Back to board
envisiones·13 days ago

SOC Manager

El Sheikh Zayed City, EgyptFull-timeSenior · 7-10 yearsH1B likely

About this role

Envision Employment Solutions is currently looking for a SOC Manager for one of our partners, a leading Digital Bank!

 

THE ROLE

You lead the defense the digital bank will be a target from the day it opens, and the Security Operations Centre you run is what detects an attack, contains it and brings the digital bank back to safety. When a major incident occurs, you and the team will lead the response, coordinate decisions and ensure customers and the bank are protected.

WHAT YOU’LL DO

  • Lead the cybersecurity incident response lifecycle end to end, from identification and containment through eradication, recovery, post incident review & feeding lessons back into the organisation 
  • Oversee 24x7 security monitoring and incident handling against defined procedures, escalation paths and service levels 
  • Build and continuously improve the incident response frameworks, playbooks and readiness exercises, including tabletop simulations 
  • Drive threat intelligence, threat hunting and security investigations to identify emerging risks before they become incidents. 
  • Act as the primary escalation point during major cyber incidents, coordinating technical teams, senior management, communications and regulators. 
  • Improve detection quality by reducing false positives, closing visibility gaps and measuring control effectiveness. 
  • Ensure SIEM, SOAR, EDR and threat intelligence platforms are integrated, automated and tuned to support effective response. 
  • Work with Security Engineering, infrastructure and application teams to embed detection and response requirements into new systems. 
  • Develop the SOC team through coaching, practical exercises and clear analyst progression.

WHAT WE’RE LOOKING FOR

  • 7 to 10 years in cybersecurity, with 4 to 5 years clearly running a Security Operations Center (SOC)
  • Command of the full incident response lifecycle, grounded in a recognised framework such as NIST or SANS
  • Hands on depth with SIEM, SOAR, EDR and threat intelligence platforms
  • A record of building detection capability, playbooks and operating procedures, and readiness exercises
  • Strong judgement under pressure and the ability to communicate clearly during major incidents. Certifications such as CISSP, CISM, GCIH or GCFA, and financial services cybersecurity experience, are valuable not essential
  • Familiarity and experience with the Egyptian Cybersecurity framework is valuable not essential

YOU’LL THRIVE HERE IF YOU

  • You stay clear headed in the middle of an incident
  • You challenge weak detections
  • You’d rather hunt the threat than wait for the alert
  • You treat every incident as an opportunity to strengthen the digital bank's defences further
  • You know the difference between a SOC that looks ready and one that is