Job Description/Specification:
A leading organization in Doha, Qatar is urgently seeking a highly skilled Tier 3 SOC Analyst to join its Security Operations Center. This is the highest technical escalation role within the SOC, responsible for tackling complex cyber threats, leading full‑lifecycle incident response, and driving advanced detection engineering initiatives.
💼 Key Responsibilities
-
Act as the final escalation point for high‑severity security alerts
-
Lead full‑lifecycle incident response: detection, containment, eradication, recovery, and post‑incident review
-
Conduct advanced threat hunting across endpoints, networks, identity, and cloud environments
-
Map findings to the MITRE ATT&CK framework for structured analysis
-
Investigate sophisticated attacks including ransomware, privilege escalation, lateral movement, and data exfiltration
-
Develop and optimize SIEM correlation rules, custom use cases, and alert logic
-
Build and maintain SOPs, runbooks, and incident response playbooks
-
Champion automation initiatives using SOAR platforms
-
Collaborate with Infrastructure, Cloud, IAM, and Network teams during critical incidents
-
Mentor Tier 1 and Tier 2 analysts to elevate SOC capabilities
🎯 Required Qualifications & Technical Skills
-
Minimum 8+ years of cybersecurity experience, focused on SOC operations and incident response
-
Deep hands‑on expertise with SIEM platforms (Microsoft Sentinel, Splunk ES, IBM QRadar, Google Chronicle)
-
Proven experience with EDR/XDR tools (CrowdStrike, Microsoft Defender XDR, SentinelOne) and SOAR orchestration
-
Advanced knowledge of Windows/Linux OS, Active Directory, TCP/IP, firewalls, proxies, IDS/IPS, and cloud architectures (Azure, AWS, GCP)
-
Proficiency in scripting (Python, PowerShell, Bash) for automation
-
Mandatory active SANS/GIAC certification (GCIH, GCFA, GCIA, GNFA, GCFE, GCTI, GSOC, or GSEC)
🚀 Preferred Qualifications
-
Additional certifications (CISSP, CCSP, OSCP, SC‑200/SC‑100)
-
Experience in enterprise, government, critical infrastructure, or MSSP environments
-
Familiarity with compliance frameworks (NIST, ISO 27001, CIS)
👤 Candidate Profile
-
Willing and able to relocate to Qatar and work 100% onsite
-
Strong professional background in European markets preferred
-
Exceptional written and verbal English communication skills
-
Flexible to participate in shift work or on‑call rotations during critical incidents
⭐ Skills That Will Help You Succeed
-
Advanced incident response and forensic analysis
-
Threat hunting and detection engineering expertise
-
Strong SIEM/EDR/XDR configuration and optimization skills
-
Ability to lead cross‑functional collaboration during crises
-
Mentorship and leadership within SOC environments
💡 How to Stand Out
Hiring managers will value candidates who:
-
Highlight measurable outcomes (e.g., reduced incident response times, improved detection coverage)
-
Showcase experience in handling ransomware or advanced persistent threats (APTs)
-
Demonstrate leadership in building SOC playbooks and automation initiatives
-
Provide examples of mentoring junior analysts and elevating SOC maturity
🎤 Interview Preparation
Expect questions such as:
-
“Describe a major incident you led from detection to recovery.”
-
“How do you approach proactive threat hunting in enterprise environments?”
-
“What steps do you take to optimize SIEM rules and reduce false positives?” Prepare by discussing real cases, emphasizing technical depth, leadership, and measurable impact.
📈 Career Growth
This role can lead to:
-
SOC Manager or Head of Cybersecurity Operations
-
Threat Intelligence Lead or Incident Response Director
-
Opportunities to specialize in advanced detection engineering or cyber defense strategy
❓ Frequently Asked Questions
Q: Is relocation required? Yes, candidates must be willing to relocate and work onsite in Qatar.
Q: Are certifications mandatory? Yes, at least one active SANS/GIAC certification is required.
Q: What type of environments will I work in? Enterprise SOC with exposure to government, critical infrastructure, and MSSP operations.
Q: Is European market experience important? Yes, candidates with significant European market experience are highly preferred.