SOC Engineer - L3 (Senior)
Job Description Roles & Responsibilities Mal is seeking a senior SOC Analyst to establish our foundational security monitoring, detection, and incident response capabilities. As the first dedicated security operations hire at Mal, you will play a crucial role in protecting the world's first Sharia-compliant digital bank. You will work closely with our CISO and engineering teams to design, implement, and operate best-in-class security controls, ensuring the safety and resilience of our rapidly scaling banking products. Mal is looking for a Senior SOC Analyst to stand up and lead our security monitoring, detection, and incident response function. This is the founding hire of our Detection & Response team a high-ownership role where you will design our SIEM pipeline, build our detection content and runbooks, lead incident response, and shape a SOC function that will scale to 24/7 coverage. You will be our eyes on the platform and the person customers, regulators, and the business rely on to catch and stop security incidents before they cause harm. Design and build our security monitoring pipeline end-to-end log collection, SIEM, detection content, alerting, and dashboards across production, cloud, identity, endpoint, and application sources Develop and tune detection use cases aligned to Mal s threat model, product risks, and regulatory obligations; treat detections as code and manage them with the same rigor Lead incident response end-to-end triage, investigation, containment, eradication, recovery, and post-incident review and define severity schemes, runbooks, and communication procedures Run proactive threat hunts across cloud, identity, and application telemetry to uncover attacker activity and detection gaps Monitor for fraud and abuse signals relevant to a digital bank (account takeover, credential stuffing, payment abuse) in partnership with product and risk teams Stand up and manage the MSSP/MDR relationship that bridges 24/7 coverage, and progressively bring capabilities in-house as the team grows Establish and track SOC metrics (MTTD, MTTR, alert volume, false-positive rate) and drive continuous improvement against them Use AI and automation to scale triage, enrichment, and response building workflows and agents that reduce analyst toil and accelerate time to respond Feed lessons learned back into product security, engineering, and platform teams so that every incident improves the overall security posture Support audit, compliance, and regulatory readiness by producing monitoring and incident evidence aligned to PCI DSS, SOC 2, ISO 27001, and banking regulator expectations Inventory existing log sources, telemetry, and tooling; produce a prioritized gap analysis against Mal s threat model and regulatory obligations Stand up or mature the SIEM pipeline with a core set of high-signal detections across cloud, identity, and application sources Define incident severity levels, response runbooks, on-call expectations, and internal/external communication procedures Establish an MSSP/MDR engagement to bridge 24/7 coverage, with clear handoff, escalation, and quality criteria Set baseline SOC metrics (MTTD, MTTR, alert volume, false-positive rate) and start reporting against them Deliver a Detection & Response roadmap and headcount plan aligned to the CISO s InfoSec program and the banking license timeline Desired Candidate Profile Significant hands-on experience in a SOC, detection and response, or incident response role Strong experience with at least one modern SIEM platform (e.g., Splunk, Elastic, Sentinel, Chronicle, Panther) and with designing, tuning, and operating detections Proven incident response experience leading investigations through triage, containment, and post-incident review Solid experience monitoring and investigating security events in cloud environments (AWS, GWS), including identity, workloads, and infrastructure Working knowledge of EDR tooling, endpoint investigation, and log analysis techniques Strong grasp of attacker tradecraft and frameworks (e.g., MITRE ATT&CK) and how to translate them into detections Scripting or automation skills (Python, PowerShell, Bash) and comfort with detection-as-code and version-controlled workflows Experience building or improving incident response runbooks, severity schemes, and on-call processes Ability to operate with ownership and autonomy in ambiguous, fast-moving environments comfortable being the first SOC hire and building from scratch Strong written and verbal communication skills, including the ability to brief leadership calmly and clearly during incidents Previous experience in fintech, banking, or other regulated financial services environments Familiarity with financial-sector frameworks and regulations (PCI DSS, SOC 2, ISO 27001, NIST CSF, CBUAE, FSRA and breach notification obligations (GDPR, PDPL) Experience managing or transitioning away from MSSP/MDR relationships Exposure to threat intelligence, purple teaming, or adversary emulation Experience securing AI and LLM-powered products, including detections for AI-specific abuse patterns Experience using AI tools and agents to automate SOC workflows (triage, enrichment, reporting) Relevant certifications (GCIA, GCIH, GCFA, GCFR, GNFA, OSCP, or equivalent) Knowledge of English or additional languages Company Industry InternetE-commerceDotcom Department / Functional Area Engineering Keywords SOC Engineer - L3 (Senior) Get real-time job updates only on our App
Ready to apply?
You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.
Apply NowOpens the employer's site in a new tab
- CompanyMal.AI
- LocationEgypt
- CategoryAI
- SourceNaukrigulf
- Listed1 week ago
Related AI jobs
AI Engineer - Security
At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio. We are currently looking for a highly proactive and…
AI/ML Computational Scientist Manager
YOU ARE As an AI/ML Computational Scientist, you will design, build, and operationalize artificial intelligence and machine learning solutions for enterprise…
Senior Software Engineer
Aspire Software is looking for a Senior Software Engineer who is AI-first in how they think, build and work. This means using modern AI coding tools every day…
Product Owner (Core Banking)
We are seeking an exceptional Product Owner Core Banking to own the platform at the centre of the bank: the core banking system, the general ledger, treasury…