Cyber Security Operations Centre (CSOC) Specialist
TDM Group · Amman
Job description
About the role
We are seeking an experienced Cyber Security Operations Centre (CSOC) Specialist to join our dedicated team in Amman. The role focuses on continuous monitoring, proactive threat hunting, advanced security investigations, and incident response for our partners, following industry standards and modern security operations practices.
Key responsibilities
- Monitor and investigate security activity across client environments using Microsoft Sentinel, Microsoft Defender XDR and related technologies.
- Lead end‑to‑end incident response, including triage, containment, eradication, recovery and post‑incident review.
- Conduct hypothesis‑driven threat hunting and enrich investigations with threat intelligence, IOCs/IOAs and MITRE ATT&CK mapping.
- Develop, tune and maintain KQL queries, analytics rules, hunting queries and custom detections to improve coverage and reduce false positives.
- Design and maintain SOAR playbooks to automate enrichment, evidence collection, ticketing and response actions.
- Manage client incidents according to severity classifications, SLAs and MSSP service commitments, producing clear reports and remediation recommendations.
- Continuously improve detection capabilities, use‑case coverage and incident response procedures based on lessons learned.
- Mentor junior analysts and contribute to SOC procedures, playbooks, technical documentation and training exercises.
Required profile
- Bachelor’s degree in Cybersecurity, IT, Computer Science or equivalent practical experience.
- 3–5 years of hands‑on experience in a SOC, MSSP, MDR or incident response environment.
- Strong practical experience with Microsoft Sentinel, Microsoft Defender XDR, advanced KQL, threat hunting, detection engineering and SOAR automation.
- Deep understanding of MITRE ATT&CK, adversary techniques, IOC/IOA analysis and security operations across endpoint, identity, network, email and cloud.
- Relevant certifications such as SC‑200, Security+, CSA, GCIH or GCDA are desirable.
Required skills
- Microsoft Sentinel
- Microsoft Defender XDR
- KQL (Kusto Query Language)
- SOAR playbook design and automation
- SIEM and detection engineering
- Incident response lifecycle
- MITRE ATT&CK framework
- Windows and Linux operating systems
- Active Directory / Entra ID
- Network protocols and cloud technologies
What we offer
- Collaborative and supportive working environment
- Medical & dental insurance
- Additional holiday days based on length of service
- Personal days and mental health & wellbeing platform
- Learning & development platform
- Reward and recognition programs
- Gym membership contribution
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Jordan.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 3 hours ago
Expires 1 month from now
6 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
TDM Group
Amman