Join our dynamic cybersecurity team in Riyadh as a SIEM Engineer, where you will play a critical role in safeguarding our organization's digital assets. This permanent position offers a challenging and rewarding opportunity to leverage your expertise in threat detection and incident response, contributing to our robust security posture. You will be instrumental in enhancing our security monitoring capabilities and proactively identifying and mitigating potential cyber threats.
Key Responsibilities
- Deploy, configure, and maintain Security Information and Event Management (SIEM) platforms to ensure optimal performance and reliability.
- Develop and implement comprehensive log collection strategies, ensuring all relevant security events are captured and analyzed.
- Create and tune correlation rules, alerts, and dashboards to identify sophisticated threats and anomalies within the security environment.
- Conduct in-depth log analysis and threat hunting to proactively detect potential security incidents and vulnerabilities.
- Lead and participate in incident response activities, including investigation, containment, eradication, and recovery.
- Provide subject matter expertise on network security, endpoint security, and cloud security within the SIEM context.
- Collaborate with cross-functional teams to integrate new data sources and enhance the overall security monitoring framework.
Required Qualifications
Experience & Education
- Bachelor of Science or Bachelor of Computer Science (BCS) degree.
- A minimum of 3 years of progressive experience in SIEM engineering and cybersecurity operations.
Skills
- Proficiency in managing and operating SIEM platforms such as Splunk, QRadar, or ELK Stack.
- Strong understanding of log analysis, threat detection, and incident response methodologies.
- Demonstrated expertise in security monitoring, network security, and endpoint security.
- Solid knowledge of cloud security principles and their application within a SIEM environment.
- Proven ability to create effective correlation rules and data analysis techniques.
- Excellent problem-solving and analytical skills.
- Strong understanding of cybersecurity principles and best practices.
Preferred Qualifications
- CISSP, GIAC Certified Intrusion Analyst (GCIA), or relevant SIEM vendor certifications.
- Familiarity with various cybersecurity frameworks and compliance standards.
- Experience with scripting or programming languages for automation.
Languages
- English language proficiency is preferred.
What We Offer
We offer a comprehensive benefits package designed to support your well-being and professional growth. You will work in a collaborative and innovative environment in Riyadh, contributing to critical cybersecurity initiatives.