Cybersecurity Operations Engineer
Novelus · Jeddah, Makkah, Saudi Arabia
Apply & track with Apply EdgeWho We Are:Novelus Team is a group of innovative people, excessively focused on accelerating technology deployment. Our most important asset is our employees, which is why we focus on providing a progressive, vibrant and empowering culture.Why Novelus:This is a great opportunity to be part of a company with record growth. Novelus employees enjoy a comprehensive set of benefits, including but not limited to:Friendly and collaborative work environmentPersonal and professional growth opportunitiesExposure to dynamic projects and the latest technologiesWho We're Looking For:Operate the accepted security controls, identify and triage security events, coordinate response and remediation, and maintain evidence of compliance with Company-approved security requirements.
What You’ll Do
Review assigned EDR and security-monitoring alerts, validate suspicious activity, investigate affected users or devices, and escalate incidents under the agreed severity and response process.Administer approved endpoint policies and controls. Perform containment actions within delegated authority and obtain required approval for disruptive or irreversible changes.Review perimeter security configurations and proposed changes with the infrastructure team. Identify weak rules, access exposures and configuration gaps for authorised remediation.Run approved vulnerability assessments within agreed assets and windows. Validate findings, prioritise them by exposure and business impact, assign owners and verify remediation.Support privileged-access reviews, security baseline checks and compliance evidence. Maintain an exception register and report unresolved risks to the designated owner.Assist with security gap assessments, risk assessments, control implementation and policy updates within the agreed IT scope.Maintain audit evidence, support internal and external audits, and track corrective actions to closureWhat You’ll Need:3–5 years in security operations, including hands-on endpoint security, incident handling, vulnerability assessment and remediation coordination. Experience protecting enterprise users, servers and networks is preferred. Prioritise deployed EDR, SIEM and firewall vendor training, vulnerability analysis and incident-response exercises. Microsoft Certified Security Operations Analyst Associate, associated with SC-200 [4], is relevant when Microsoft security tools are used. Add security governance learning as responsibilities expand.Practical EDR, SIEM and firewall knowledge; Windows and Linux security fundamentals; incident investigation; vulnerability interpretation; and risk-based remediation. Working knowledge of ISO/IEC 27001, Information Security Management Systems (ISMS), and Governance, Risk and Compliance (GRC) practices, including risk assessments, security controls, compliance reviews, audit evidence preparation, policy and procedure management, control-gap identification, corrective-action tracking, and support for ISO 27001 certification and surveillance audits. Clear technical reporting, evidence handling, risk-register maintenance, and collaboration with infrastructure, application, compliance and audit teams are essential.