Security Operations & Monitoring Engineer
Role overview
Location: Dammam, Saudi Arabia Employment Type: Full-Time | Onsite Project Duration: Long-term project assignment
About the Role
We are seeking a Security Operations & Monitoring Engineer to provide continuous monitoring and security-event analysis across encryption, KMS, HSM, database security, and related infrastructure. The successful candidate will work closely with the SOC/SIEM and technical teams to identify suspicious activities, triage security events, support incident response, and ensure timely escalation and reporting.
Key Responsibilities
- Perform continuous monitoring of cybersecurity systems and infrastructure.
- Monitor encryption, KMS, HSM, database security, and other security-related events.
- Review and analyze system, security, audit, and application logs.
- Monitor security alerts through SIEM/SOC platforms.
- Perform first-level investigation and triage of cybersecurity events.
- Correlate alerts from multiple security technologies to identify potential incidents.
- Escalate critical or suspicious activities according to established procedures.
- Support incident-response investigations and evidence collection.
- Coordinate with engineering teams during security incidents and service-impacting events.
- Support the tuning of monitoring rules and alert thresholds.
- Prepare operational, security, and incident reports.
- Maintain incident records, monitoring procedures, and operational documentation.
- Participate in shift, maintenance, and on-call activities when required.
Requirements
Required Qualifications & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering , or related field.
- 4+ years of experience in SOC, SIEM, security monitoring, incident triage, or cybersecurity operations.
- Hands-on experience with SIEM and security monitoring platforms.
- Good understanding of security events, logs, alerts, incident handling, and escalation procedures.
- Experience integrating security solutions with central SOC/SIEM platforms.
- Strong analytical and troubleshooting skills.
- Must be available full-time onsite in Dammam .
Required Certification
- CompTIA Security+ .
Preferred Certifications
- CompTIA CySA+ .
- Splunk Core Certified Power User.
- Splunk Certified Cybersecurity Defense Analyst.
- Equivalent recognized SIEM/SOC certification.
Core Competencies SOC | SIEM | Security Monitoring | Incident Triage | Log Analysis | Incident Response | Alert Management | Threat Detection | Reporting
Candidates should include the SIEM/SOC platforms they have used, the type of monitoring environments they supported, and their relevant certifications.