Cyber Defense Specialist
Location
On-site – Riyadh, Saudi Arabia
Contract/Engagement
Project-based managed cybersecurity services (13-month RFP term)
Minimum Experience
7+ years
Role purpose
Strengthen SOC detection and monitoring capabilities across SIEM, SOAR, EDR, DLP, email security, and other security platforms.
Key responsibilities
Develop and enhance security detection capabilities across SIEM, SOAR, EDR, DLP, and email security platforms.
Design correlation logic, detection rules, threat-detection use cases, alerts, and supporting response workflows.
Integrate telemetry and logs from security systems to improve monitoring coverage.
Continuously tune detections to improve accuracy and reduce false positives.
Analyze security events and suspicious activity and escalate validated threats through approved processes.
Maintain SOC policies, procedures, workflows, and operational playbooks.
Map detection coverage to MITRE ATT&CK and coordinate improvements with cybersecurity, governance, and technical teams.
Support security assessments, regulatory compliance, reporting, and security-vendor coordination.
Requirements
Technical and professional requirements
Bachelor’s degree in Computer Science, Information Security, or a related field.
At least 7 years of experience in SOC operations or cyber defense.
Hands-on experience with SIEM, SOAR, EDR, DLP, email security gateways, and log/telemetry integration.
Proven experience developing detection use cases and tuning security rules.
Knowledge of cyberattack techniques, threat detection, MITRE ATT&CK, NCA requirements, and SOC operating models.
Personal requirements
Strong analytical and problem-solving skills.
Clear communication, documentation, and cross-team coordination.
Persistent, quality-focused, and comfortable working with vendors and technical partners.
Able to prioritize alerts and improvements in a high-volume operational environment.
Professional certifications
Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.