SIEM Administrator
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Company Overview
Innovative Solutions (IS) is a prominent cybersecurity firm founded in 2003, headquartered in Riyadh with branches in Al Khobar, Jeddah, Dubai, and Abu Dhabi. The company delivers extensive cybersecurity services including advisory, technical assurance, solution deployment, professional and managed security services. Our mission is to provide secure and intelligent digital services that enhance organizational capabilities.
About the Role
We are looking for a proficient SIEM Administrator responsible for designing, deploying, and maintaining our Security Information and Event Management (SIEM) platform. This position is integral to our log management and threat detection systems, requiring collaboration with various departments to onboard log sources, develop custom detection rules, and ensure the seamless operation of security tools to safeguard enterprise resources.
Key Responsibilities
- Architect, implement, patch, and upgrade the SIEM infrastructure and related agents.
- Work with business units to understand network hierarchies, define foundational elements, and classify logging sources.
- Create custom API connectors and parsers for log sources that lack vendor support.
- Design comprehensive threat detection use cases, craft custom SIEM detection rules, and apply MITRE ATT&CK frameworks.
- Resolve daily issues involving log sources, collectors, agents, and security operations center (SOC) tools.
- Oversee data governance including archiving, backup, retention, and purging aligned with compliance policies, with capabilities to restore data when necessary.
- Manage change tickets and audits related to administrative tasks such as patching and log onboarding; prepare platform assessment documentation.
- Use foundational Windows and Unix administration skills to maintain infrastructure health.
Qualifications and Skills
- Bachelor's degree in a related discipline or equivalent professional experience.
- Solid knowledge of cybersecurity fundamentals and IT concepts such as networking, operating systems, authentication protocols, enterprise architecture, and incident response.
- Experience with enterprise technologies and logging tools including firewalls, Active Directory, endpoint detection and response (EDR), antivirus, intrusion detection/prevention systems (IDS/IPS), proxies, and cloud environments; knowledge of Security Orchestration, Automation, and Response (SOAR) is advantageous.
- Competency with SIEM platforms like Splunk, IBM QRadar, LogRhythm, Microsoft Sentinel, or Palo Alto XSIAM.
- Comprehensive understanding of security best practices including risk management, CIA triad, cryptography, identity and access management (IAM), access controls, and network security strategies.
- Experience in system administration with a focus on hardening networks, operating systems, and infrastructure components.
Minimum education
Bachelor's Degree
Industry
Cybersecurity