Overview
Security Operations Center (SOC) SME Jobs in Damascus Governorate, Syria at Norconsult Telematics
Title: Security Operations Center (SOC) SME
Company: Norconsult Telematics
Location: Damascus Governorate, Syria
This position is on-site based in Damascus Governorate, Syria.
Position Objective:
The SOC SME is responsible for providing deep technical expertise to support the SOC operating model design, developing detailed SIEM/SOAR specifications and incident response procedures, and validating technical readiness ahead of Day-1 launch. Post-launch, the role transitions to providing technical oversight of the MSP SOC function.
Job Description & Responsibilities:
- Develop detailed SIEM correlation rules, alert thresholds, SOAR playbook requirements, and incident response procedures.
- Develop security procedures for international regulatory compliance, including cross-border incident notification requirements and carrier licensing obligations.
- Develop SOC runbooks and technical procedures for common security event scenarios.
- Support the SOC Lead in defining staffing skills requirements and training content.
- Participate in SOC readiness simulations and incident response drills.
- Support acceptance testing of SOC tooling.
- Define compliance validation requirements aligned to ISO, IEC, and NCA standards.
- Define KPI measurement methodology for SOC operational KPIs — data sources, calculation logic, and SIEM configuration requirements to support accurate KPI reporting.
- Contribute to OAT (Operational Acceptance Testing) by validating SOC tooling, procedures, and integration readiness.
- Review MSP SIEM rule updates and validate technical accuracy and completeness.
- Assess MSP SOAR playbook changes and incident response procedure updates.
- Support SOC governance reviews with technical analysis of detection gaps and false positive trends.
- Validate MSP compliance controls against ISO 27001, IEC 62443, and NCA requirements.
- Support development of security specifications for carrier peering and interconnection infrastructure, including BGP security controls.
Qualifications & Experience:
- Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology
- Minimum 8 years in cybersecurity operations with hands-on SOC analyst or engineering experience.
- Technical expertise in SIEM, SOAR, and threat intelligence platforms.
- Experience in OT/IT security convergence in telecommunications or critical infrastructure.
- Experience developing SIEM rules, playbooks, and incident response procedures.
- Familiarity with ISO 27001, IEC 62443, and NCA standards.
- Deep technical knowledge of cybersecurity monitoring, threat detection, and incident response.
- Ability to develop SIEM rules, playbooks, and security procedures.
- Strong analytical and problem-solving skills.
- Familiarity with SIEM, SOAR, EDR, and threat intelligence tools.
- Strong written and verbal communication in English; Arabic is an advantage
- Experience with international telecommunications security compliance and carrier-specific threat landscapes.