Position: Tier 2 SOC Analyst
Location: Tripoli
Employment Type: Full-Time
Reports To: Chief Information Security Officer (CISO)
Role Purpose
Perform advanced security investigations, threat hunting, evidence analysis, root-cause analysis and containment recommendations for escalated cases.
Core Responsibilities
- Investigate escalated alerts and incidents using approved tools and procedures.
- Correlate endpoint, network, identity, application and threat-intelligence evidence.
- Perform proactive threat hunting and document hypotheses and results.
- Develop incident timelines, RCA findings and corrective-action recommendations.
- Support containment and recovery decisions within delegated limits.
- Review Tier 1 escalations and provide quality guidance.
- Maintain complete case evidence and escalate critical exposure promptly.
Key Deliverables
- Investigation and threat-hunting reports.
- Incident timeline and RCA.
- Containment and remediation recommendations.
- Tier 1 quality feedback.
- Complete evidence and case records.
Authority and Escalation
- Authority Level: Advanced analytical and response authority within approved playbooks; cannot independently approve high-impact containment or enterprise risk acceptance.
- Escalates To: SOC Manager/CISO for critical incident, high-impact containment, material business impact or unclear authority.
Capability Requirements
- Technical / Functional Knowledge: Threat hunting, incident investigation, SIEM/EDR, malware/network analysis, evidence handling and RCA.
- Experience: Experienced SOC, incident-response or threat-detection background.
- Education / Certifications: Relevant degree; CySA+, GCIH or comparable certification preferred.
- Core Behaviors: Analytical rigor, curiosity, documentation, teamwork, escalation judgment and resilience.
a.mohamed@fawri.ly
https://wa.me/218919020942
Location: Tripoli_/_طرابلس | Type: Contract_-_عقد_عمل | Category: Information_Security-أمن_المعلومات







