SOC Engineer - Doha18,000 - 20,000
Security Monitoring & Incident Detection • Monitor SIEM, XDR, EDR, NDR, IDS/IPS, Firewall, and Cloud security alerts. Identify, validate, triage, and prioritize security incidents based on severity and business impact. Incident Response & Threat Investigation • Perform in-depth investigations, analyze malware and attack techniques, identify root cause, coordinate containment and eradication, and support incident recovery. Detection Engineering & Threat Hunting • Execute scheduled threat hunting queries, monitor hunting dashboards, validate suspicious activities, and report findings. Vulnerability & Security Operations Support • Review vulnerability scan results, track remediation status, validate patch completion, and update tickets. Reporting & Continuous Improvement • Update incident tickets, maintain shift handover notes, prepare daily operational reports, and ensure SLA compliance
Necessary Knowledge and Experience to be able to do the Job:• 1–4 years of experience in a Security Operations Center (SOC)• Experience in monitoring SIEM, EDR/XDR, IDS/IPS, firewalls, email security, and cloud security alerts.• Knowledge of alert triage, incident classification, escalation procedures, and ticket management.• Understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, routing, switching, and common network protocols.• Knowledge of Windows and Linux administration, system logs, and endpoint security.• Familiarity with common cyber threats such as phishing, malware, ransomware, brute-force attacks, web attacks, and insider threats
Education and Certification Requirements • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.• Comp TIA Security+, Comp TIA CySA+, EC-Council CND, Cisco Cyber Ops Associate, Microsoft SC-200• Added advantages CHFI , DFIR Foundations
Job Specific Skills • Ability to document incidents clearly, communicate effectively, and coordinate with internal teams during security incidents.• Basic knowledge of Power Shell, Python, or Bash for automation and log analysis is an advantage.• Ability to analyze logs from endpoints, servers, firewalls, proxies, Active Directory, cloud platforms, and security devices.