Overview
Security Operations Center (SOC) Lead Jobs in Damascus Governorate, Syria at Norconsult Telematics
Title: Security Operations Center (SOC) Lead
Company: Norconsult Telematics
Location: Damascus Governorate, Syria
This position is on-site based in Damascus Governorate, Syria.
Position Objective:
Defining and governing the SOC operating model and cybersecurity operations framework, ensuring all security monitoring, threat detection, incident response, and compliance requirements are fully designed, resourced, tooled, and validated ahead of Day-1 launch. Post-launch, the role transitions to governing the MSP SOC function.
Job Description & Responsibilities:
- Define the SOC operating model — structure, scope, shift model, and interface with NOC and IT operations.
- Define the cybersecurity monitoring framework — OT/IT convergence, network security, endpoint security, and threat intelligence.
- Define SIEM correlation rules, alert thresholds, SOAR playbook requirements, and incident response procedures.
- Define escalation paths for security incidents and regulatory authority interfaces.
- Define staffing levels, skills requirements, and security training framework.
- Govern SOC readiness validation — simulations, incident response drills, and acceptance sign-off.
- Define compliance validation requirements aligned to ISO 27001, IEC 62443, and NCA standards.
- Define SOC KPIs and SLA requirements covering threat detection times, incident response times, and compliance reporting obligations.
- Define SOC operating procedures and runbooks for Day-1 launch scenarios.
- Participate in cross-functional OAT (Operational Acceptance Testing) to validate end-to-end SOC readiness.
Qualifications & Experience:
- Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology
- Minimum 10 years in cybersecurity operations with SOC management or design experience.
- Experience designing or leading a SOC in a telecommunications or critical infrastructure environment.
- Knowledge of OT/IT security convergence, SIEM/SOAR platforms, and threat intelligence.
- Experience with ISO 27001, IEC 62443, and NCA security frameworks.
- Greenfield or build-to-operate program experience is advantageous.
- Strong knowledge of cybersecurity operations, threat detection, and incident response.
- Ability to define security monitoring frameworks and SOAR playbook requirements.
- Strong stakeholder management and cross-functional coordination.
- Familiarity with SIEM, SOAR, EDR, and threat intelligence platforms.
- Strong written and verbal communication in English; Arabic is an advantage.
- Experience with MSP governance, vendor performance management, and continual service improvement in security operations.