Middle Security Operations Center Engineer L2

Agencijski radVertex TechnologiesCairowuzzufobjavljeno 17. 08. 2026.
Obavezno:PythonAWSAzureGoogle CloudCloudFinTechSecurity

We are looking for a Middle SOC Engineer (L1/L2) to join our team and provide advanced security monitoring, threat detection, and incident response for an enterprise client within a B2B environment. This role focuses on deep security triage, active incident investigation, and coordination of threat containment for international clients in English.

The position requires working in a 3-shift rotation (8 hours per shift) based on Cairo time : Morning Shift: 08:00 AM – 04:00 PM

Evening Shift: 04:00 PM – 12:00 AM (Midnight)

Night Shift: 12:00 AM – 08:00 AM

What you'll be doing Perform real-time security monitoring, deep-dive analysis, and triage (L1/L2) of security alerts escalated from multiple sources (SIEM, EDR, firewalls, and system logs).

Log, track, and manage complex security incidents through ticketing systems, driving them to resolution or coordinating escalations.

Analyze network traffic (PCAP), system logs (Windows/Linux), and endpoint behavior to track lateral movement and analyze malware delivery.

Coordinate host isolation, credential revocation, and other immediate threat containment actions according to incident response playbooks.

Investigate multi-stage security incidents, draft detailed incident reports, and perform thorough root cause analysis (RCA).

Work on fine-tuning SIEM correlation rules, security tool dashboards, and optimizing detection alerts to minimize false positives.

Develop, test, and automate incident response runbooks (playbooks) and response procedures.

Communicate technical incident findings clearly to international clients and internal stakeholders via email, chat, and online meetings.

What We Offer Opportunity to work on large-scale, impactful projects

Clear career growth path within a team with 27+ years of experience

Professional, friendly, and supportive team environment

EST time zone schedule with paid overtime when applicable (up to 12 hours per shift)

Modern office in the Smart Village district.

Flexible and transparent compensation review system

Overtime compensation options

Private medical insurance after completing the probation period

Payments in USD

Upper-Intermediate to Advanced English (B2/C1, written and spoken) for daily client and internal communications.

Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical industry experience.

2 to 4 years of hands-on experience in a SOC, Security Operations Center, or active incident response role.

Solid knowledge of operating systems (Windows and Linux administration, system logs) and core networking protocols (TCP/IP, DNS, HTTP/HTTPS, SSL/TLS).

In-depth familiarity with the MITRE ATT&CK framework, common attack vectors, and techniques used by threat actors.

Practical experience working with SIEM platforms (such as Splunk, Microsoft Sentinel, or Elastic) and EDR/XDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).

Strong analytical thinking, technical documentation skills, and the ability to work under high pressure during major security incidents.

Availability to work on an 8-hour rotational shift schedule, including night shifts, weekends, and holidays.

Nice to have Relevant industry certifications (e.g., CompTIA CySA+, Blue Team Level 1/2, CEH, GCIH, or Microsoft Certified: Security Operations Analyst Associate).

Scripting and automation experience using Python, PowerShell, or Bash for security integrations and workflow optimization.

Familiarity with Cloud Security architecture (AWS, Azure, or GCP).

Experience with Security Orchestration, Automation, and Response (SOAR) platforms and Threat Intelligence Platforms (TIP).

Experience using ticketing and incident management tools like ServiceNow and JIRA.