Security Operations Specialist
Tamkeen Technologies · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJob SummaryWe are looking for an experienced SOC L3 Analyst to join our Security Operations team. The ideal candidate will have strong experience in Security Operations, Incident Response, Threat Hunting, and advanced security investigations.The role will be responsible for handling complex and high-severity security incidents, conducting advanced investigations, performing digital forensics, developing detection capabilities, and providing technical guidance to SOC L1/L2 analysts.Key Responsibilities:Lead the investigation and response to high-severity and complex cybersecurity incidents.Perform advanced "Incident Response" investigations across endpoints, servers, networks, cloud environments, and identity infrastructure.Conduct detailed analysis of malware, ransomware, persistence mechanisms, lateral movement, privilege escalation, and data exfiltration.Perform threat hunting across SIEM, EDR, NDR, network, and other security telemetry.Analyze and correlate security events from multiple sources to determine the attack timeline, root cause, scope, and impact.Conduct malware and suspicious-file analysis using appropriate forensic and security tools.Develop and maintain advanced SIEM detection rules, correlation searches, and security use cases.Improve existing detection capabilities based on incident findings and emerging threats.Conduct proactive threat hunting based on IOCs, TTPs, threat intelligence, and MITRE ATT&CK techniques.Provide technical escalation support to SOC L1 and L2 analysts.Develop detailed incident investigation reports, root cause analysis, and remediation recommendations.Participate in major incident response activities and coordinate with relevant IT, infrastructure, network, and security teams.Support incident containment, eradication, and recovery activities.Conduct post-incident reviews and identify opportunities to improve security controls and detection capabilities.Maintain and improve IR procedures, playbooks, and investigation methodologies.Support security monitoring improvements across SIEM, EDR, NDR, SOAR, firewall, WAF, and other security technologies.Provide technical recommendations to improve overall security monitoring and incident response maturity.Qualifications:Bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related field.5+ years of experience in SOC, Incident Response, or a related cybersecurity role.Strong hands-on experience in SOC L3 operations and incident investigation.Strong understanding of Windows and Linux operating systems and their forensic artifacts.Experience investigating malware, ransomware, phishing, credential compromise, lateral movement, persistence, and privilege escalation.Strong experience with SIEM/EDR platforms.Experience with forensic and investigation tools such as Volatility, KAPE, FTK, Velociraptor, or similar tools.Experience with managed security services and external customer management is highly desirable.Relevant certifications such as GIAC GCIH, GCFA, or equivalent are preferred.