IT Security Officer (Amman, Jordan) Ref# ITG_53 ITG Vacancies Job Title: IT Security Officer (Amman, Jordan) Ref# ITG_53 Location - Country, City: Amman, Jordan Job Summary: The IT Security Officer will help protect the organization’s systems and information by monitoring security events, identifying vulnerabilities, implementing security controls and responding to incidents. Responsibilities: SOC operations and daily SIEM alert investigation, preferably using Elastic Security. Experience with Splunk, QRadar or Microsoft Sentinel is also acceptable. Practical experience with SIEM integration, including onboarding different log sources and developing, testing and tuning security use cases, correlation rules and alerts. Practical threat intelligence experience using free or paid platforms to collect, validate and analyze indicators of compromise (IOCs) and supporting evidence. EDR alert investigation, including process analysis, endpoint isolation, containment and false-positive identification. Practical incident response for malware, phishing, unauthorized access and other security incidents. Vulnerability assessment using Nessus, Tenable, Qualys or OpenVAS, including validating findings, prioritizing risks, following up remediation and retesting. Hands-on network and web application penetration testing using Kali Linux, Nmap, Burp Suite, Metasploit or similar tools. Windows and Linux security experience, including Windows Event Logs, Active Directory, PowerShell and Linux logs. Practical security hardening for Active Directory, firewalls, Windows and Linux servers, with good experience applying CIS Benchmarks. Good understanding of network security, firewalls, TCP/IP, DNS, VPNs and VLANs. Ability to document security findings, prepare clear technical reports and provide practical remediation recommendations. Required Skills: Hands-on experience investigating SIEM and EDR alerts and responding to security incidents. Practical knowledge of vulnerability assessment, security hardening and remediation validation. Ability to analyze threat intelligence, indicators of compromise and security logs. Strong knowledge of network security, firewalls, IDS/IPS, TCP/IP, DNS, VPNs and VLANs. Working knowledge of ISO/IEC 27001, risk assessment, security policies and audit requirements. Strong analytical, problem-solving, documentation, and communication skills. Qualifications and Experience: Bachelor's degree in Cyber Security, Computer Science, Information Technology, or a related field. Minimum of 2 years of practical experience in cybersecurity. Expertise in conducting security assessments. Proven ability to develop and implement security policies. Experience managing security and data protection risk assessments. Preferred certifications (not mandatory): SOC and Incident Response: Elastic Certified SIEM Analyst, eSOC, eCIR, eCTHP, eCDFP, HTB CDSA, BTL1, CCDL1. Advanced Defensive Security: BTL2 or CCDL2. Penetration Testing: OSCP/OSCP+, eJPT, eCPPT, eWPTX, HTB CPTS/CWES, or CEH Practical. GRC and ISO: ISO/IEC 27001 Lead Implementer/Lead Auditor, CISA, or COBIT 2019. Apply