SIEM/SOC Engineer
Teslm · Mecca, Makkah, Saudi Arabia
Apply & track with Apply Edge***Why this role exists***Teslm is establishing its central SIEM/SOC capability and needs one hands-on engineer to own it end to end. You will decide how the pipeline is assembled, bring the log sources in, write the detections and run the daily triage — working directly with the CEO & CISO. If you have built or run a SIEM with your own hands and want the whole thing to be your responsibility, this is that role.***About the role***12 months in, success looks like this: every relevant log source from our AWS environment and our applications is onboarded, normalised into a common schema and reported healthy every month; a focused set of priority detections is live and tuned so that the alert queue can be trusted; the triage workflow (alert → investigate → contain → document → close or escalate) is documented in runbooks that an L1 Analyst can follow; log retention and an immutable archive are in place; and the evidence an auditor asks for under PCI DSS v4 Requirement 10, PDPL, NCA ECC-2:2024 and ISO/IEC 27001 A.8.15 and A.8.16 can be produced on request. You will also give day-to-day technical direction to an L1 SOC Analyst.We are deliberately not fixed on a vendor. You may build Wazuh from scratch, monitor and maintain CrowdStrike, or work with a Wazuh service provider — we are hiring for general SIEM competence, not for a product.***What you'll do***• Own log-source onboarding: CloudTrail, GuardDuty and Security Hub findings, infrastructure logs and application security events, each parsed into a common schema.• Own the detection set: write, version and tune a small number of high-value rules mapped to our top risks, and review false positives every week.• Own the health of every log source — spot silent gaps before an auditor or an attacker does.• Own daily triage and containment: investigate related events by host, user and IP, contain with a second pair of eyes before any destructive production action, and document every case.• Own retention and evidence: an immutable log archive, retention aligned to our compliance obligations, and quarterly evidence packs.• Own the runbooks, saved queries and escalation path the L1 SOC Analyst works from, and set that analyst's daily priorities.***Required***• 2–4 years of hands-on SIEM/SOC work in which you personally onboarded log sources, wrote or tuned detection rules, and triaged the resulting alerts.• You have built or maintained a SIEM yourself — Wazuh, Elastic, Splunk, CrowdStrike or similar — and can explain the design choices you made.• Working knowledge of AWS security logging: CloudTrail, GuardDuty and Security Hub, and how their events end up in a SIEM.• Comfortable with log parsing and normalisation, query languages, and Linux administration for the components you run.• Able to write clear runbooks and incident documentation.• This is a hands-on practitioner role, not an architect or leadership position — you will build and run the tooling yourself, working directly with the CEO & CISO. If you are looking for a team to manage, this is not the right fit.***Nice to have***• CompTIA Security+ or CySA+• AWS Certified Security – Specialty• Wazuh, Elastic or Splunk vendor training• GIAC certifications (GCIA, GCIH or GMON)• Experience with file-integrity monitoring, vulnerability detection or PCI DSS dashboards inside a SIEM***Details***• Location: Makkah, Saudi Arabia — on-site• Employment: full-time, permanent, start as soon as possible• Reports to: the CEO & CISO• Scope: Teslm's AWS environment and applications• International candidates are welcome to apply.***How to apply***Apply via LinkedIn.