Cyber Security Engineer - SOC
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 1–5 yrs
- Salary
- —
- Openings
- 4
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology or related discipline
- Eligibility
- The recruitment is specifically open to Saudi nationals only.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
Ebryx LLC is seeking experienced Security Operations Center (SOC) Analysts to join their cybersecurity team in Riyadh, Saudi Arabia. This full-time onsite role is exclusively open to Saudi nationals. Candidates will play a vital role in monitoring, detecting, and responding to security incidents within the SOC environment.
Key Duties
- Monitor security events and alerts utilizing SIEM and other monitoring solutions.
- Conduct investigation and triage of security incidents and suspicious activities.
- Analyze logs and events to detect potential security threats and compromise indicators.
- Perform initial investigations on incidents and escalate issues following defined protocols.
- Support containment, remediation, and incident response measures.
- Document security incidents and prepare detailed reports.
- Track threat intelligence feeds to stay informed about emerging security risks.
- Contribute to enhancement of SOC processes, detection rules, and monitoring capabilities.
- Collaborate closely with cybersecurity and IT teams to resolve issues.
- Adhere to established security policies and incident response workflows.
Candidate Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, IT, or related discipline required.
- Relevant SOC or Security Operations experience as per position level (ranging from 1 to 5+ years).
- Strong foundation in SIEM technology, SOC operations, incident response, network security, and cybersecurity principles.
- Experience in security monitoring, log analysis, alert triage, and incident investigation.
- Good knowledge of networking (TCP/IP), Windows/Linux security, and cyber threat landscape.
- Excellent analytical thinking and problem-solving capabilities.
- Effective communication skills, both written and verbal.
- Availability to work onsite and undertake rotational shift duties as necessary.
Mandatory Certifications
Candidates must hold at least one recognized SOC/cybersecurity certification such as CompTIA Security+, CompTIA CySA+, EC-Council Certified SOC Analyst (CSA), Certified Cybersecurity Analyst (CySA+), GIAC Security Operations/Incident Response certifications, Microsoft Security Operations Analyst (SC-200), or equivalent certifications.
Preferred Expertise
- Practical experience with SIEM platforms like Microsoft Sentinel, Splunk, IBM QRadar, or ArcSight.
- Familiarity with endpoint detection and response (EDR/XDR), intrusion detection/prevention systems (IDS/IPS), firewalls, and vulnerability management tools.
- Understanding of MITRE ATT&CK framework and typical attack methodologies.
- Experience in threat intelligence analysis and Indicators of Compromise (IOC) assessment.
- Hands-on involvement in incident response and security investigations.
Minimum education
Bachelor's Degree
Industry
Cybersecurity