IT Security Officer (Amman, Jordan) Ref# ITG_53

Job Title: IT Security Officer (Amman, Jordan) Ref# ITG_53

Location - Country, City: Amman, Jordan

Job Summary:

The IT Security Officer will help protect the organization’s systems and information by monitoring security events, identifying vulnerabilities, implementing security controls and responding to incidents.

Responsibilities:

  • SOC operations and daily SIEM alert investigation, preferably using Elastic Security. Experience with Splunk, QRadar or Microsoft Sentinel is also acceptable.
  • Practical experience with SIEM integration, including onboarding different log sources and developing, testing and tuning security use cases, correlation rules and alerts.
  • Practical threat intelligence experience using free or paid platforms to collect, validate and analyze indicators of compromise (IOCs) and supporting evidence.
  • EDR alert investigation, including process analysis, endpoint isolation, containment and false-positive identification.
  • Practical incident response for malware, phishing, unauthorized access and other security incidents.
  • Vulnerability assessment using Nessus, Tenable, Qualys or OpenVAS, including validating findings, prioritizing risks, following up remediation and retesting.
  • Hands-on network and web application penetration testing using Kali Linux, Nmap, Burp Suite, Metasploit or similar tools.
  • Windows and Linux security experience, including Windows Event Logs, Active Directory, PowerShell and Linux logs.
  • Practical security hardening for Active Directory, firewalls, Windows and Linux servers, with good experience applying CIS Benchmarks.
  • Good understanding of network security, firewalls, TCP/IP, DNS, VPNs and VLANs.
  • Ability to document security findings, prepare clear technical reports and provide practical remediation recommendations.

Required Skills:

  • Hands-on experience investigating SIEM and EDR alerts and responding to security incidents.
  • Practical knowledge of vulnerability assessment, security hardening and remediation validation.
  • Ability to analyze threat intelligence, indicators of compromise and security logs.
  • Strong knowledge of network security, firewalls, IDS/IPS, TCP/IP, DNS, VPNs and VLANs.
  • Working knowledge of ISO/IEC 27001, risk assessment, security policies and audit requirements.
  • Strong analytical, problem-solving, documentation, and communication skills.

 

Qualifications and Experience:

  • Bachelor's degree in Cyber Security, Computer Science, Information Technology, or a related field.
  • Minimum of 2 years of practical experience in cybersecurity.
  • Expertise in conducting security assessments.
  • Proven ability to develop and implement security policies.
  • Experience managing security and data protection risk assessments.
  • Preferred certifications (not mandatory):
    • SOC and Incident Response: Elastic Certified SIEM Analyst, eSOC, eCIR, eCTHP, eCDFP, HTB CDSA, BTL1, CCDL1.
    • Advanced Defensive Security: BTL2 or CCDL2.
    • Penetration Testing: OSCP/OSCP+, eJPT, eCPPT, eWPTX, HTB CPTS/CWES, or CEH Practical.
    • GRC and ISO: ISO/IEC 27001 Lead Implementer/Lead Auditor, CISA, or COBIT 2019.