L3 Security Monitoring Manager
Talent Blueprint FZ LLC · Riyadh, Saudi Arabia
Apply & track with Apply EdgePosition: L3 Security Monitoring Manager Location: Riyadh / Jeddah, Saudi ArabiaContract Duration: 1 Dec 2026 - 28th Feb 2027 ( 3 months contract)About the RoleWe are seeking an experienced L3 Security Monitoring Manager to lead the SOC's Tier 3 security monitoring and incident response function for a major football event project in Saudi Arabia.The role will be responsible for advanced security investigations, incident response coordination, SOC operational quality, and ensuring effective detection and response across a 24/7 security monitoring environment.The successful candidate will lead L2 analyst teams, manage escalated security incidents, improve SOC detection and response capabilities, and coordinate security response activities during live event operations.Key ResponsibilitiesLead the SOC's Tier 3 / L3 security monitoring function, ensuring effective detection, investigation, and response to cybersecurity incidents.Manage L2 security analyst teams across 24/7 shift rotations, including staffing, scheduling, workload management, and quality assurance.Perform advanced Tier 3 investigations into escalated security incidents.Own incident classification, severity determination, escalation, and response coordination.Lead incident response activities through containment and eradication for confirmed cybersecurity incidents.Escalate major and critical incidents to the appropriate senior stakeholders.Own and continuously improve SOC playbooks, procedures, SIEM use cases, and SOAR workflows.Review and refine SIEM/SOAR detection content to improve detection accuracy and reduce false positives.Conduct root-cause analysis and post-incident / after-action reviews, ensuring lessons learned are incorporated into detection and response improvements.Own the quality of shift handovers, ensuring continuity of monitoring and that no critical security events or investigations are missed.Track, analyze, and report SOC operational metrics, including:Alert volumesFalse-positive ratesMean Time to Detect (MTTD)Mean Time to Respond (MTTR)Escalation accuracyIncident volumes and severityMentor and develop L2 analysts and support the team's training, skills development, and certification pathway.Act as Incident Commander for security events during live event operations.Coordinate security incidents with IT, cybersecurity, venue/facilities security, and relevant external stakeholders, including law enforcement liaisons where required.Ensure SOC operations and incident response processes remain effective throughout live event periods.Identify operational gaps and implement improvements to SOC processes, procedures, tooling, and analyst capabilities.Requirements3+ years of relevant cybersecurity/SOC experience, with strong experience in Tier 2/Tier 3 security operations.Proven experience leading or supervising SOC/security monitoring teams.Strong hands-on experience in advanced security incident investigation and incident response.Experience managing 24/7 SOC operations and shift-based teams.Strong knowledge of SIEM and SOAR technologies, security monitoring, alert triage, and detection engineering.Experience developing and maintaining SOC playbooks and incident response procedures.Strong understanding of incident classification, severity assessment, escalation, containment, and eradication.Experience with root-cause analysis and post-incident reviews.Ability to analyze SOC operational metrics and drive continuous improvement.Strong leadership, mentoring, communication, and stakeholder management skills.Experience coordinating cybersecurity incidents across multiple technical and operational teams.Experience working in a high-volume, high-availability, or mission-critical environment would be an advantage.Experience supporting cybersecurity operations during major events would be an advantage.Preferred CertificationsRelevant cybersecurity and SOC certifications would be an advantage, including:CISSPGIAC / GCIH / GCIA / GCFASecurity+CEHCertified SOC Analyst (CSA)Other recognized incident response, SOC, or cybersecurity certificationsThe role combines hands-on Tier 3 technical investigation with SOC operational leadership, making it particularly suited to candidates who have progressed from L2/Senior SOC Analyst responsibilities into SOC leadership or management