Security Operations and Monitoring Engineer

CCDSDammamgulftalentopublikowano 28.08.2026
Wymagane:Security

Location

Dammam, Saudi Arabia

Employment type

Full-time | Onsite

Project duration

Long-term project assignment

About the role

We are seeking a Security Operations & Monitoring Engineer to provide continuous monitoring and security-event analysis across encryption, KMS, HSM, database security, and related infrastructure.

The successful candidate will work closely with the SOC/SIEM and technical teams to identify suspicious activities, triage security events, support incident response, and ensure timely escalation and reporting.

Key responsibilities

Perform continuous monitoring of cybersecurity systems and infrastructure.

Monitor encryption, KMS, HSM, database security, and other security-related events.

Review and analyze system, security, audit, and application logs.

Monitor security alerts through SIEM/SOC platforms.

Perform first-level investigation and triage of cybersecurity events.

Correlate alerts from multiple security technologies to identify potential incidents.

Escalate critical or suspicious activities according to established procedures.

Support incident-response investigations and evidence collection.

Coordinate with engineering teams during security incidents and service-impacting events.

Support the tuning of monitoring rules and alert thresholds.

Prepare operational, security, and incident reports.

Maintain incident records, monitoring procedures, and operational documentation.

Participate in shift, maintenance, and on-call activities when required.

Requirements

Required qualifications & experience

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.

4+ years of experience in SOC, SIEM, security monitoring, incident triage, or cybersecurity operations.

Hands-on experience with SIEM and security monitoring platforms.

Good understanding of security events, logs, alerts, incident handling, and escalation procedures.

Experience integrating security solutions with central SOC/SIEM platforms.

Strong analytical and troubleshooting skills.

Must be available full-time onsite in Dammam.

Required certification

CompTIA Security+.

Preferred certifications

CompTIA CySA+.

Splunk Core Certified Power User.

Splunk Certified Cybersecurity Defense Analyst.

Equivalent recognized SIEM/SOC certification.

Core competencies

SOC | SIEM | Security monitoring | Incident triage | Log analysis | Incident response | Alert management | Threat detection | Reporting

Candidates should include the SIEM/SOC platforms they have used, the type of monitoring environments they supported, and their relevant certifications.