Cyber Security Engineer
Ebryx LLC · Riyadh, Saudi Arabia
Apply & track with Apply EdgeCyberSecurity Engineers - SOCLocation: Riyadh, Saudi Arabia
The successful candidates will be responsible for monitoring security events, investigating alerts, identifying potential threats, and supporting incident response activities within a Security Operations Center.
Key Responsibilities
Monitor security alerts and events using SIEM and other security monitoring tools.Investigate and triage security incidents and suspicious activities.Analyze logs and security events to identify potential threats and indicators of compromise.Perform initial incident investigation and escalation according to defined procedures.Support incident response, containment, and remediation activities.Prepare and maintain incident reports and security documentation.Monitor threat intelligence feeds and identify emerging security threats.Assist in improving SOC processes, use cases, detection rules, and monitoring capabilities.Collaborate with other cybersecurity and IT teams to resolve security incidents.Follow established security policies, procedures, and incident response processes.
Requirements
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.Relevant hands-on experience in a SOC/Security Operations environment according to the position level.Strong understanding of SIEM, SOC operations, incident response, network security, and cybersecurity fundamentals.Experience with security monitoring, log analysis, alert triage, and incident investigation.Good understanding of TCP/IP, networking, Windows/Linux security, and common cyber threats.Strong analytical and problem-solving skills.Good written and verbal communication skills.Willingness to work in an onsite SOC environment and, where required, rotational shifts.Certifications – MandatoryCandidates must hold at least one relevant SOC/cybersecurity certification, such as:CompTIA Security+CompTIA CySA+EC-Council Certified SOC Analyst (CSA)Certified Cybersecurity Analyst (CySA+)GIAC Security Operations / Incident Response certificationsMicrosoft Security Operations Analyst (SC-200)Other recognized and relevant SOC/security certifications will also be considered.Preferred Skills:Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, or ArcSight.Knowledge of EDR/XDR, IDS/IPS, firewalls, and vulnerability management tools.Familiarity with MITRE ATT&CK and common attack techniques.Understanding of threat intelligence and IOC analysis.Experience with incident response and security investigation processes.