Cyber Defense Specialist - Detection & Monitoring
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-09-17
Listing for:
CCDS
Full Time
position Listed on 2026-09-17
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Job Description & How to Apply Below
Location:
On-site – Riyadh, Saudi Arabia
Contract/engagement:
Project-based managed cybersecurity services (13-month RFP term)
Minimum experience:
7+ years
Strengthen SOC detection and monitoring capabilities across SIEM, SOAR, EDR, DLP, email security, and other security platforms.
Key Responsibilities- Develop and enhance security detection capabilities across SIEM, SOAR, EDR, DLP, and email security platforms.
- Design correlation logic, detection rules, threat-detection use cases, alerts, and supporting response workflows.
- Integrate telemetry and logs from security systems to improve monitoring coverage.
- Continuously tune detections to improve accuracy and reduce false positives.
- Analyze security events and suspicious activity and escalation validated threats through approved processes.
- Maintain SOC policies, procedures, workflows, and operational playbooks.
- Map detection coverage to MITRE ATT&CK and coordinate improvements with cybersecurity, governance, and technical teams.
- Support security assessments, regulatory compliance, reporting, and security-vendor coordination.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- At least 7 years of experience in SOC operations or cyber defense.
- Hands-on experience with SIEM, SOAR, EDR, DLP, email security gateways, and log/telemetry integration.
- Proven experience developing detection use cases and tuning security rules.
- Knowledge of cyberattack techniques, threat detection, MITRE ATT&CK, NCA requirements, and SOC operating models.
- Strong analytical and problem-solving skills.
- Clear communication, documentation, and cross-team coordination.
- Persistent, quality-focused, and comfortable working with vendors and technical partners.
- Able to prioritize alerts and improvements in a high-volume operational environment.
Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×