# SOC Manager

**Company:** [Envision Employment Solutions](http://jobs.workable.com/companies/ojATcwx3VkivFzs5Nma6Ka.md)
**Location:** El Sheikh Zayed City, Egypt
**Workplace:** on site
**Employment type:** Full-time
**Department:** Information Technology

[Apply for this job](http://jobs.workable.com/view/56a4284e-9ab3-494f-8027-0aa74a3e7569)

## Description

_**Envision Employment Solutions**_ _is currently looking for a_ _**SOC Manager**_ _for one of our partners, a leading Digital Bank!_

**THE ROLE**

You lead the defense the digital bank will be a target from the day it opens, and the Security Operations Centre you run is what detects an attack, contains it and brings the digital bank back to safety. When a major incident occurs, you and the team will lead the response, coordinate decisions and ensure customers and the bank are protected.

**WHAT YOU’LL DO**

-   Lead the cybersecurity incident response lifecycle end to end, from identification and containment through eradication, recovery, post incident review & feeding lessons back into the organisation 
-   Oversee 24x7 security monitoring and incident handling against defined procedures, escalation paths and service levels 
-   Build and continuously improve the incident response frameworks, playbooks and readiness exercises, including tabletop simulations 
-   Drive threat intelligence, threat hunting and security investigations to identify emerging risks before they become incidents. 
-   Act as the primary escalation point during major cyber incidents, coordinating technical teams, senior management, communications and regulators. 
-   Improve detection quality by reducing false positives, closing visibility gaps and measuring control effectiveness. 
-   Ensure SIEM, SOAR, EDR and threat intelligence platforms are integrated, automated and tuned to support effective response. 
-   Work with Security Engineering, infrastructure and application teams to embed detection and response requirements into new systems. 
-   Develop the SOC team through coaching, practical exercises and clear analyst progression.

**WHAT WE’RE LOOKING FOR**

-   **7 to 10 years in cybersecurity, with 4 to 5 years clearly running a Security Operations Center (SOC)**
-   Command of the full incident response lifecycle, grounded in a recognised framework such as NIST or SANS
-   Hands on depth with SIEM, SOAR, EDR and threat intelligence platforms
-   A record of building detection capability, playbooks and operating procedures, and readiness exercises
-   Strong judgement under pressure and the ability to communicate clearly during major incidents. Certifications such as CISSP, CISM, GCIH or GCFA, and financial services cybersecurity experience, are valuable not essential
-   Familiarity and experience with the Egyptian Cybersecurity framework is valuable not essential

**YOU’LL THRIVE HERE IF YOU**

-   You stay clear headed in the middle of an incident
-   You challenge weak detections
-   You’d rather hunt the threat than wait for the alert
-   You treat every incident as an opportunity to strengthen the digital bank's defences further
-   You know the difference between a SOC that looks ready and one that is
