- Experience
- 2–4 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Purpose
Teslm is setting up a centralized SIEM/SOC capability and requires a proactive engineer to handle it end-to-end. This role involves deciding the entire pipeline structure, integrating log sources, crafting detections, and leading daily alert triage, working closely with the CEO and CISO.
Position Overview
By the 12-month mark, the successful candidate will ensure all necessary log sources from AWS and applications are onboarded and normalized into a unified schema, with monthly health reports. Priority detections will be live, finely tuned, and trusted for alerts. The triage workflow will be fully documented to guide L1 Analysts, with log retention and immutable archives in place. The candidate will provide required audit evidence for PCI DSS v4, PDPL, NCA ECC-2:2024, and ISO/IEC 27001 standards. Additionally, they will mentor an L1 SOC Analyst on technical matters.
There is flexibility on vendor or tool choice, focusing on SIEM expertise rather than any particular product. This may involve building Wazuh from scratch, managing CrowdStrike, or working with other providers.
Key Responsibilities
- Integrate and onboard multiple log sources such as CloudTrail, GuardDuty, Security Hub findings, infrastructure and application security events into a normalized format.
- Develop, version, and optimize a focused set of detection rules aligned with top organizational risks; regularly review and reduce false positives.
- Monitor health for all log sources, proactively identifying gaps before they impact audits or security.
- Lead daily triage and containment processes, thoroughly investigating alerts by host, user, and IP; ensure proper documentation and pair reviews before actions affecting production.
- Manage log retention policies and immutable archives to meet compliance obligations; prepare quarterly audit evidence packages.
- Create and maintain runbooks, saved queries, and escalation procedures for L1 SOC Analysts; direct daily task prioritization.
Required Qualifications and Skills
- 2 to 4 years of hands-on SIEM/SOC experience with demonstrated involvement in log onboarding, detection rule creation/tuning, and alert triage.
- Experience building or maintaining SIEM solutions (e.g., Wazuh, Elastic, Splunk, CrowdStrike) with an ability to justify architectural decisions.
- Proficient in AWS security logging platforms including CloudTrail, GuardDuty, and Security Hub, and their integration into SIEMs.
- Competent in log parsing, normalization, relevant query languages, and Linux administration for deployed components.
- Skilled at writing clear, structured runbooks and incident reports.
- Hands-on practitioner role requiring direct operation of tools; not a managerial or architectural position.
Preferred Credentials
- Certifications such as CompTIA Security+, CySA+, AWS Certified Security Specialty.
- Vendor training on Wazuh, Elastic, or Splunk.
- GIAC certifications (GCIA, GCIH, or GMON).
- Experience with file integrity monitoring, vulnerability detection, or PCI DSS dashboards within SIEMs.
Additional Information
- Location: Onsite in Makkah, Saudi Arabia.
- Employment Type: Full-time permanent role.
- Immediate or earliest possible joining preferred.
- Reporting line: CEO & CISO.
- Scope: Teslm’s AWS environment and applications.
- International applicants are encouraged.