Cyber Defense Specialist - Detection & Monitoring
Role overview
Location: On-site – Riyadh, Saudi Arabia Contract/engagement: Project-based managed cybersecurity services (13-month RFP term) Minimum experience: 7+ years
Role Purpose Strengthen SOC detection and monitoring capabilities across SIEM, SOAR, EDR, DLP, email security, and other security platforms.
Key Responsibilities · Develop and enhance security detection capabilities across SIEM, SOAR, EDR, DLP, and email security platforms. · Design correlation logic, detection rules, threat-detection use cases, alerts, and supporting response workflows. · Integrate telemetry and logs from security systems to improve monitoring coverage. · Continuously tune detections to improve accuracy and reduce false positives. · Analyze security events and suspicious activity and escalate validated threats through approved processes. · Maintain SOC policies, procedures, workflows, and operational playbooks. · Map detection coverage to MITRE ATT&CK and coordinate improvements with cybersecurity, governance, and technical teams. · Support security assessments, regulatory compliance, reporting, and security-vendor coordination.
Requirements Technical and Professional Requirements · Bachelor’s degree in Computer Science, Information Security, or a related field. · At least 7 years of experience in SOC operations or cyber defense. · Hands-on experience with SIEM, SOAR, EDR, DLP, email security gateways, and log/telemetry integration. · Proven experience developing detection use cases and tuning security rules. · Knowledge of cyberattack techniques, threat detection, MITRE ATT&CK, NCA requirements, and SOC operating models.
Personal Requirements · Strong analytical and problem-solving skills. · Clear communication, documentation, and cross-team coordination. · Persistent, quality-focused, and comfortable working with vendors and technical partners. · Able to prioritize alerts and improvements in a high-volume operational environment.
Professional Certifications Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.