Skip to content
Maroc Emploi IT

SOC, pentest, GRC and network security Cybersecurity jobs in Morocco

SOC, penetration testing, governance, network or cloud security: drop your CV. Your tools and certifications are read with their dates, your current employer is hidden by default, and companies come to you.

Your CV isn't on this phone?

Have a paper CV? Take a photo of it, flat and readable.

You'll receive the link to this page to upload your CV from your computer. No account is created.

Your contact details stay hidden until an approved company reaches out to you.

  • Free, always
  • No account, no password
  • Invisible to your current employer

Recognised skills

What our analysis recognises in a cybersecurity CV

The skills referential holds 104 entries for this field, recognised under their usual names and abbreviations. Nothing is added that isn't in your CV; anything you add yourself is marked “declared”.

Security104 skills

  • LDAP
  • Microsoft Defender for Endpoint
  • Microsoft Purview
  • Cybersecurity
  • Fortinet
  • Palo Alto Networks
  • Check Point
  • Sophos
  • Stormshield
  • pfSense
  • Zscaler
  • Security Operations Center
  • SIEM
  • Splunk
  • IBM QRadar
  • Wazuh
  • ArcSight
  • LogRhythm
  • FortiSIEM
  • Cortex XDR
  • SOAR
  • EDR
  • CrowdStrike Falcon
  • SentinelOne
  • Kaspersky
  • Trend Micro
  • Symantec
  • IDS/IPS
  • Penetration testing
  • Red teaming
  • OWASP
  • Burp Suite
  • Metasploit
  • Nessus
  • Qualys
  • Nmap
  • Vulnerability management
  • Application security
  • DevSecOps
  • Snyk
  • Checkmarx
  • Trivy
  • Cloud security
  • OT security
  • Identity and access management
  • Privileged access management
  • Okta
  • SailPoint
  • Keycloak
  • HashiCorp Vault
  • OAuth 2.0
  • OpenID Connect
  • SAML
  • JWT
  • PKI
  • Cryptography
  • DLP
  • WAF
  • Zero Trust
  • Digital forensics
  • Incident response
  • Threat intelligence
  • Malware analysis
  • Reverse engineering
  • Security audit
  • IT audit
  • GRC
  • ISO 27001
  • ISO 27005
  • EBIOS Risk Manager
  • NIST Cybersecurity Framework
  • PCI DSS
  • GDPR
  • Moroccan Law 09-08
  • NIS 2
  • DORA
  • CISSP
  • CISM
  • CISA
  • CEH
  • OSCP
  • CompTIA Security+
  • Bank Al-Maghrib regulation
  • MITRE ATT&CK
  • Threat hunting
  • Cobalt Strike
  • BloodHound
  • Impacket
  • TheHive
  • Sigma rules
Plus 14 more specific skills (services, versions, sub-frameworks)
  • Microsoft Defender for Cloud
  • Kali Linux
  • AD FS
  • Cisco ASA
  • Cisco ISE
  • Network security
  • Firewalls
  • Microsoft Sentinel
  • CyberArk
  • WALLIX
  • Security Operations Analyst (SC-200)
  • Ghidra
  • MISP
  • Elastic Security (SIEM)

Proven or declared

A proven skill is worth more than a keyword.

A skill is “proven” when a dated experience in your CV shows you used it, and “declared” otherwise. The recruiter sees the difference, along with the sentence from your CV that serves as evidence.

  • Date every assignmentStart and end month and year: the duration of each skill is calculated from your dates.
  • Name the tools inside the assignmentA tool mentioned in a dated experience is proven. In a plain list at the end of the CV, it stays declared.
  • At an IT services firm, name the end clientEmployer and end client are read separately: the recruiter sees who you actually worked for.

Example — fictitious data

SOC analyst — An IT services firm in Rabat for a banking group · 01/2023 → today
Alert investigation on Microsoft Sentinel and CrowdStrike Falcon, detection rules mapped to MITRE ATT&CK, incident tracking in TheHive.

Taken from this line, and proven by it:

Microsoft Sentinel · CrowdStrike Falcon · MITRE ATT&CK · TheHive

Matching

How your profile is matched with a job ad

For each job ad, your profile gets a score out of 100, built from six criteria. Every point gained or lost is explained to the recruiter, who makes the decision: nobody is rejected automatically.

Your role, and the neighbouring roles

Your main role is compared with the role of the job. Experience in a neighbouring role partly counts; in a related role, a little less.

  • DevOps / SRECybersecurityrelated
  • Cloud engineeringCybersecurityrelated
  • Networks and systemsCybersecurityrelated
  • Microsoft infrastructureCybersecurityrelated

Equivalent tools, not exact keywords

If the job ad asks for a tool you don't have but you master its equivalent, your experience still partly counts. A more specific skill also counts for its family, and the other way round. An exact match counts more.

  • SIEM platformsequivalentSplunk, IBM QRadar, Microsoft Sentinel, Wazuh, Elastic Security (SIEM), ArcSight, LogRhythm, FortiSIEM
  • EDR / XDR platformsequivalentCrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR
  • FirewallsneighboursFortinet, Palo Alto Networks, Check Point, Cisco ASA, Sophos, Stormshield, pfSense
  • Vulnerability scannersequivalentNessus, Qualys
  • Code and dependency scanningneighboursCheckmarx, Snyk, SonarQube, Trivy
  • Risk analysis methodsequivalentEBIOS Risk Manager, ISO 27005
  • PAM solutionsneighboursCyberArk, WALLIX
  • Offensive security certificationsneighboursCEH, OSCP

A broad requirement, proven by your tools

When the job ad asks for a field rather than a tool, it is proven by the specific tools in your CV:

  • Security Operations CenterSIEM, EDR, Splunk, IBM QRadar, Microsoft Sentinel, Wazuh, Elastic Security (SIEM), ArcSight and more
  • SIEMSplunk, IBM QRadar, Microsoft Sentinel, Wazuh, Elastic Security (SIEM), ArcSight, LogRhythm, FortiSIEM
  • EDRCrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR
  • Network securityFortinet, Palo Alto Networks, Check Point, Cisco ASA, IDS/IPS, VPN

The six criteria of the score

  • 35%SkillsThe required skills, backed by your experience, with how long and how recently you used them.
  • 15%RoleYour main role compared with the job: DevOps, data, development…
  • 20%ExperienceRelevant years for this job — not too few, not way too many.
  • 12%SalaryYour net expectation compared with the company's budget, also net.
  • 10%LocationCity, remote work, mobility: what works for both sides.
  • 8%AvailabilityWhen you can start, notice period included.

Default weighting, published on the “How it works” page.

The job's must-have skills count separately: if one is missing, the whole score goes down and the profile cannot be rated “Strong”.

In cybersecurity, certifications (CISSP, CISM, CEH, OSCP…) are read with their dates: an expired certification is not counted.

How the score works, in full

Your journey

What you do, and nothing more.

  1. 1

    You drop your CV

    PDF, Word or a photo, up to 10 MB. No account, no password. Your consent is asked before any analysis.

  2. 2

    Your profile fills in

    Experience, skills, certifications, languages, live. You remove what was misread and add what's missing.

  3. 3

    Five questions, then a final check

    Location, availability, pay as a net monthly salary or a day rate, spoken languages, French companies. Then your e-mail if it isn't on your CV, the companies that must not see you, and a summary.

  4. 4

    Companies come to you

    Your profile appears, without your name or contact details, in the rankings of the job ads that match you. An interested company contacts you by e-mail.

Your data, under your control

  • Free for candidates, always.
  • Your current employer, read from your CV, is hidden by default.
  • Your contact details are only visible to an approved company that decides to contact you, and that access is logged.
  • You can delete everything from “My profile”, immediately. Otherwise, everything is deleted 24 months after your last activity.

For companies

And on the recruiters' side?

Companies are approved by our team before they can access profiles. They paste their job ad and receive ranked, explained profiles, with the sentence from the CV that proves each skill. Name, photo, age, gender, school: none of it goes into the score.

Frequently asked questions

You're probably wondering…

The job ad asks for a “SOC”, my CV mentions Splunk and CrowdStrike. Does it count?

Yes: a requirement like SOC is proven by the specific tools in your CV, for example a SIEM (Splunk, IBM QRadar, Microsoft Sentinel…) or an EDR (CrowdStrike Falcon, SentinelOne…).

Are my CEH or OSCP certifications taken into account?

Yes, with their dates: an expired certification is not counted. CEH and OSCP are neighbouring certifications: one partly counts when the job ad asks for the other.

I work at a bank: will my employer see my profile?

No, if you don't want it to. Your current employer, read from your CV, is hidden by default, and you can hide other companies too.

I come from networks or systems. Does my experience count?

Partly: networks and systems, Microsoft infrastructure, DevOps and cloud are related roles of cybersecurity. Experience in security counts more.

Ready? Drop your CV.

Free, no account, and invisible to your current employer.

Drop your CV