IT SOC Analyst

PARCO - Pak-Arab Refinery Limited

Karachi Division

On-site

PKR 1,800,000 - 2,800,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Pak-Arab Refinery Limited (PARCO) invites applications for an IT SOC Analyst (Contractual) to manage cybersecurity incidents through their lifecycle, enhance threat detection, and coordinate with technical and business teams during incidents. The role requires 5–8 years of hands-on cyber security experience and strong SIEM/EDR expertise.

The incumbent will perform threat hunting, incident response playbooks, tabletop exercises, and cross-functional collaboration to strengthen PARCO's security

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, IT, or a related field.
  • Strong analytical, investigative, and problem-solving capabilities.
  • Ability to manage cybersecurity incidents in high-pressure situations.
  • Coordination across technical, risk, and business functions.
  • Excellent documentation and stakeholder communication skills.
  • Certs such as ECIH, CHFI, CySA+ preferred.

Responsibilities

  • Monitor, investigate, and respond to cybersecurity incidents end-to-end.
  • Proactive threat hunting across endpoints, networks, cloud, and identities.
  • Analyze alerts, IOCs, and attacker TTPs to improve detections.
  • Develop and tune SIEM/EDR detection rules and use cases.
  • Prepare incident reports with timelines, findings, and actions.

Skills

Cybersecurity Incident Response
Threat Hunting
SIEM
EDR/XDR
MITRE ATT&CK
KQL/SPL
Incident Investigation
Root Cause Analysis
Report Writing

Education

Bachelor’s degree in Information Security
Bachelor’s degree in Computer Science/IT

Tools

Splunk
IBM QRadar
Trend Micro
Microsoft Defender
CrowdStrike

Job description

Pak-Arab Refinery Limited

IT SOC Analyst (Contractual)
Pak-Arab Refinery Limited (PARCO)

Pak-Arab Refinery Limited (PARCO), an integrated energy conglomerate, is a Joint Venture between Pakistan and Emirate of Abu Dhabi. PARCO owns and operates Pakistan’s most modern refinery, over 2,000 kms of pipeline network, strategic storage facilities and marketing operations. The Company has Joint Ventures with renowned international companies and is continually following an aggressive growth strategy with planned expansions, acquisitions, and penetration into new markets.

PARCO is seeking applications for the position of IT SOC Analyst (Contractual).

About The Role

The role is responsible for managing cybersecurity incidents throughout their complete lifecycle and strengthening the organization’s threat detection and response capabilities. The position will conduct proactive threat hunting, investigate security alerts, improve SIEM and EDR/XDR detections, maintain incident response playbooks, facilitate tabletop exercises, and coordinate with technical and business teams during cybersecurity incidents.

Qualification and Competencies
  • Bachelor’s degree in Information Security, Computer Science, IT, or a related field.
  • Strong analytical, investigative, and problem-solving capabilities.
  • Ability to work effectively in high-pressure situations and manage cybersecurity incidents in a structured manner.
  • Strong coordination and collaboration capabilities across technical, risk, and business functions.
  • Ability to clearly document and communicate technical findings, incident impact, root causes, and recommended actions.
  • Strong report-writing, presentation, and stakeholder-management skills.
  • Relevant certifications such as ECIH, CHFI, CySA+, or equivalent will be preferred.
Experience
  • 5-8 years of relevant hands-on experience in cybersecurity, incident response, threat hunting, security operations, or a related field.
  • Demonstrated experience managing end-to-end cybersecurity incidents, including Detection, Investigation, Containment, Eradication, Recovery and Post-incident review.
  • Strong practical experience conducting threat hunting using SIEM, EDR/XDR, network, endpoint, identity, and cloud telemetry.
  • Experience developing, tuning, and improving security detection rules, alerts, and monitoring use cases.
  • Experience developing, maintaining, and improving incident response playbooks and procedures.
  • Experience assessing organizational incident response capabilities and identifying improvement areas through tabletop exercises and other simulations.
  • Experience working in a Security Operations Centre or cybersecurity operations environment and coordinating with cross-functional teams.
  • Exposure to threat intelligence, vulnerability management, security assessments, and security-control improvement will be preferred.
  • Experience in a 24/7 SOC or mature cybersecurity operations environment will be an added advantage.
  • Candidates with experience in the following industries will be preferred:
  • Oil and Gas
  • Banking and Financial Services
  • Telecommunications
  • Technology and IT Services
  • Critical Infrastructure
  • Other highly regulated or security-sensitive industries
Job Responsibilities
  • Monitor, investigate, and respond to cybersecurity incidents from initial detection through containment, eradication, recovery, and post-incident review.
  • Conduct proactive threat hunting across endpoints, networks, identities, cloud environments, applications, and security logs.
  • Analyze security alerts, Indicators of Compromise (IOCs), and attacker Tactics, Techniques, and Procedures.
  • Develop, tune, test, and continuously improve SIEM and EDR/XDR detection rules, alerts, correlation logic, and security-monitoring use cases.
  • Investigate security events, determine their scope and impact, and perform detailed root-cause analysis.
  • Prepare comprehensive incident reports covering the incident timeline, findings, root cause, impact, response actions, and lessons learned.
  • Develop, maintain, test, and continuously improve incident response playbooks, procedures, and escalation mechanisms.
  • Plan, coordinate, and facilitate cybersecurity tabletop exercises to assess organizational incident response preparedness.
  • Develop realistic tabletop exercise scenarios based on relevant cyber threats and business risks.
  • Document tabletop exercise observations, findings, gaps, lessons learned, and improvement recommendations.
  • Track remediation activities arising from tabletop exercises and ensure their timely closure.
  • Use threat intelligence and the MITRE ATT&CK framework to enhance threat-hunting, detection, investigation, and defensive capabilities.
  • Collaborate with SOC, IT, infrastructure, cloud, application, risk, and business teams during cybersecurity incidents.
  • Continuously identify gaps in security processes and controls and recommend practical improvements.
Specific Skills
  • Strong expertise in cybersecurity Incident Response and Threat Hunting.
  • Hands-on experience with SIEM platforms such as Splunk, IBM Q-Radar or any other equivalent.
  • Hands-on experience with EDR/XDR platforms such as Trend Micro / Microsoft Defender / CrowdStrike or any other equivalent.
  • Strong knowledge of MITRE ATT&CK framework, Cyber threat intelligence, Indicators of Compromise (IOCs), Tactics, Techniques, and Procedures (TTPs) and Adversary behaviour and attack patterns.
  • Ability to analyze Windows and Linux logs, network traffic, endpoint telemetry, identity and authentication events, cloud telemetry and security alerts & event logs.
  • Knowledge of Kusto Query Language (KQL), Search Processing Language (SPL), or equivalent security query languages.
  • Ability to develop, test, and tune detection rules and monitoring use cases while reducing false positives.
  • Strong skills in tabletop exercise planning, scenario development, coordination, facilitation, documentation, and reporting.
  • Knowledge of recognized incident response frameworks, incident response playbooks, escalation procedures, and post-incident review processes.
  • Strong incident investigation, root-cause analysis, technical documentation, and report-writing skills.
Location

Corporate Headquarters - Karachi

PARCO is an equal opportunity employer. We value diversity and encourage candidates from all backgrounds to apply. Our commitment to a conducive work environment is designed to attract and nurture top talent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT SOC Analyst: Incident Response & Threat Hunting
Senior IT SOC Analyst: Incident Response & Threat Hunting

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 1,800,000 - 2,800,000
IT/IS Governance Analyst
IT/IS Governance Analyst

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 2,400,000 - 4,200,000
Assistant Security Officer
Assistant Security Officer

PARCO - Pak-Arab Refinery Limited • Kot Chutta

On-site
PKR 420,000 - 720,000
SAP Integration Specialist
SAP Integration Specialist

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
SOC Manager
SOC Manager

Mobilink Microfinance Bank Ltd • Gadap Town

On-site
PKR 2,500,000 - 3,500,000
SharePoint Developer
SharePoint Developer

PARCO - Pak-Arab Refinery Limited • Kot Chutta

On-site
PKR 1,800,000 - 3,000,000
Security & Pipeline Protection Officer (Contract)
Security & Pipeline Protection Officer (Contract)

PARCO - Pak-Arab Refinery Limited • Kot Chutta

On-site
PKR 420,000 - 720,000
Group Head HR - Transformation & Projects
Group Head HR - Transformation & Projects

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 2,400,000 - 5,400,000
IT/IS GRC Analyst — ISO 27001 & Risk
IT/IS GRC Analyst — ISO 27001 & Risk

PARCO - Pak-Arab Refinery Limited • Karachi Division

On-site
PKR 2,400,000 - 4,200,000
Customer Engineering Technician
Customer Engineering Technician

Parco Pearl Gas • Karachi Division

On-site
PKR 600,000 - 1,000,000