Apply Edge Start your job search

Cybersecurity Defense Manager

Talent Blueprint FZ LLC · Riyadh, Saudi Arabia

Apply & track with Apply Edge

Location: Riyadh, Saudi ArabiaContract Duration: 15 Oct 2026 - 28th Feb 2027 ( 4 months contract)Position: Cybersecurity Defense ManagerAbout the RoleWe are seeking an experienced Cybersecurity Defense Manager to lead the organization's cybersecurity defense function for a major football event project in Saudi Arabia.The role will have end-to-end responsibility for the 24/7 Security Operations Center (SOC), incident response, threat intelligence, vulnerability management, and cybersecurity defense operations.The successful candidate will ensure that the organization's security monitoring and response capabilities are continuously matured and are fully prepared to support the heightened security requirements of a major international football event in KSA.Key ResponsibilitiesOwn and lead the organization's overall cybersecurity defense function, including SOC operations, incident response, threat intelligence, and vulnerability management.Own and continuously mature the 24/7 SOC operating model, including staffing, shift coverage, escalation procedures, processes, and security tooling.Lead the enterprise incident response program, including incident response playbooks, tabletop exercises, escalation procedures, and live incident command.Act as incident commander for confirmed major cybersecurity incidents and coordinate response activities across relevant technical and operational teams.Own the vulnerability management and penetration testing lifecycle, including vulnerability identification, risk prioritization, remediation SLAs, and remediation validation.Oversee cybersecurity defense controls across:Network securityEndpoint securityCryptographyIdentity and access management monitoringIntegrate threat intelligence into SOC detection capabilities and security monitoring use cases, with particular focus on threats relevant to major national and international events.Own the SIEM/SOAR architecture from a defense operations perspective.Define and manage the log source onboarding strategy, ensuring critical systems and applications provide appropriate security telemetry.Establish and maintain appropriate security event logging and retention requirements.Monitor and report cybersecurity defense KPIs to senior leadership, including:Mean Time to Detect (MTTD)Mean Time to Respond (MTTR)Detection coverageVulnerability remediationIncident volumes and severityPartner closely with the Cybersecurity Architecture Manager to ensure new systems and solutions are designed with appropriate security monitoring and detectability capabilities before go-live.Lead heightened cybersecurity operations during the live event window, including surge staffing, enhanced monitoring, escalation readiness, and security war-room operations.Identify opportunities to improve security detection, response, resilience, and operational maturity.Coordinate with internal IT, cybersecurity, venue operations, facilities/security teams, vendors, and other stakeholders during major security events.Requirements3+ years of relevant cybersecurity experience, with significant experience in cybersecurity defense and security operations.Proven experience managing or leading SOC / Security Operations functions.Strong hands-on and leadership experience in incident response and incident management.Experience designing or operating 24/7 SOC environments.Strong understanding of SIEM and SOAR technologies, security monitoring, detection engineering, and log management.Experience with threat intelligence and integrating intelligence into security detection and response.Strong knowledge of vulnerability management and penetration testing, including remediation tracking and validation.Experience across network security, endpoint security, identity security, and cryptographic controls.Experience developing and executing incident response playbooks and tabletop exercises.Strong understanding of security metrics and operational KPIs, including MTTD, MTTR, and detection coverage.Strong leadership, stakeholder management, communication, and incident coordination skills.Experience working in large-scale, high-availability, or mission-critical environments would be an advantage.Experience supporting cybersecurity operations during major events would be an advantage.Preferred CertificationsRelevant cybersecurity certifications would be an advantage, including:CISSPCISMGIAC / GCIH / GCIA / GCFACEHSecurity+Certified SOC Analyst (CSA)Other recognized cybersecurity, incident response, or security operations certifications