SOC Manager
Envision Employment Solutions is currently looking for a SOC Manager for one of our partners, a leading Digital Bank!
THE ROLE
You lead the defense the digital bank will be a target from the day it opens, and the Security Operations Centre you run is what detects an attack, contains it and brings the digital bank back to safety. When a major incident occurs, you and the team will lead the response, coordinate decisions and ensure customers and the bank are protected.
WHAT YOU’LL DO
- Lead the cybersecurity incident response lifecycle end to end, from identification and containment through eradication, recovery, post incident review & feeding lessons back into the organisation
- Oversee 24x7 security monitoring and incident handling against defined procedures, escalation paths and service levels
- Build and continuously improve the incident response frameworks, playbooks and readiness exercises, including tabletop simulations
- Drive threat intelligence, threat hunting and security investigations to identify emerging risks before they become incidents.
- Act as the primary escalation point during major cyber incidents, coordinating technical teams, senior management, communications and regulators.
- Improve detection quality by reducing false positives, closing visibility gaps and measuring control effectiveness.
- Ensure SIEM, SOAR, EDR and threat intelligence platforms are integrated, automated and tuned to support effective response.
- Work with Security Engineering, infrastructure and application teams to embed detection and response requirements into new systems.
- Develop the SOC team through coaching, practical exercises and clear analyst progression.
WHAT WE’RE LOOKING FOR
- 7 to 10 years in cybersecurity, with 4 to 5 years clearly running a Security Operations Center (SOC)
- Command of the full incident response lifecycle, grounded in a recognised framework such as NIST or SANS
- Hands on depth with SIEM, SOAR, EDR and threat intelligence platforms
- A record of building detection capability, playbooks and operating procedures, and readiness exercises
- Strong judgement under pressure and the ability to communicate clearly during major incidents. Certifications such as CISSP, CISM, GCIH or GCFA, and financial services cybersecurity experience, are valuable not essential
- Familiarity and experience with the Egyptian Cybersecurity framework is valuable not essential
YOU’LL THRIVE HERE IF YOU
- You stay clear headed in the middle of an incident
- You challenge weak detections
- You’d rather hunt the threat than wait for the alert
- You treat every incident as an opportunity to strengthen the digital bank's defences further
- You know the difference between a SOC that looks ready and one that is
As published by workable
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter
- How did you hear about us? choose one
- If you were referred to this role by a recruiter, please provide their name. written answer
- Do you have a minimum of 7-10 years of overall cybersecurity experience? yes / no
- Do you have at least 4-5 years of experience specifically leading or running a Security Operations Center (SOC)? yes / no
- Have you worked in banking, financial services, or another regulated industry? yes / no
- Do you hold or have you held a relevant certification (e.g., CISSP, CISM, GCIH, GCFA)? yes / no
- Do you have hands-on experience with SIEM, SOAR, EDR, or threat intelligence platforms? ( yes / no
- This is a full-time, on-site role (9 AM to 6 PM). Are you comfortable and available to work on-site during these hours? yes / no
- Are you currently based in Egypt? If not, are you willing to relocate to Egypt for this role? choose one
- How would you rate your English proficiency (written and spoken)? written answer
- Describe your experience leading or running a Security Operations Center. What was the team size and scope of coverage (24/7, hybrid, etc.)? written answer
- Walk us through a major security incident you managed end-to-end, from detection through containment, recovery, and post-incident review. written answer
- What incident response frameworks (e.g., NIST, SANS) have you used, and how did you apply them in practice? written answer
- Tell us about your experience with threat hunting or threat intelligence, how did you use it to proactively reduce risk? written answer
- Describe a time you had to act as the primary escalation point during a major cyber incident. How did you coordinate with leadership and other teams? written answer
- What SIEM, SOAR, or EDR platforms have you worked with, and what was your role in optimizing their use? written answer
- Briefly describe your experience working within a regulated environment (banking, finance, or similar), including any compliance requirements relevant to a SOC. written answer
- What is your current monthly net salary? written answer
- What are your expected monthly net salary requirements? written answer
- When can you start? (Notice Period) written answer