Commercial International Bank
CIB is a financial service company that strives to provide superior financial solutions to meet all customers’ needs.
- Open roles
- 94
Company signals
Score: 76Job facts
- Location
- Giza, Egypt
Last verified live 1 week, 2 days ago · checked directly on the company's Oracle Taleo
More roles at Commercial International Bank
- MANPOWER BUDGETING OFFICER · Egypt-Giza-SMART VILLAGE BLDG. 4
- ACTIVATION AGENT · Egypt-Cairo-MOBTADAYAN
- Better Together – All Governorates · Egypt-Giza-GIZA BRANCH
- L&D DATA ENTRY PROCESSOR ( Outsource) · Egypt-Giza-SMART VILLAGE BLDG. 4
- PMO MANAGER · Egypt-Giza-SMART VILLAGE BLDG. 1
- Cash Counting Sub-Clerk - Maadi Area (People With Disabilities) · Egypt-Cairo-MAADI BRANCH
SOC Integration Engineer/Senior Engineer
at Commercial International Bank
-
Ensure that all log sources are reporting to the SIEM platform in order to maintain the availability of the logs.
-
Ensure all the integrated assets are reporting to their relevant solution (such as Data Activity Monitor, File Integrity Monitor, Firewall Monitor, SOAR, or TIP)
-
Monitor the log sources to make sure the log sources are sending proper logs that are used to identify incidents for reporting, detecting incidents and/or contextual data by designing and creating dashboards & periodical reports to ensure that all the integrations are functional and in healthy posture.
-
Implement and fine tune use cases over different SOC technologies (including but not limited to SIEM) as required by Security Intel team to identify incidents.
-
Implement Runbooks & automations for detection and response over SOAR platform.
-
Maintain & enhance TIP technology according to Threat Intel team operation requirements.
-
Integrate new commercial and non-commercial Threat Intel feeds with the TIP solution to enhance SOC detections, identifications, investigation and response.
-
Recommend, develop and release new integrations to maximize the benefits and efficiencies from a SOAR platform.
-
Generate reports as required by SOC management teams to be presented to the management to be used in further data analysis.
-
Work with IT systems owners to establish SIEM & SOAR technologies integrations to meet the strategic goals of identifying security incidents by defining Use Cases.
-
Deployment and Development of customized and non-customized SIEM connectors for supported and unsupported SOC log sources, and modify configuration files to achieve the full integrations with different log sources.
-
Develop scripts (Java, Python, Bash) whenever required for automating SOAR responses and SIEM log collection.
-
Fine tune collected log events to minimize false positive alerts.
-
Prepare reports to ensure compliance with the SOC requirements from regulatory and security perspectives.
-
Ensure effective records of log resources and SOC relevant platforms, to maintain the integrity and availability of all evidences used for incident response
-
Manage the continuous improvement of systems engineering processes and activities to enhance the efficiency and effectiveness of reporting and alerting.
-
Research, analyse and understand log sources utilized for the purpose of security monitoring, particularly security and networking devices (such as firewalls, routers, anti-virus products, proxies, EDR, operating systems, etc…), in order to increase effectiveness of the log correlation.
-
Provide technical inputs to management during proof-of-concept reviews for new security products to ensure alignment with the set policies and guidelines.
-
Provide technical guidance to the Security teams and/or the lines of business during investigations or incident response in order to help in the investigation and root cause analysis.