Live opening · Posted 22 hours ago

CyberSoc Specialist

TDM Group · Amman, Jordan
Bamboohr No Full-Time
You are 22 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 22 hours ago
CompanyTDM Group
LocationAmman, Jordan
Job typeFull-Time
Work modeNo
SourceBamboohr
Listed22 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
1 min from Bamboohr publishing this role to us finding it
8 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
73,082 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Cyber Security Operations Centre (CSOC) Specialist
We are looking for an experienced Cyber Security Operations Centre (CSOC) Specialist to join our dedicated team. This role is critical to providing continuous monitoring, proactive threat hunting, advanced security investigation, and incident response for our partners. The CSOC Specialist will work closely with partners and internal teams to ensure comprehensive protection against security threats based on industry standards and modern security operations practices.
The successful candidate will be expected to demonstrate strong hands-on expertise across Microsoft Sentinel, advanced KQL, Microsoft Defender XDR, threat hunting, SOAR automation, detection engineering, and incident response.
Key Responsibilities
Security Monitoring and Threat Detection
Monitor and investigate security activity across client environments using Microsoft Sentinel, Microsoft Defender XDR and other security technologies.
Correlate endpoint, identity, network, email, cloud and application telemetry to identify suspicious behaviour, attack patterns and potential compromise.
Develop, maintain and tune KQL queries, analytics rules, hunting queries and custom detections to improve coverage and reduce false positives.
Incident Response and Coordination
Lead incident triage and end-to-end response, including investigation, containment, eradication, recovery and post-incident review.
Determine the scope, impact, attack path and root cause of incidents by correlating evidence across affected systems and accounts.
Coordinate containment and remediation with internal teams, partners and clients while maintaining accurate documentation and meeting escalation requirements.
Threat Intelligence and Advanced Defence
Conduct proactive, hypothesis-driven threat hunting across endpoint, identity, network, email and cloud environments.
Research emerging threats and enrich investigations using threat intelligence, IOCs, IOAs and adversary behaviours.
Map findings to MITRE ATT&CK and translate them into improved detections, security controls and response recommendations.
SIEM, SOAR and Detection Engineering
Develop and optimise detection capabilities and investigation workflows within Microsoft Sentinel and Microsoft Defender XDR.
Design and maintain SOAR playbooks to automate enrichment, evidence collection, ticketing, notifications and appropriate response actions.
Perform detection-gap analysis and continuously improve security coverage based on incidents, threat intelligence and client-specific risks.
Client Reporting and SLA Management
Manage incidents in accordance with severity classifications, client SLAs and MSSP service commitments.
Produce clear client reporting covering incidents, security trends, detection performance, threat-hunting activity and operational metrics.
Maintain accurate investigation records and provide clients with clear findings, risk context and remediation recommendations.
Continuous Improvement and Service Excellence
Review and improve security use cases, detection rules, monitoring coverage and incident response procedures.
Use operational data, lessons learned and security exercises to identify opportunities for automation and service improvement.
Remain current with emerging threats and technologies and contribute to the continued development of TDM’s SOC capabilities and MSSP services.
Collaboration and Knowledge Sharing
Work with internal teams, partners and clients to support coordinated incident response and security improvement.
Mentor junior analysts and share knowledge across KQL, threat hunting, investigations, SIEM, SOAR and incident response.
Contribute to SOC procedures, playbooks, technical documentation, training and tabletop exercises.
Qualifications and Experience
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related field, or equivalent practical experience.
At least 3–5 years of hands-on experience within a SOC, MSSP, MDR, incident response or security operations environment.
Strong practical experience with Microsoft Sentinel, Microsoft Defender XDR, advanced KQL, threat hunting, detection engineering, SOAR automation and end-to-end incident response.
Strong understanding of MITRE ATT&CK, adversary techniques, IOC/IOA analysis and security operations across endpoint, identity, network, email and cloud environments.
Relevant certifications such as SC-200, Security+, CSA, GCIH or GCDA are desirable, alongside familiarity with NIST, ITIL and recognised incident response frameworks.
Skills and Competencies
Ability to independently investigate complex security incidents, distinguish genuine compromise from benign activity and develop effective detections and automated response workflows.
Strong analytical and technical knowledge across SIEM, SOAR, EDR/XDR, Windows/Linux, Active Directory/Entra ID, network protocols and cloud technologies.
Clear communication and documentation skills, with the ability to explain technical findings, risks and recommendations to clients and internal stakeholders.
Ability to manage high-severity incidents, multiple client environments and competing priorities while remaining calm, structured and focused on SLA delivery.
Strong collaboration, mentoring and continuous-learning mindset, with a commitment to keeping current with emerging threats and security technologies.
What We Offer
Collaborative and supportive working environment.
Medical & Dental insurance
Additional holiday days for length of service
Personal Days
Mental health & wellbeing platform
Learning & Development platform
Reward and Recognition Programs
Gym Membership Contribution
TDM Group Amman Office hours are from Monday to Friday, 10:30 AM-7:00 PM.

Employment type
Full-Time

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App