Middle Security Operations Center Engineer L2
Middle
Tech Support
B2/C1 English, technical degree or equivalent experience, 2–4 years in SOC/incident response, Windows/Linux and networking knowledge, MITRE ATT&CK, SIEM and EDR/XDR experience, strong analytical skills, shift flexibility, scripting, cloud security and SOAR/TIP knowledge.
Middle Security Operations Center Engineer L2
Middle Security Operations Center Engineer L2
Middle
Tech Support
We are looking for a Middle SOC Engineer (L1/L2) to join our team and provide advanced security monitoring, threat detection, and incident response for an enterprise client within a B2B environment. This role focuses on deep security triage, active incident investigation, and coordination of threat containment for international clients in English.
The position requires working in a 3-shift rotation (8 hours per shift) based on Cairo time:
Morning Shift: 08:00 AM – 04:00 PM
Evening Shift: 04:00 PM – 12:00 AM (Midnight)
Night Shift: 12:00 AM – 08:00 AM
Key Responsibilities
Perform real-time security monitoring, deep-dive analysis, and triage (L1/L2) of security alerts escalated from multiple sources (SIEM, EDR, firewalls, and system logs).
Log, track, and manage complex security incidents through ticketing systems, driving them to resolution or coordinating escalations.
Analyze network traffic (PCAP), system logs (Windows/Linux), and endpoint behavior to track lateral movement and analyze malware delivery.
Coordinate host isolation, credential revocation, and other immediate threat containment actions according to incident response playbooks.
Investigate multi-stage security incidents, draft detailed incident reports, and perform thorough root cause analysis (RCA).
Work on fine-tuning SIEM correlation rules, security tool dashboards, and optimizing detection alerts to minimize false positives.
Develop, test, and automate incident response runbooks (playbooks) and response procedures.
Communicate technical incident findings clearly to international clients and internal stakeholders via email, chat, and online meetings.
Required Skills & Qualifications
Upper-Intermediate to Advanced English (B2/C1, written and spoken) for daily client and internal communications.
Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical industry experience.
2 to 4 years of hands-on experience in a SOC, Security Operations Center, or active incident response role.
Solid knowledge of operating systems (Windows and Linux administration, system logs) and core networking protocols (TCP/IP, DNS, HTTP/HTTPS, SSL/TLS).
In-depth familiarity with the MITRE ATT&CK framework, common attack vectors, and techniques used by threat actors.
Practical experience working with SIEM platforms (such as Splunk, Microsoft Sentinel, or Elastic) and EDR/XDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).
Strong analytical thinking, technical documentation skills, and the ability to work under high pressure during major security incidents.
Availability to work on an 8-hour rotational shift schedule, including night shifts, weekends, and holidays.
Nice to Have
Relevant industry certifications (e.g., CompTIA CySA+, Blue Team Level 1/2, CEH, GCIH, or Microsoft Certified: Security Operations Analyst Associate).
Scripting and automation experience using Python, PowerShell, or Bash for security integrations and workflow optimization.
Familiarity with Cloud Security architecture (AWS, Azure, or GCP).
Experience with Security Orchestration, Automation, and Response (SOAR) platforms and Threat Intelligence Platforms (TIP).
Experience using ticketing and incident management tools like ServiceNow and JIRA.
What We Offer
Opportunity to work on large-scale, impactful global cybersecurity projects.
Clear career growth path to Senior SOC Analyst, Security Engineer, Threat Hunter, or DevSecOps roles within a team with 27+ years of experience.
Professional, friendly, and supportive team environment.
Rotational 8-hour shift schedule with additional night-shift and overtime compensation options.
Modern office in the Smart Village district (Cairo).
Flexible and transparent compensation review system.
Private medical insurance after completing the probation period.
Payments in USD.
Questions
We are looking for a Middle SOC Engineer (L1/L2) to join our team and provide advanced security monitoring, threat detection, and incident response for an enterprise client within a B2B environment. This role focuses on deep security triage, active incident investigation, and coordination of threat containment for international clients in English.
The position requires working in a 3-shift rotation (8 hours per shift) based on Cairo time:
Morning Shift: 08:00 AM – 04:00 PM
Evening Shift: 04:00 PM – 12:00 AM (Midnight)
Night Shift: 12:00 AM – 08:00 AM
Key Responsibilities
Perform real-time security monitoring, deep-dive analysis, and triage (L1/L2) of security alerts escalated from multiple sources (SIEM, EDR, firewalls, and system logs).
Log, track, and manage complex security incidents through ticketing systems, driving them to resolution or coordinating escalations.
Analyze network traffic (PCAP), system logs (Windows/Linux), and endpoint behavior to track lateral movement and analyze malware delivery.
Coordinate host isolation, credential revocation, and other immediate threat containment actions according to incident response playbooks.
Investigate multi-stage security incidents, draft detailed incident reports, and perform thorough root cause analysis (RCA).
Work on fine-tuning SIEM correlation rules, security tool dashboards, and optimizing detection alerts to minimize false positives.
Develop, test, and automate incident response runbooks (playbooks) and response procedures.
Communicate technical incident findings clearly to international clients and internal stakeholders via email, chat, and online meetings.
Required Skills & Qualifications
Upper-Intermediate to Advanced English (B2/C1, written and spoken) for daily client and internal communications.
Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical industry experience.
2 to 4 years of hands-on experience in a SOC, Security Operations Center, or active incident response role.
Solid knowledge of operating systems (Windows and Linux administration, system logs) and core networking protocols (TCP/IP, DNS, HTTP/HTTPS, SSL/TLS).
In-depth familiarity with the MITRE ATT&CK framework, common attack vectors, and techniques used by threat actors.
Practical experience working with SIEM platforms (such as Splunk, Microsoft Sentinel, or Elastic) and EDR/XDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).
Strong analytical thinking, technical documentation skills, and the ability to work under high pressure during major security incidents.
Availability to work on an 8-hour rotational shift schedule, including night shifts, weekends, and holidays.
Nice to Have
Relevant industry certifications (e.g., CompTIA CySA+, Blue Team Level 1/2, CEH, GCIH, or Microsoft Certified: Security Operations Analyst Associate).
Scripting and automation experience using Python, PowerShell, or Bash for security integrations and workflow optimization.
Familiarity with Cloud Security architecture (AWS, Azure, or GCP).
Experience with Security Orchestration, Automation, and Response (SOAR) platforms and Threat Intelligence Platforms (TIP).
Experience using ticketing and incident management tools like ServiceNow and JIRA.
What We Offer
Opportunity to work on large-scale, impactful global cybersecurity projects.
Clear career growth path to Senior SOC Analyst, Security Engineer, Threat Hunter, or DevSecOps roles within a team with 27+ years of experience.
Professional, friendly, and supportive team environment.
Rotational 8-hour shift schedule with additional night-shift and overtime compensation options.
Modern office in the Smart Village district (Cairo).
Flexible and transparent compensation review system.
Private medical insurance after completing the probation period.
Payments in USD.
Questions
Middle Security Operations Center Engineer L2
Content
Middle
B2/C1 English, technical degree or equivalent experience, 2–4 years in SOC/incident response, Windows/Linux and networking knowledge, MITRE ATT&CK, SIEM and EDR/XDR experience, strong analytical skills, shift flexibility, scripting, cloud security and SOAR/TIP knowledge.