Security Operations Center Analyst
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Security or equivalent.
- Eligibility
- Applicants must be citizens of Saudi Arabia.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
NourNet is seeking a Cyber Defense Center Level 1 Security Operations Center (SOC) Analyst to be the frontline defender against cyber threats. This position involves continuously monitoring security systems, triaging alerts, conducting preliminary investigations, executing immediate response actions, and escalating issues as needed within the SOC framework.
Key Responsibilities
- Monitor security alerts generated by platforms including SIEM, XDR, EDR, Firewall, IDS/IPS, WAF, and Email Security systems.
- Conduct initial alert triage by validating events, identifying false positives, and assigning severity levels appropriately.
- Perform basic investigations and enhance Indicators of Compromise (IOC) with relevant threat intelligence.
- Execute authorized first-response measures such as isolating endpoints, terminating sessions, and temporarily blocking threats.
- Escalate validated or suspicious incidents to Level 2 teams or Incident Response as per established protocols.
- Maintain thorough documentation of investigation processes, findings, and actions within the ticketing system.
- Follow SOC operational procedures including runbooks, playbooks, and escalation flows.
- Prepare detailed shift handovers covering ongoing incidents, watchlist items, and operational updates.
- Engage in security drills, training sessions, and ongoing enhancement activities.
Candidate Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related discipline.
- Practical exposure to SIEM technologies such as XSIAM, Splunk, or QRadar.
- Basic experience managing incidents, handling phishing triage, and enriching IOCs.
- Familiarity with SOC operational procedures and working in a shift-based monitoring environment.
- Strong analytical mindset with problem-solving capabilities.
- Meticulous attention to detail and disciplined documentation skills.
- Capability to work effectively within a 24x7 shift schedule.
- Must be a citizen of Saudi Arabia.
Preferred Technical Platforms
- SIEM: XSIAM, Splunk, QRadar
- EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne
- Email Security: Proofpoint, Mimecast, Microsoft 365 Defender
- Ticketing: ServiceNow, JIRA, Remedy
Additional Information
This position offers a career growth opportunity for individuals passionate about cybersecurity, especially in the areas of threat detection and SOC operations within a Cyber Defense Center environment.
Minimum education
Bachelor's Degree