Cyber Security Operations Centre (CSOC) Specialist
We are looking for an experienced Cyber Security Operations Centre (CSOC) Specialist to join our dedicated team. This role is critical to providing continuous monitoring, proactive threat hunting, advanced security investigation, and incident response for our partners. The CSOC Specialist will work closely with partners and internal teams to ensure comprehensive protection against security threats based on industry standards and modern security operations practices.
The successful candidate will be expected to demonstrate strong hands-on expertise across Microsoft Sentinel, advanced KQL, Microsoft Defender XDR, threat hunting, SOAR automation, detection engineering, and incident response.
Key Responsibilities
Security Monitoring and Threat Detection
- Monitor and investigate security activity across client environments using Microsoft Sentinel, Microsoft Defender XDR and other security technologies.
- Correlate endpoint, identity, network, email, cloud and application telemetry to identify suspicious behaviour, attack patterns and potential compromise.
- Develop, maintain and tune KQL queries, analytics rules, hunting queries and custom detections to improve coverage and reduce false positives.
Incident Response and Coordination
- Lead incident triage and end-to-end response, including investigation, containment, eradication, recovery and post-incident review.
- Determine the scope, impact, attack path and root cause of incidents by correlating evidence across affected systems and accounts.
- Coordinate containment and remediation with internal teams, partners and clients while maintaining accurate documentation and meeting escalation requirements.
Threat Intelligence and Advanced Defence
- Conduct proactive, hypothesis-driven threat hunting across endpoint, identity, network, email and cloud environments.
- Research emerging threats and enrich investigations using threat intelligence, IOCs, IOAs and adversary behaviours.
- Map findings to MITRE ATT&CK and translate them into improved detections, security controls and response recommendations.
SIEM, SOAR and Detection Engineering
- Develop and optimise detection capabilities and investigation workflows within Microsoft Sentinel and Microsoft Defender XDR.
- Design and maintain SOAR playbooks to automate enrichment, evidence collection, ticketing, notifications and appropriate response actions.
- Perform detection-gap analysis and continuously improve security coverage based on incidents, threat intelligence and client-specific risks.
Client Reporting and SLA Management
- Manage incidents in accordance with severity classifications, client SLAs and MSSP service commitments.
- Produce clear client reporting covering incidents, security trends, detection performance, threat-hunting activity and operational metrics.
- Maintain accurate investigation records and provide clients with clear findings, risk context and remediation recommendations.
Continuous Improvement and Service Excellence
- Review and improve security use cases, detection rules, monitoring coverage and incident response procedures.
- Use operational data, lessons learned and security exercises to identify opportunities for automation and service improvement.
- Remain current with emerging threats and technologies and contribute to the continued development of TDM’s SOC capabilities and MSSP services.
Collaboration and Knowledge Sharing
- Work with internal teams, partners and clients to support coordinated incident response and security improvement.
- Mentor junior analysts and share knowledge across KQL, threat hunting, investigations, SIEM, SOAR and incident response.
- Contribute to SOC procedures, playbooks, technical documentation, training and tabletop exercises.
Qualifications and Experience
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related field, or equivalent practical experience.
- At least 3–5 years of hands-on experience within a SOC, MSSP, MDR, incident response or security operations environment.
- Strong practical experience with Microsoft Sentinel, Microsoft Defender XDR, advanced KQL, threat hunting, detection engineering, SOAR automation and end-to-end incident response.
- Strong understanding of MITRE ATT&CK, adversary techniques, IOC/IOA analysis and security operations across endpoint, identity, network, email and cloud environments.
- Relevant certifications such as SC-200, Security+, CSA, GCIH or GCDA are desirable, alongside familiarity with NIST, ITIL and recognised incident response frameworks.
Skills and Competencies
- Ability to independently investigate complex security incidents, distinguish genuine compromise from benign activity and develop effective detections and automated response workflows.
- Strong analytical and technical knowledge across SIEM, SOAR, EDR/XDR, Windows/Linux, Active Directory/Entra ID, network protocols and cloud technologies.
- Clear communication and documentation skills, with the ability to explain technical findings, risks and recommendations to clients and internal stakeholders.
- Ability to manage high-severity incidents, multiple client environments and competing priorities while remaining calm, structured and focused on SLA delivery.
- Strong collaboration, mentoring and continuous-learning mindset, with a commitment to keeping current with emerging threats and security technologies.
What We Offer
- Collaborative and supportive working environment.
- Medical & Dental insurance
- Additional holiday days for length of service
- Personal Days
- Mental health & wellbeing platform
- Learning & Development platform
- Reward and Recognition Programs
- Gym Membership Contribution
TDM Group Amman Office hours are from Monday to Friday, 10:30 AM-7:00 PM.