Analyst, Information Security (SOC)
Core
Administering Elastic SIEM, managing Cyble CTI/brand protection platforms, governing detection engineering, and overseeing managed SOC service performance for a Fintech company.
Role type
SOC/CTI Analyst (Internal Security Operations)
Builds
Operational security visibility, validated detection rules, and incident closure workflows for Tabby's Fintech infrastructure.
Domain
Fintech / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Elastic SIEM administration, log source management, detection engineering governance, cyber threat intelligence (CTI), brand protection monitoring, incident validation and closure, SLA tracking, use case library management
Preferred skills
MITRE ATT&CK framework knowledge, SAMA CSF compliance, NCA ECC requirements, Fintech threat landscape understanding
Technologies
Elastic SIEM, Cyble, syslog, Beats agents, API connectors
Responsibilities
Administer Elastic SIEM deployment including health monitoring, index lifecycle management, and log ingestion; Own log source onboarding and maintain asset inventory; Review, test, and approve detection rules and use cases from the managed SOC provider; Manage Cyble CTI platform configuration, IOC registry, and brand protection alerts; Act as internal liaison with managed SOC provider to validate escalations and oversee incident closure; Monitor managed SOC SLA performance and maintain incident registers.
Seniority
Individual Contributor (IC), mid-level specialist