Cyber Defense Specialist - Detection & Monitoring

CCDS

Sign In to Apply

Pay not listed

  • Full-time
  • Riyadh, Riyadh Province, Saudi Arabia
  • 1mo ago

Job Description

Location: On-site – Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month RFP term)

Minimum experience: 7+ years

Role Purpose

Strengthen SOC detection and monitoring capabilities across SIEM, SOAR, EDR, DLP, email security, and other security platforms.

Key Responsibilities

·      Develop and enhance security detection capabilities across SIEM, SOAR, EDR, DLP, and email security platforms.

·      Design correlation logic, detection rules, threat-detection use cases, alerts, and supporting response workflows.

·      Integrate telemetry and logs from security systems to improve monitoring coverage.

·      Continuously tune detections to improve accuracy and reduce false positives.

·      Analyze security events and suspicious activity and escalate validated threats through approved processes.

·      Maintain SOC policies, procedures, workflows, and operational playbooks.

·      Map detection coverage to MITRE ATT&CK and coordinate improvements with cybersecurity, governance, and technical teams.

·      Support security assessments, regulatory compliance, reporting, and security-vendor coordination.

Requirements

Technical and Professional Requirements

·      Bachelor’s degree in Computer Science, Information Security, or a related field.

·      At least 7 years of experience in SOC operations or cyber defense.

·      Hands-on experience with SIEM, SOAR, EDR, DLP, email security gateways, and log/telemetry integration.

·      Proven experience developing detection use cases and tuning security rules.

·      Knowledge of cyberattack techniques, threat detection, MITRE ATT&CK, NCA requirements, and SOC operating models.

Personal Requirements

·      Strong analytical and problem-solving skills.

·      Clear communication, documentation, and cross-team coordination.

·      Persistent, quality-focused, and comfortable working with vendors and technical partners.

·      Able to prioritize alerts and improvements in a high-volume operational environment.

Professional Certifications

Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.