Job Grade: OG-II
Reports to: SOC Manager
Location: Head Office, Islamabad
The role involves monitoring, detecting, investigating, and responding to security incidents across the Bank. The successful candidate will ensure timely resolution of escalated alerts by leveraging advanced security monitoring tools, conducting thorough incident investigations, performing threat hunting activities, and continuously improving the SOC’s detection and response capabilities. This position plays a critical role in safeguarding the Bank’s information assets and maintaining a strong security posture.
Key Responsibilities
- Monitor and investigate security alerts using SIEM, XDR/EDR, DLP, DAM, PAM, WAF, IDS/IPS, and firewall technologies.
- Perform advanced log analysis, event correlation, IOC investigation, and root-cause analysis to identify security threats.
- Investigate and respond to various security incidents such as malware infections, phishing attacks, account compromises, privilege abuse, lateral movement, and data exfiltration.
- Conduct proactive threat hunting using SIEM, EDR/XDR, and threat intelligence to identify emerging threats. Develop, tune, and optimize security tools through correlation rules, use cases, queries, and dashboards.
- Identify gaps in monitoring capabilities and support the onboarding and validation of new log sources. Analyze threat intelligence and translate relevant threats into actionable detection use cases.
- Maintain detailed incident records, investigation timelines, and comprehensive incident reports. Collaborate with IT, Network, Infrastructure, and Application teams to ensure effective containment and remediation of incidents.
- Update and maintain SOC runbooks, playbooks, and monitoring procedures to ensure operational readiness and consistency.
Required Qualifications
- Strong knowledge of SOC operations and incident response processes.
- Hands-on experience with IBM QRadar or equivalent SIEM platforms.
- Solid understanding of Windows and Linux operating systems, networking fundamentals, Active Directory, and authentication mechanisms.
- Familiarity with MITRE ATT&CK framework, threat hunting methodologies, and IOC analysis. Experience with XDR/EDR, DLP, DAM, PAM, WAF, and IDS/IPS is preferred.
- Scripting skills in PowerShell, Python, or Bash are advantageous.
- 1 to 3 years of experience in SOC or cybersecurity roles, ideally within the banking or financial services sector.
Preferred Qualifications and Benefits
- Understanding of AI models and Agentic AI concepts related to SOC operations is a plus.
Mobilink Bank serves over 64 million registered users, including 21 million monthly active customers across Pakistan. The Bank operates through a hybrid model that integrates traditional microfinance with mobile and digital banking technologies. With a network of more than 132 branches and 324,000 branchless banking agents, Mobilink Bank offers a wide range of digital financial services including USSD-based savings, microenterprise loans, housing loans, remittances, bill collection, mobile wallets, insurance, and various payment solutions. This extensive reach positions the Bank as a leader in promoting financial inclusion across the country.
Mobilink Bank is dedicated to fostering a positive and productive workplace culture. The organization values innovation, entrepreneurship, teamwork, collaboration, and a customer-centric approach in all business activities. Joining Mobilink Bank offers an opportunity to contribute meaningfully to transformative change, empowering millions with the tools needed to succeed in the digital age. This role is ideal for professionals passionate about making a difference in cybersecurity within a dynamic and impactful environment.