SIEM Security Operations Engineer (Saudi Nationals)
Socium - Teams Done Differently · Riyadh, Saudi Arabia
Apply & track with Apply EdgeWe are seeking experienced SIEM Security Operations Engineers to support enterprise cybersecurity monitoring, threat detection, incident analysis, and vulnerability management initiatives within a highly secure cloud environment.The successful candidates will play a key role in deploying and operating the organization's Security Information and Event Management (SIEM) platform, integrating security products, monitoring security events, investigating alerts, and coordinating vulnerability remediation activities across cloud services and enterprise infrastructure.This role is ideal for cybersecurity professionals with hands-on experience in SIEM operations, Security Operations Center (SOC) environments, log analysis, security monitoring, and vulnerability management who are passionate about strengthening enterprise cyber resilience.You will work closely with cybersecurity engineers, cloud teams, product development teams, and regulatory stakeholders to enhance security monitoring capabilities, improve threat detection, and ensure timely response to security incidents.Key ResponsibilitiesAssist in the deployment, configuration, and ongoing operation of the enterprise SIEM platform.Integrate security logs from enterprise security solutions including WAF, HIDS, DDoS protection systems, cloud platforms, and other security technologies.Configure and optimize SIEM correlation rules, alert logic, dashboards, and detection use cases.Monitor security events, investigate alerts, and perform initial triage of potential security incidents.Analyze logs to identify suspicious activities, indicators of compromise (IOCs), and emerging security threats.Escalate validated security incidents to the appropriate cybersecurity or engineering teams for remediation.Manage and track security vulnerability tickets for cloud services and enterprise platforms.Validate reported vulnerabilities, coordinate remediation with engineering teams, and perform post-remediation verification.Assist in improving detection capabilities by tuning alert rules and reducing false positives.Support security compliance initiatives and maintain operational documentation.Conduct technical demonstrations and explain cybersecurity solutions during regulatory reviews, audits, or customer engagements.Collaborate with cloud, infrastructure, application, and security teams to continuously improve enterprise security posture.Stay up to date with emerging cyber threats, attack techniques, and security best practices.Required QualificationsBachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Security, or a related field.Minimum 2 years of professional experience in SIEM Security Operations, SOC Operations, Cybersecurity Monitoring, or Information Security.Saudi National.Hands-on experience operating SIEM platforms in enterprise environments.Experience with security log collection, correlation, analysis, and alert investigation.Good understanding of cybersecurity threats, attack techniques, indicators of compromise (IOCs), and security monitoring.Experience in vulnerability management and remediation workflows.Familiarity with enterprise security technologies such as:Web Application Firewall (WAF)Host Intrusion Detection Systems (HIDS)DDoS ProtectionCloud Security PlatformsStrong analytical and troubleshooting skills.Good written and verbal communication skills in English.Preferred QualificationsExperience working within a Security Operations Center (SOC).Knowledge of cloud security concepts and cloud-native security services.Understanding of AI Security or Cloud Security technologies.Knowledge of Saudi Arabia cybersecurity regulations and compliance frameworks (e.g., NCA ECC, SAMA Cybersecurity Framework, PDPL).Experience presenting technical security concepts to auditors, regulators, or customers.Participation or recognition in cybersecurity competitions (e.g., CTFs, hacking competitions).Relevant cybersecurity certifications such as:CompTIA Security+CompTIA CySA+GIAC CertificationsCEHSplunk Core Certified User/Power UserMicrosoft SC-200Google Professional Cloud Security Engineer (advantage)ISC2 CC or CISSP (advantage)