Key Result Areas:
- Contribute to the development and implement strategies for containment and recovery, including advanced forensics and mitigating actions to contain malicious activity. Facilitate further remedial actions and identification of threat campaigns to strengthen the overall security posture.
- Prioritize and manage actions during incident response, carry out analysis for the containment of cybersecurity incidents, and communicate any special requirements of high severity incidents to internal stakeholders to ensure comprehensive threat mitigations.
- Respond to incidents raised by Security Operations Analysts by following Bapco Energies’ Incident Response process. Carry out advanced technical tasks such as forensics and malware reverse-engineering to identify threat scope and remediate the most difficult incidents to restore the services.
- Perform regular vulnerability assessments to assess the effectiveness of security systems. Isolate and remediate areas of weakness to ensure continuous and optimal protection for integrity and availability.
- Review alerts, threat intelligence and other security data, and perform Threat Hunting to identify threats and take the appropriate steps to eliminate them.
- Develop incident playbooks, custom scripts, or utility applications to process repetitive tasks and increase CDC/NOC team productivity; develop use cases to support CDC operations.
- Support the creation of business continuity/disaster recovery plans, including conducting disaster recovery tests, publishing test results, and making changes necessary to address deficiencies for ensuring the business continuity
- Assist in the design of systems security infrastructure and provide technical security guidance as needed for projects.
- Participate in development of security plans, risk assessment plans, business continuity plans, incident response plans, and cybersecurity policies and standards
- Train and mentor CDC/NOC analysts in utilizing security tools and understanding security threats and intelligence.
Communications and Working Relationships:
Internal
Interacts frequently with Manager Cyber Defense Center to discuss operational issues and to provide daily status updates for ongoing work, as well as other relevant compliance reports and performance metrics as required.
Communicates regularly and aligns actions with all IT/OT technical groups to ensure that all systems and networks are operated securely.
Liaises with other IT/OT groups and ITD sections and – if needed - with business units, to identify and validate attempts at intrusion or compromise, and provides high quality investigation and response actions.
Liaises closely with IT Governance section to ensure that all formally documented processes, policies, procedures, and guidelines remain commensurate with the current security threat environment.
External
Acts as focal point of communication with relevant service providers in the event of high severity Incident Response.
Liaises with cybersecurity agencies to collect and exchange threat intelligence and coordinate incident response activities.
Works with vendors to ensure any upgrades or patches to security solutions are implemented in a timely manner.
Minimum 6–8 years of experience in cybersecurity, with a strong focus on security operations, incident response, threat hunting, or related domains.
- Bachelor’s degree in Computer Science, Information Security, or a related field. Relevant industry certifications (e.g., CISSP, CISM, GIAC) are preferred.
- Advanced proficiency with security technologies, including SIEM platforms, intrusion detection/prevention systems, endpoint detection and response (EDR) solutions, and network security monitoring tools.
- Demonstrated ability to analyze complex security event data, identify patterns and anomalies, and make data-driven decisions to detect and respond to threats effectively.
- Deep understanding of cybersecurity principles, technologies, and best practices, with working knowledge of industry standards and frameworks such as the NIST Cybersecurity Framework and MITRE ATT&CK.
- Proven experience in leading or mentoring SOC teams or junior analysts, with the ability to coordinate and guide incident response activities.
- Strong analytical, problem-solving, and communication skills, with the ability to document findings and present technical information clearly to both technical and non-technical audiences.
Skills Required
- 6-8 years of experience in cybersecurity with focus on security operations, incident response, or threat hunting.
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Relevant industry certifications (e.g., CISSP, CISM, GIAC).
- Advanced proficiency with SIEM platforms, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR) solutions, and network security monitoring tools.
- Experience performing digital forensics and malware reverse-engineering.
- Demonstrated ability to analyze complex security event data, identify patterns/anomalies, and make data-driven decisions.
- Working knowledge of NIST Cybersecurity Framework and MITRE ATT&CK.
- Proven experience leading or mentoring SOC teams and coordinating incident response activities.
- Experience developing incident playbooks, use cases, and automation/scripts to streamline SOC workflows.
- Strong analytical, problem-solving, documentation, and communication skills for technical and non-technical audiences.
What We Do
To power the next generation.








