An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Oman Investment Authority seeks a Senior Specialist SOC to lead advanced security investigations and improve detection and response across on‑premises and cloud environments. You will guide junior analysts, develop use cases, and partner with threat intelligence to elevate proactive defense.
As a Tier-3 SME, you will design detection logic, review incident workflows, and drive continuous improvement, aligning with MITRE ATT&CK, NIST CSF and ISO 27035 frameworks.
ROLE OBJECTIVE Senior Specialist SOC is responsible for advanced security event analysis complex incident investigation and continuous improvement of SOC detection and response capabilities Acting as a Tier-3 analyst and technical SME the role provides guidance to junior analysts develops advanced use cases and ensures that all detection mechanisms and incident workflows are optimized for accuracy speed and resilience The incumbent also collaborates with threat intelligence and vulnerability management teams to build a proactive defense posture across all monitored environments
Lead advanced incident investigations across multiple security domains including network endpoint application and cloud environments Perform in-depth root cause analysis RCA and support major incident response and forensics as part of L3 escalation Design and optimize detection logic and correlation rules within SIEM SOAR and EDR platforms Develop automation playbooks to streamline triage and containment activities reducing MTTD and MTTR Conduct proactive threat hunting based on intelligence reports behavioral analytics and anomaly detection Coordinate with internal and external threat intelligence sources to contextualize alerts and enhance detection maturity Validate and integrate threat feeds and ensure enrichment of SOC alerting with contextual indicators IOCs TTPs threat campaigns
Maintain and enhance SOC playbooks escalation matrices and knowledge base documentation Ensure SOC processes align with frameworks such as MITRE ATT amp CK NIST CSF and ISO 27035 Conduct post-incident reviews and lessons-learned workshops with stakeholders to drive continuous improvement Support compliance and audit requirements through proper evidence collection and reporting Participate in internal tabletop exercises and ensure readiness of incident response protocols
Provide technical advisory support during customer escalations or executive reviews Develop and deliver weekly monthly SOC performance and threat trend reports to management Support onboarding of new customers into SOC services including configuration of log sources connectors and correlation logic
Mentor SOC Analysts Tier-1 and Tier-2 in advanced analytical and investigative techniques Conduct internal knowledge-sharing sessions on new threats vulnerabilities and emerging attack techniques Contribute to the creation of SOC training materials and technical assessments Support capacity building initiatives by recommending certification and skill development plans
Bachelor s degree in Information Technology, Cybersecurity, or related discipline.Certification GCIA, GCIH, CEH, CHFI, CompTIA CySA+, or SANS Threat Hunting certifications preferred.Minimum 5 7 years in SOC operations or incident response, with at least 2 years in Tier-3 analysis or advanced forensics.Skills SOC management, threat response, governance, customer reporting, team leadership, and service management.