دیجی‌‌کالا | Digikala

تاسیس در ۱۳۸۴ کامپیوتر، فناوری اطلاعات و اینترنت بیش از ۱۰۰۰ نفر digikala.com

استخدام SOC Team Lead

  • دسته‌بندی شغلی

    IT / DevOps / Server
  • موقعیت مکانی

    تهران ، تهران
  • نوع همکاری

    تمام وقت
  • حداقل سابقه کار

    بیش از شش سال
  • حقوق

    توافقی

شرح موقعیت شغلی

Overview:

The SOC Team Lead leads an engineering-driven Security Operations function covering detection, threat hunting, investigation, incident response, forensics, automation, and security platforms.

This role develops a team of SOC Engineers and modernizes SOC capabilities through improved telemetry, integrated security tools, engineering practices, and AI-enabled workflows.

Responsibilities:

  • Define and execute the SOC strategy, architecture, operating model, and modernization roadmap.
  • Lead and develop SOC Engineers across detection, hunting, investigation, response, forensics, automation, and platform operations.
  • Lead complex incidents and coordinate investigation, containment, remediation, forensic analysis, and post-incident improvements.
  • Develop and continuously validate detection rules, hunting content, playbooks, and response workflows.
  • Improve security visibility across endpoints, networks, identities, applications, cloud environments, and infrastructure.
  • Own and integrate SIEM, SOAR, EDR/XDR, NDR, DLP, PAM, vulnerability management, and security platforms.
  • Automate enrichment, triage, investigation, hunting, response, and reporting using scripts, APIs, SOAR, and specialized AI agents with appropriate human oversight.
  • Define and track detection coverage, investigation quality, response time, automation effectiveness, and security-tool health.
  • Collaborate with OffSec, IT, infrastructure, cloud, DevOps, risk and compliance teams.
  • Communicate incidents, capability gaps, risks, and improvement priorities to senior management.
Requirements:

  • 7+ years of experience in security operations, detection engineering, incident response, threat hunting, forensics, or security engineering.
  • Proven experience leading multidisciplinary security engineers and technical initiatives.
  • Deep hands-on experience with SIEM platforms, particularly Splunk Enterprise Security.
  • Strong knowledge of security telemetry, detection engineering, investigation, threat hunting, incident response, and digital forensics.
  • Practical experience with major SOC technologies, including EDR/XDR, NDR, SOAR, DLP, PAM, IAM, vulnerability management, and cloud security tools.
  • Experience integrating and automating security platforms using APIs and scripting, preferably Python or PowerShell.
  • Strong knowledge of MITRE ATT&CK, network security, identity threats, and cloud security.
  • Strong leadership, systems thinking, technical decision-making, and stakeholder communication skills.
Preferred Certifications:

CISSP, CISM, GCFA, GCIH, GCIA, Splunk Enterprise Certified Architect, or equivalent practical qualifications.

معرفی شرکت

ما در دیجی‌کالا به عنوان شرکتی که در حوزه تجارت الکترونیک فعالیت می‌کنه، به دنبال تحقق رویای «لبخندی برای همه ایران» هستیم. در همین راستا، با بهره‌گیری از فناوری‌های روز دنیا و توسعه مداوم سرویس‌های مبتنی بر تکنولوژی، ارزش‌های‌ خودمون رو در مشتری‌محوری، اشتیاق برای تعالی، کارگروهی و نتیجه‌گرایی دنبال می‌کنیم.
در گروه دیجی‌کالا امکانی فراهم شده تا ما با افراد با تخصص‌های متنوع در یک مجموعه فعالیت کنیم. علاوه بر این، با توجه به سرعت رشد بالا در دیجی‌کالا، امکان رشد و توسعه رو در مواجهه با چالش‌ها و استفاده از برنامه‌های توسعه و آموزش متنوع داریم.
  • مهارت‌های مورد نیاز

    soc امنیت شبکه siem
  • جنسیت

    مهم نیست
  • وضعیت نظام وظیفه

    معافیت تحصیلی معافیت دائم پایان خدمت
  • حداقل مدرک تحصیلی

    کارشناسی

مشاغل مشابه

چه موردی را می‌خواهید گزارش کنید؟

از اینجا شروع کنید

در شغل بهتری استخدام شوید! رایگان!

  • جستجو و ارسال رزومه به آگهی‌های استخدام بیش از ۱۰۰,۰۰۰ شرکت ایرانی
  • رزومه‌ساز رایگان
  • دریافت فرصت‌های شغلی جدید مرتبط از طریق ایمیل (Job Alert)
  • شناخت محیط کار و فرهنگ سازمانی شرکت‌های در حال استخدام
image/svg+xml