (Windows/Linux), and endpoint behavior to track lateral movement and analyze malware delivery.

  • Coordinate host isolation, credential revocation, and other immediate threat containment actions according to incident response playbooks.

  • Investigate multi-stage security incidents, draft detailed incident reports, and perform thorough root cause analysis (RCA).

  • Work on fine-tuning SIEM correlation rules, security tool dashboards, and optimizing detection alerts to minimize false positives.

  • Develop, test, and automate incident response runbooks (playbooks) and response procedures.

  • Communicate technical incident findings clearly to international clients and internal stakeholders via email, chat, and online meetings.

Required Skills & Qualifications

  • Upper-Intermediate to Advanced English (B2/C1, written and spoken) for daily client and internal communications.

  • Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical industry experience.

  • 2 to 4 years of hands-on experience in a SOC, Security Operations Center, or active incident response role.

  • Solid knowledge of operating systems (Windows and Linux administration, system logs) and core networking protocols (TCP/IP, DNS, HTTP/HTTPS, SSL/TLS).

  • In-depth familiarity with the MITRE ATT&CK framework, common attack vectors, and techniques used by threat actors.

  • Practical experience working with SIEM platforms (such as Splunk, Microsoft Sentinel, or Elastic) and EDR/XDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).

  • Strong analytical thinking, technical documentation skills, and the ability to work under high pressure during major security incidents.

  • Availability to work on an 8-hour rotational shift schedule, including night shifts, weekends, and holidays.

Nice to Have

  • Relevant industry certifications (e.g., CompTIA CySA+, Blue Team Level 1/2, CEH, GCIH, or Microsoft Certified: Security Operations Analyst Associate).

  • Scripting and automation experience using Python, PowerShell, or Bash for security integrations and workflow optimization.

  • Familiarity with Cloud Security architecture (AWS, Azure, or GCP).

  • Experience with Security Orchestration, Automation, and Response (SOAR) platforms and Threat Intelligence Platforms (TIP).

  • Experience using ticketing and incident management tools like ServiceNow and JIRA.

What We Offer

  • Opportunity to work on large-scale, impactful global cybersecurity projects.

  • Clear career growth path to Senior SOC Analyst, Security Engineer, Threat Hunter, or DevSecOps roles within a team with 27+ years of experience.

  • Professional, friendly, and supportive team environment.

  • Rotational 8-hour shift schedule with additional night-shift and overtime compensation options.

  • Modern office in the Smart Village district (Cairo).

  • Flexible and transparent compensation review system.

  • Private medical insurance after completing the probation period.

  • Payments in USD.



Questions



We are looking for a Middle SOC Engineer (L1/L2) to join our team and provide advanced security monitoring, threat detection, and incident response for an enterprise client within a B2B environment. This role focuses on deep security triage, active incident investigation, and coordination of threat containment for international clients in English.

The position requires working in a 3-shift rotation (8 hours per shift) based on Cairo time:

  • Morning Shift: 08:00 AM – 04:00 PM

  • Evening Shift: 04:00 PM – 12:00 AM (Midnight)

  • Night Shift: 12:00 AM – 08:00 AM

Key Responsibilities

  • Perform real-time security monitoring, deep-dive analysis, and triage (L1/L2) of security alerts escalated from multiple sources (SIEM, EDR, firewalls, and system logs).

  • Log, track, and manage complex security incidents through ticketing systems, driving them to resolution or coordinating escalations.

  • Analyze network traffic (PCAP), system logs (Windows/Linux), and endpoint behavior to track lateral movement and analyze malware delivery.

  • Coordinate host isolation, credential revocation, and other immediate threat containment actions according to incident response playbooks.

  • Investigate multi-stage security incidents, draft detailed incident reports, and perform thorough root cause analysis (RCA).

  • Work on fine-tuning SIEM correlation rules, security tool dashboards, and optimizing detection alerts to minimize false positives.

  • Develop, test, and automate incident response runbooks (playbooks) and response procedures.

  • Communicate technical incident findings clearly to international clients and internal stakeholders via email, chat, and online meetings.

Required Skills & Qualifications

  • Upper-Intermediate to Advanced English (B2/C1, written and spoken) for daily client and internal communications.

  • Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical industry experience.

  • 2 to 4 years of hands-on experience in a SOC, Security Operations Center, or active incident response role.

  • Solid knowledge of operating systems (Windows and Linux administration, system logs) and core networking protocols (TCP/IP, DNS, HTTP/HTTPS, SSL/TLS).

  • In-depth familiarity with the MITRE ATT&CK framework, common attack vectors, and techniques used by threat actors.

  • Practical experience working with SIEM platforms (such as Splunk, Microsoft Sentinel, or Elastic) and EDR/XDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).

  • Strong analytical thinking, technical documentation skills, and the ability to work under high pressure during major security incidents.

  • Availability to work on an 8-hour rotational shift schedule, including night shifts, weekends, and holidays.

Nice to Have

  • Relevant industry certifications (e.g., CompTIA CySA+, Blue Team Level 1/2, CEH, GCIH, or Microsoft Certified: Security Operations Analyst Associate).

  • Scripting and automation experience using Python, PowerShell, or Bash for security integrations and workflow optimization.

  • Familiarity with Cloud Security architecture (AWS, Azure, or GCP).

  • Experience with Security Orchestration, Automation, and Response (SOAR) platforms and Threat Intelligence Platforms (TIP).

  • Experience using ticketing and incident management tools like ServiceNow and JIRA.

What We Offer

  • Opportunity to work on large-scale, impactful global cybersecurity projects.

  • Clear career growth path to Senior SOC Analyst, Security Engineer, Threat Hunter, or DevSecOps roles within a team with 27+ years of experience.

  • Professional, friendly, and supportive team environment.

  • Rotational 8-hour shift schedule with additional night-shift and overtime compensation options.

  • Modern office in the Smart Village district (Cairo).

  • Flexible and transparent compensation review system.

  • Private medical insurance after completing the probation period.

  • Payments in USD.



Questions



Middle Security Operations Center Engineer L2

Content

Middle

B2/C1 English, technical degree or equivalent experience, 2–4 years in SOC/incident response, Windows/Linux and networking knowledge, MITRE ATT&CK, SIEM and EDR/XDR experience, strong analytical skills, shift flexibility, scripting, cloud security and SOAR/TIP knowledge.