logo

Information Security Engineer - SOC L2 (Security Operations Center)

Tanger-Tétouan-Al Hoceïma

Décryptage du poste par Postule AI

About Tabby

Tabby is a leading FinTech platform in the GCC region with over 25 million users, enabling flexible payment solutions for shoppers and businesses. The company has raised over $1 billion in funding and is valued at $6.5 billion.

Role Overview

As an Information Security Engineer (SOC L2), you will be a key defender of Tabby's infrastructure, applications, and cloud environments. You'll lead incident response efforts, develop detection rules, investigate security events, and collaborate with cross-functional teams to strengthen our security posture.

Main Responsibilities

Security Monitoring & Detection

  • Monitor and analyze logs and alerts from firewalls, IDS/IPS, endpoints, servers, and cloud platforms
  • Perform event correlation across multiple sources to identify advanced threats and unusual behavior patterns
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio
  • Maintain dashboards and reporting for real-time visibility into security posture

Incident Response & Investigation

  • Serve as frontline responder for security incidents, managing full lifecycle from detection through recovery
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches
  • Perform root cause analysis and forensic investigations using endpoint and network artifacts
  • Maintain detailed incident documentation and contribute to post-mortem analysis

Threat Intelligence & Detection Rule Development

  • Research emerging threats and trends to inform detection strategies
  • Create and tune detection rules, threat-hunting queries, and use cases across multiple platforms
  • Maintain CTI Platform and integrate CTI feeds with security controls for active threat-driven detections

Collaboration and Communication

  • Communicate effectively with IT, DevOps, Risk, and Compliance teams during incidents
  • Provide clear updates to stakeholders and management during incident handling
  • Mentor junior analysts and assist in SOC team training efforts

Required Skills & Experience

  • 2–3 years in SOC or cybersecurity operations role, preferably in fintech or enterprise environment
  • Strong knowledge of incident handling, alert triage, log analysis, and threat modeling
  • Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms
  • Familiarity with DLP, AV, and anti-malware systems from operational perspective
  • Experience with phishing detection, user behavior analytics, and security awareness
  • Understanding of REST APIs, microservices, and modern application architectures
  • Scripting experience (Python) to automate tasks and improve SOC efficiency
  • Familiarity with cloud environments and cloud-native logging and monitoring tools

Security certifications (Security+, CySA+, eCIR, eCTHPv2, GCIA, GMON) are preferred but not required.

Cette description d'emploi a pu être reformatée par Postule pour améliorer sa lisibilité et sa présentation. Le contenu et les informations restent fidèles à l'offre d'emploi originale. .

Offres similaires

Recevoir les offres similaires

Sécurité, chaque matin par e-mail.

Voir les offres Sécurité