SOC Manager
El Sheikh Zayed City, EgyptFull-timeSenior · 7-10 yearsH1B likely
About this role
Envision Employment Solutions is currently looking for a SOC Manager for one of our partners, a leading Digital Bank!
THE ROLE
You lead the defense the digital bank will be a target from the day it opens, and the Security Operations Centre you run is what detects an attack, contains it and brings the digital bank back to safety. When a major incident occurs, you and the team will lead the response, coordinate decisions and ensure customers and the bank are protected.
WHAT YOU’LL DO
- Lead the cybersecurity incident response lifecycle end to end, from identification and containment through eradication, recovery, post incident review & feeding lessons back into the organisation
- Oversee 24x7 security monitoring and incident handling against defined procedures, escalation paths and service levels
- Build and continuously improve the incident response frameworks, playbooks and readiness exercises, including tabletop simulations
- Drive threat intelligence, threat hunting and security investigations to identify emerging risks before they become incidents.
- Act as the primary escalation point during major cyber incidents, coordinating technical teams, senior management, communications and regulators.
- Improve detection quality by reducing false positives, closing visibility gaps and measuring control effectiveness.
- Ensure SIEM, SOAR, EDR and threat intelligence platforms are integrated, automated and tuned to support effective response.
- Work with Security Engineering, infrastructure and application teams to embed detection and response requirements into new systems.
- Develop the SOC team through coaching, practical exercises and clear analyst progression.
WHAT WE’RE LOOKING FOR
- 7 to 10 years in cybersecurity, with 4 to 5 years clearly running a Security Operations Center (SOC)
- Command of the full incident response lifecycle, grounded in a recognised framework such as NIST or SANS
- Hands on depth with SIEM, SOAR, EDR and threat intelligence platforms
- A record of building detection capability, playbooks and operating procedures, and readiness exercises
- Strong judgement under pressure and the ability to communicate clearly during major incidents. Certifications such as CISSP, CISM, GCIH or GCFA, and financial services cybersecurity experience, are valuable not essential
- Familiarity and experience with the Egyptian Cybersecurity framework is valuable not essential
YOU’LL THRIVE HERE IF YOU
- You stay clear headed in the middle of an incident
- You challenge weak detections
- You’d rather hunt the threat than wait for the alert
- You treat every incident as an opportunity to strengthen the digital bank's defences further
- You know the difference between a SOC that looks ready and one that is
