×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cyber Simulation Exercises Scenario Developer

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: FNRCO
Full Time position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 270000 - 360000 SAR Yearly SAR 270000.00 360000.00 YEAR
Job Description & How to Apply Below

The Cyber Simulation Exercises Scenario Developer designs, builds, and delivers large-scale cybersecurity simulation exercises (Threat Hunting Event, Live Fire Exercises, Capture the Flag) to uplift workforce cyber capability. This role develops realistic scenarios on a cyber range platform, creates exercise “injects” and artifacts, and builds/maintains the supporting lab infrastructure to enable repeatable, measurable training at scale.

Key Responsibilities:
  • Design end-to-end cyber simulation exercises aligned to organizational capability uplift goals (e.g., phishing response, ransomware, cloud misconfigurations, insider threat, incident response coordination).
  • Translate learning objectives into engaging storylines, technical objectives, and measurable outcomes.
  • Develop multi-track scenarios for different audiences (IT, SOC, incident commanders, and executives) with appropriate complexity and realism.
  • Ensure scenarios reflect current threat landscape and common enterprise environments (Windows/Linux, AD, email, web applications, cloud, endpoints).
2) Content Creation (Exercise Materials & Artifacts)
  • Produce complete exercise packages including: facilitator guides, participant instructions, runbooks, timelines, scoring rubrics, and debrief materials.
  • Create realistic artifacts: emails, chat transcripts, tickets, logs, alerts, threat intel snippets, media statements, executive briefings, and policy references.
  • Build assessment content (pre/post checks, knowledge validations, performance-based evaluation criteria).
  • Create and manage exercise injects (technical and non-technical) to drive decision-making and actions during the simulation.
  • Implement inject delivery mechanisms within the cyber range (automated triggers, timed releases, event-driven injects).
  • Coordinate inject timing, escalation paths, and branching logic based on participant actions.
4) Cyber Range Infrastructure Build & Maintenance
  • Build and configure lab environments required for scenarios (networks, endpoints, servers, identity services, security tooling).
  • Integrate common security tools and telemetry sources (SIEM, EDR, IDS, email security, vulnerability scanners) as required by the exercise.
5) Exercise Delivery Support & Facilitation Enablement
  • Support dry runs, pilot sessions, and production execution; troubleshoot technical issues during live exercises.
  • Provide facilitators with clear runbooks, decision points, and expected participant actions.
  • Capture exercise telemetry and participant performance data for reporting and continuous improvement.
6) Measurement, Reporting & Continuous Improvement
  • Define KPIs and scoring models (time-to-detect, time-to-contain, decision quality, process adherence, communication effectiveness).
  • Produce post-exercise reports and lessons learned; recommend improvements to content, controls, and processes.
Required Qualifications:
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent practical experience.
  • Proven experience developing cybersecurity simulation exercises on a cyber range platform (hands‑on).
  • Demonstrated ability to create injects and exercise artifacts that drive realistic participant behavior.
  • Experience building and operating lab infrastructure (virtualized or cloud‑based) for cyber scenarios.
  • Strong understanding of incident response lifecycle, common attack techniques, and defensive controls.
Required Technical

Skills:
  • Cyber range platforms: hands‑on experience with at least one commercial or open cyber range solution (platform‑agnostic, but must have real implementation experience).
  • Infrastructure: virtualization and networking fundamentals (segmentation, routing, DNS, AD basics).
  • Automation/scripting:
    Power Shell, Python, Bash (at least one strong).
  • Logging/monitoring concepts: SIEM/EDR telemetry, log sources, alerting logic.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary