Pakistan Digital Authority is seeking a Security Operations Engineer to join its team in Islamabad. The successful candidate will be responsible for managing and optimizing the security operations infrastructure, including monitoring, incident response, and threat hunting. This role involves investigating security events, tuning security controls, supporting forensic evidence collection, and contributing to the continuous enhancement of the Security Operations Center (SOC). The position requires close collaboration with various technical teams to ensure robust security posture and compliance with organizational policies.
Key Responsibilities
- Monitor and investigate security alerts using SIEM, EDR/XDR, firewalls, IDS/IPS, FIM, and other security platforms. Conduct incident triage, escalation, containment, and forensic support.
- Maintain and optimize SIEM rules, dashboards, correlation logic, alert thresholds, and log sources. Administer and troubleshoot security monitoring tools, supporting upgrades, tuning, integrations, and vendor coordination.
- Perform threat hunting by analyzing logs from servers, endpoints, network devices, firewalls, applications, and authentication systems. Investigate malware, phishing attempts, unauthorized access, privilege escalation, and suspicious network activity.
- Configure and manage firewalls, VPNs, IDS/IPS, NAT, routing, access controls, VLANs, trunking, ACLs, network segmentation, and troubleshoot related network infrastructure components.
- Support vulnerability management processes, including remediation tracking and monitoring security control effectiveness to identify and close gaps.
- Maintain SOC governance documentation such as playbooks, SOPs, incident response procedures, and investigation records. Assist in security assessments, audits, compliance activities, and remediation efforts.
- Prepare regular security operations reports with relevant KPIs and KRIs. Coordinate with Network, Infrastructure, DevOps, Application, and Information Security teams to resolve security issues and enhance controls.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related field from an HEC-recognized institution.
- Minimum 4+ years of hands-on experience in SOC operations, incident response, network security, or cybersecurity roles.
- Practical experience with SIEM, EDR/XDR, firewalls, IDS/IPS, Active Directory, vulnerability management, Windows/Linux security, and log analysis.
- Strong understanding of TCP/IP, DNS, DHCP, VPN, routing, switching, network segmentation, and network security principles.
Preferred Qualifications and Benefits
- Certifications such as Security+, CEH, SC-200, CCNP, Fortinet, or vendor-specific SIEM/security certifications are highly desirable.
- Experience with enterprise-grade firewalls like FortiGate or Cisco, and Cisco or equivalent network switches/routers is preferred.
- Familiarity with security platforms such as FortiSIEM, LogRhythm, Splunk, Microsoft Sentinel, Trend Micro, Microsoft Defender, and Nessus will be advantageous.
- Knowledge of the MITRE ATT&CK framework, basic scripting and automation skills, and ability to work in a 24x7/shift SOC environment are important competencies.
- Strong analytical thinking, incident management skills, and ability to maintain confidentiality in a dynamic security operations environment.
Applications will be accepted for 15 days from the date of publication, with ongoing review until the position is filled. Interested candidates are encouraged to apply promptly to be considered for this critical role within Pakistan Digital Authority.