Defense Engineer - System Operator (RE)
Innovative Solutions SA · Riyadh, Riyadh, Saudi Arabia
Apply & track with Apply EdgeCompany OverviewInnovative Solutions (IS) is a leading Cybersecurity company established in 2003, with its headquarters in Riyadh and additional offices in Al Khobar, Jeddah, Dubai, and Abu Dhabi. We specialize in delivering Comprehensive Cybersecurity Solutions and Services encompassing Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed Security Services.Our mission is "Delivering secure and intelligent digital services that empower organizations"Role SummaryThe Defense Engineer - System Operator (RE) is responsible for continuously monitoring cybersecurity threats and security incidents across the company's systems. The role focuses on detecting, analyzing, documenting, and responding to cybersecurity incidents while maintaining the security and integrity of the company's systems and information.Key ResponsibilitiesMonitor and manage cybersecurity systems and security controls, including EDR, AV, SIEM, WAF, Firewall, NAC, Proxy, and HXContinuously monitor security alerts and events, classify incidents based on severity and impact, and take appropriate actionAssess security incidents and follow established incident response procedures, including:Notifying relevant system ownersInitiating appropriate incident response actionsEscalating incidents according to defined proceduresDocumenting incident details, findings, and actions takenInvestigate cybersecurity incidents and cyberattacks and analyze relevant security events and indicatorsDocument, track, and report cybersecurity incidents in accordance with established proceduresHandle and follow up on users' Service Requests related to information securityCreate, develop, and update security use cases for existing and newly implemented security systems and applicationsAnalyze cybersecurity incidents and security events and report them through the Saudi Cybersecurity Authority channels, where applicableConduct regular security scans to identify vulnerabilities, security gaps, and potential threatsEnsure compliance with applicable cybersecurity standards, policies, and requirements approved by the Information Technology AdministrationCoordinate with relevant departments and system owners during cybersecurity investigations and incident response activitiesPrepare monthly reports summarizing major cybersecurity incidents, findings, trends, and actions takenMaintain and operate security systems and ensure they are updated to the latest approved versionsIdentify, classify, and prioritize security events and incidents collected through security controls, including firewalls, network and proxy devices, IDS/IPS systems, antivirus solutions, databases, and endpointsSupport the continuous improvement of security monitoring, incident detection, and response processesPerform other cybersecurity monitoring, investigation, and incident response duties as assignedQualifications & ExperienceMinimum Experience: 5+ years of relevant experience in cybersecurity, security operations, or a related fieldRequired Certifications: CISSP or CASP+ and CCNAStrong knowledge of cybersecurity monitoring, threat detection, incident investigation, and incident responseHands-on experience with security monitoring and protection technologies, including SIEM, EDR/AV, WAF, Firewalls, NAC, Proxy, HX, IDS/IPS, databases, and endpoint security solutionsAbility to analyze security alerts and events, assess risks, prioritize incidents, and follow established incident response proceduresKnowledge of vulnerability assessment, security scanning, and cybersecurity controlsStrong analytical, problem-solving, documentation, reporting, communication, and coordination skillsRequirementsCore CompetenciesCybersecurity MonitoringSecurity OperationsSecurity Incident ResponseThreat Detection and AnalysisSecurity Information and Event Management (SIEM)Vulnerability Assessment and Security ScanningCybersecurity InvestigationIncident Documentation and ReportingRisk Assessment and Incident ClassificationSecurity Controls ManagementCross-functional Communication