Senior Associate - SOC
Al Etihad Payments empowers employees to work in an environment that best promotes their productivity and well-being, while providing high-quality workplace and fantastic professional experience.
|Get to Know Us
Al Etihad Payments is the UAE’s designated retail payments entity, dedicated to developing and operating world-class infrastructure, standards, and solutions for the UAE Economy. Al Etihad Payments is a subsidiary of the Central Bank of the UAE, strongly supported by the UAE Government.
Al Etihad Payments is the UAE’s designated retail payments entity, dedicated to developing and operating world-class infrastructure, standards, and solutions for the UAE Economy. Al Etihad Payments is a subsidiary of the Central Bank of the UAE, strongly supported by the UAE Government.
Our employees are committed to work with licensed financial institutions and other payment service providers to foster innovation and deliver excellent financial services to all in the UAE, efficiently and without friction.
Al Etihad Payments supports the government’s objectives of a cashless society, national digitization, and the Central Bank of the UAE objective of being a top ten central bank globally.
|Our Culture
We are a collaborative, diverse and passionate group of individuals that works as one team. We support one another, make impactful contributions to the organization, and develop and nurture meaningful connections across the payment’s ecosystem!
|About the role
Lead the day-to-day operations, governance, and continuous improvement of the Security Operations Center (SOC), ensuring effective detection, investigation, response, and monitoring of cybersecurity threats across AEP’s technology environment.
|What You’ll Do:
SOC Operations
- Lead day-to-day SOC operations and ensure continuous security monitoring.
- Oversee monitoring of SIEM, SOAR, EDR, and other security technologies.
- Ensure security alerts are appropriately triaged, investigated, escalated and closed.
- Review and optimize security use cases, correlation rules, detection logic and alert thresholds.
- Ensure appropriate prioritization of use cases based on business risk and threat intelligence.
- Monitor SOC KPIs including MTTD, MTTA, MTTR, incident closure time, SLA compliance and alert volumes.
- Liaise with Security Administration Team as and when needed for technical issues pertaining SOC.
Incident Response
- Lead investigation and response to security incidents, including high-severity and critical incidents.
- Coordinate with Network, Application, Infrastructure and other teams during incident response.
- Ensure appropriate escalation with relevant stakeholders.
- Coordinate containment, eradication and recovery activities.
- Conduct post-incident reviews and ensure lessons learned are incorporated into detection and response processes.
Threat Detection & Engineering
- Develop and continuously improve SOC detection capabilities.
- Identify gaps in security monitoring and log coverage.
- Ensure critical security logs are onboarded, retained and monitored appropriately.
- Work with threat intelligence and threat hunting teams to develop relevant detection use cases.
Governance & Compliance
- Maintain SOC procedures, playbooks, escalation matrices and operational documentation.
- Support regulatory, internal and external audits.
- Ensure SOC operations align with applicable regulatory requirements and frameworks such as ISO 27001, PCI DSS and UAE regulatory requirements, as applicable.
- Maintain evidence of monitoring, investigation, incident handling and SLA performance.
Qualifications & Years of Experience
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science or related field.
- 8+ years of cybersecurity/security operations experience, with relevant SOC leadership experience.
- Experience managing enterprise SOC operations and/or MSSP.
- Strong SIEM, SOAR and EDR/XDR experience.
- Strong understanding of network, endpoint, identity and application security.
Required Skills
- CISSP/CISM.
- GIAC certifications.
- Hands on Experience in Splunk/ XSOAR.
- Splunk / Palo Alto / Fortinet or other relevant technology certifications.
- SIEM & Log Management: Advanced administration and detection-engineering experience with enterprise SIEM platform Splunk Enterprise Security.
- Threat Hunting & Intelligence: Ability to operationalize Cyber Threat Intelligence (CTI) feeds and proactively hunts for hidden threats using frameworks like the MITRE ATT&CK Framework.
|What you can expect from us
- Modern work environment with level of flexibility;
- Dynamic and motivated team of colleagues working towards achieving UAE National Objectives;
- Competitive compensation package, including annual bonus and additional benefits like child educational allowance and annual flight tickets (where eligible);
- Comprehensive health insurance coverage;
أخصائي أول - SOC
تمكّن شركة "الاتحاد لمدفوعات" الموظفين من العمل في بيئة تعزز إنتاجيتهم ورفاهيتهم بأفضل شكل، مع توفير مكان عمل عالي الجودة وتجربة مهنية رائعة.
|تعرّف علينا
تُعد شركة "الاتحاد لمدفوعات" الجهة المحددة لمدفوعات التجزئة في دولة الإمارات العربية المتحدة، وهي مكرسة لتطوير وتشغيل بنية تحتية ومعايير وحلول عالمية المستوى لاقتصاد دولة الإمارات. وشركة "الاتحاد لمدفوعات" هي شركة تابعة لمصرف الإمارات العربية المتحدة المركزي، وتحظى بدعم قوي من حكومة دولة الإمارات.
تُعد شركة "الاتحاد لمدفوعات" الجهة المحددة لمدفوعات التجزئة في دولة الإمارات العربية المتحدة، وهي مكرسة لتطوير وتشغيل بنية تحتية ومعايير وحلول عالمية المستوى لاقتصاد دولة الإمارات. وشركة "الاتحاد لمدفوعات" هي شركة تابعة لمصرف الإمارات العربية المتحدة المركزي، وتحظى بدعم قوي من حكومة دولة الإمارات.
يلتزم موظفونا بالعمل مع المؤسسات المالية المرخصة ومزودي خدمات المدفوعات الآخرين لتعزيز الابتكار وتقديم خدمات مالية ممتازة للجميع في دولة الإمارات، بكفاءة وسلاسة.
تدعم "الاتحاد لمدفوعات" أهداف الحكومة المتمثلة في مجتمع غير نقدي، والتحول الرقمي الوطني، وهدف مصرف الإمارات العربية المتحدة المركزي في أن يكون ضمن أفضل عشرة مصارف مركزية على مستوى العالم.
|ثقافتنا
نحن مجموعة متعاونة ومتنوعة وشغوفة من الأفراد نعمل كفريق واحد. ندعم بعضنا البعض، ونقدم مساهمات مؤثرة للمؤسسة، ونبني وننمي علاقات ذات مغزى عبر منظومة المدفوعات!
|عن الوظيفة
قيادة العمليات اليومية والحوكمة والتحسين المستمر لمركز عمليات الأمن (SOC)، وضمان الكشف الفعال والتحقيق والاستجابة والمراقبة لتهديدات الأمن السيبراني عبر البيئة التكنولوجية للشركة.
|المهام والمسؤوليات:
عمليات مركز عمليات الأمن (SOC)
- قيادة عمليات SOC اليومية وضمان المراقبة الأمنية المستمرة.
- الإشراف على مراقبة تقنيات SIEM وSOAR وEDR وغيرها من التقنيات الأمنية.
- ضمان تصنيف التنبيهات الأمنية والتحقيق فيها وتصعيدها وإغلاقها بشكل مناسب.
- مراجعة وتحسين حالات الاستخدام الأمني، وقواعد الربط، ومنطق الكشف، وعتبات التنبيه.
- ضمان تحديد الأولويات المناسبة لحالات الاستخدام بناءً على مخاطر الأعمال ومعلومات التهديدات.
- مراقبة مؤشرات الأداء الرئيسية لـ SOC بما في ذلك MTTD وMTTA وMTTR وزمن إغلاق الحوادث والامتثال لاتفاقية مستوى الخدمة (SLA) وحجم التنبيهات.
- التنسيق مع فريق إدارة الأمن حسب الحاجة للمشكلات الفنية المتعلقة بـ SOC.
الاستجابة للحوادث
- قيادة التحقيق والاستجابة للحوادث الأمنية، بما في ذلك الحوادث عالية الخطورة والحرجة.
- التنسيق مع فرق الشبكات والتطبيقات والبنية التحتية والفرق الأخرى أثناء الاستجابة للحوادث.
- ضمان التصعيد المناسب مع أصحاب المصلحة المعنيين.
- تنسيق أنشطة الاحتواء والقضاء على التهديدات والتعافي.
- إجراء مراجعات ما بعد الحوادث وضمان دمج الدروس المستفادة في عمليات الكشف والاستجابة.
كشف التهديدات وهندستها
- تطوير قدرات الكشف في SOC وتحسينها باستمرار.
- تحديد الفجوات في المراقبة الأمنية وتغطية السجلات.
- ضمان إدراج سجلات الأمن الحرجة والاحتفاظ بها ومراقبتها بشكل مناسب.
- العمل مع فرق استخبارات التهديدات وتتبع التهديدات لتطوير حالات استخدام الكشف ذات الصلة.
الحوكمة والامتثال
- صيانة إجراءات SOC، وأدلة العمليات (playbooks)، ومصفوفات التصعيد، والوثائق التشغيلية.
- دعم عمليات التدقيق التنظيمية والداخلية والخارجية.
- ضمان توافق عمليات SOC مع المتطلبات والأطر التنظيمية المعمول بها مثل ISO 27001 وPCI DSS والمتطلبات التنظيمية لدولة الإمارات، حسب الاقتضاء.
- الاحتفاظ بأدلة المراقبة والتحقيق والتعامل مع الحوادث وأداء اتفاقية مستوى الخدمة (SLA).
المؤهلات وسنوات الخبرة
- درجة البكالوريوس في الأمن السيبراني، أو أمن المعلومات، أو علوم الحاسوب، أو مجال ذي صلة.
- خبرة لا تقل عن 8 سنوات في مجال الأمن السيبراني/عمليات الأمن، مع خبرة قيادية ذات صلة في SOC.
- خبرة في إدارة عمليات SOC المؤسسية و/أو مزودي خدمات الأمن المُدارة (MSSP).
- خبرة قوية في تقنيات SIEM وSOAR وEDR/XDR.
- فهم قوي لأمن الشبكات والأجهزة الطرفية والهوية والتطبيقات.
المهارات المطلوبة
- شهادة CISSP/CISM.
- شهادات GIAC.
- خبرة عملية في Splunk / XSOAR.
- شهادات اعتماد في Splunk / Palo Alto / Fortinet أو التقنيات الأخرى ذات الصلة.
- إدارة SIEM والسجلات: خبرة متقدمة في الإدارة وهندسة الكشف باستخدام منصة SIEM المؤسسية Splunk Enterprise Security.
- تتبع التهديدات والاستخبارات: القدرة على تشغيل خلاصة استخبارات التهديدات السيبرانية (CTI) والتعقب الاستباقي للتهديدات الخفية باستخدام أطر عمل مثل MITRE ATT&CK Framework.
|ما يمكنك توقعه منا
- بيئة عمل حديثة مع مستوى من المرونة؛
- فريق ديناميكي ومتحفز من الزملاء يعملون نحو تحقيق الأهداف الوطنية لدولة الإمارات؛
- حزمة تعويضات تنافسية، تشمل مكافأة سنوية ومزايا إضافية مثل بدل تعليم الأطفال وتذاكر طيران سنوية (للمستحقين)؛
- تغطية تأمين صحي شاملة؛