More jobs:
Senior Specialist Cybersecurity Production
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-07-17
Listing for:
TAWANTECH
Full Time
position Listed on 2026-07-17
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Responsibilities
- Provide end-to-end production support for cybersecurity platforms including Splunk (SIEM), SOAR, and VPN infrastructure ensuring high availability and service reliability.
- Monitor security platforms, dashboards, and alerts to ensure continuous operational effectiveness and proactive issue detection.
- Manage Incident, Problem, and Change processes in accordance with ITIL standards, ensuring timely resolution and proper escalation.
- Perform root cause analysis (RCA) for system outages, performance degradation, and security incidents, ensuring corrective and preventive actions are implemented.
- Administer and support Splunk use cases, correlation rules, log ingestion pipelines, and performance optimization.
- Operate and maintain SOAR playbooks, workflows, and automation scripts to enhance incident response and reduce manual intervention.
- Support VPN technologies including secure remote access, site-to-site connectivity, authentication mechanisms, and encryption protocols.
- Ensure compliance with SAMA Cybersecurity Framework, NCA ECC, PDPL, and NDMO data governance and classification requirements.
- Execute Disaster Recovery (DR) and Business Continuity Plan (BCP) activities including regular testing, failover validation, and documentation updates.
- Collaborate with internal security teams, infrastructure teams, and external vendors for issue resolution, patching, upgrades, and system enhancements.
- Maintain operational documentation including runbooks, SOPs, playbooks, system configurations, and knowledge base articles.
- Implement monitoring, alert tuning, and automation to improve detection accuracy, reduce false positives, and increase operational efficiency.
- Track KPIs, SLAs, and system performance metrics for cybersecurity platforms and produce operational reports.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field.
- 4–8 years of experience in cybersecurity production support within banking or financial services environments.
- Hands‑on experience with Splunk (Enterprise / ES), SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR), and VPN solutions (e.g., IPSec, SSL VPN).
- Strong understanding of SIEM use cases, log management, threat detection, and incident response workflows.
- Experience with ITIL processes including Incident, Problem, and Change Management.
- Exposure to SAMA regulations, NCA ECC controls, PDPL, and NDMO data governance frameworks.
- Experience working with vendors and managed service providers for cybersecurity tools and platforms.
- Familiarity with DR/BCP planning, execution, and audit requirements.
- Basic scripting or automation knowledge (Python, Power Shell, or similar) is preferred.
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×