Tier 3 SOC Analyst (Incident Management)
Halian
Date: 9 hours ago
City: Riyadh
Contract type: Contractor
Job Title:Tier 3 SOC Analyst (Incident Management)
Location: Riyadh, Saudi Arabia
Employment Type:
Contract
Role – Tier 3 SOC Analyst (Incident Management)
Location - Qatar
Contract - 10 months, extendable
Job summary:
Candidates in this role will be responsible for conducting incident response operations according to documented procedures
and industry best practices. Candidates must have excellent communication skills and extensive experience in multiple
security areas such as SIEM, EDR, NDR, IDS, APT, and WAF. Candidates will be required to participate in multiple intelligence
communities and should be able to disseminate pertinent information throughout the SOC. Ideal candidates should have
extensive experience in Linux and/or Windows operating systems and have deep knowledge of networking and attack
techniques. Candidates must display enthusiasm and interest in Information Security.
Standard job requirements
Must have:
Nice to have:
Preferred:
Tier 3 SOC Analyst (Incident Management) in Riyadh, Saudi Arabia
Location: Riyadh, Saudi Arabia
Employment Type:
Contract
Role – Tier 3 SOC Analyst (Incident Management)
Location - Qatar
Contract - 10 months, extendable
Job summary:
Candidates in this role will be responsible for conducting incident response operations according to documented procedures
and industry best practices. Candidates must have excellent communication skills and extensive experience in multiple
security areas such as SIEM, EDR, NDR, IDS, APT, and WAF. Candidates will be required to participate in multiple intelligence
communities and should be able to disseminate pertinent information throughout the SOC. Ideal candidates should have
extensive experience in Linux and/or Windows operating systems and have deep knowledge of networking and attack
techniques. Candidates must display enthusiasm and interest in Information Security.
Standard job requirements
- Work as a part of the SOC team
- Operate as a first point of escalation for Tier 2.
- Hunt for suspicious anomalous activity based on data alerts or data outputs from various toolsets.
- Review and build new operational processes and procedures.
- Provide first-responder forensics analysis and investigation.
- Triage and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs).
- Work directly with data asset owners and business response plan owners during low and medium severity
- Provide advice on the tuning of Security controls like proxy policy, in-line malware tools based on threat feeds,
- Develop SOC use cases, provide tuning recommendations to administrators based on findings during investigations
- Perform Threat hunting based on threat intelligence received from CTI team.
- Lead response actions for incidents where CIRT is not required to intervene (low/medium priority).
- Perform administrative tasks per management request (ad hoc reports/ trainings).
Must have:
- Passion and drive to work with the potential of significant growth in scope and services
- Good logical and analytical skills to help in the analysis of security events/ incidents
- Experience of network security zones and firewall configurations
- In depth knowledge of TCP / IP
- Knowledge of systems communications from OSI Layer 1 to 7
- Experience with Systems Administration, Middleware, and Application administration
- Experience with Network and Network Security tools administration
- Experience with log search tools, usage of regular expressions, and natural language queries
- Knowledge of log formats and ability to aggregate and parse log data for syslog, http logs, and DB logs for
- Ability to make/create a containment strategy and execute
- Experience with Security Assessment tools (NMAP, Nessus, Metasploit, Netcat)
- Good knowledge of threat areas and common attack vectors (malware, phishing, APT, technology attack, etc.) and
Nice to have:
- Knowledge of common security frameworks (ISO 27001, COBIT, NIST)
- Knowledge on MITRE ATT&CK, TTPs
- Advanced network packet analysis/forensics skills
Preferred:
- Graduate degree or equivalent
- 5+ years of minimum experience in Information security
- 2+ years of prior experience in a similar position
- CEH certified
- SEC511: Continuous Monitoring and Security Operations training
- SANS SEC504: Hacker tools, Techniques, Exploits, and Incident Handling training
- SANS FOR500 series training
- Advanced Security Essentials – SEC501 (optional GCED certification)
- Perimeter Protection In-Depth – SEC502 (optional GCFW certification)
- CISSP, GIAC Reverse Engineering Malware (GREM), Offensive Security Certified Expert, GIAC Certified Forensic
Tier 3 SOC Analyst (Incident Management) in Riyadh, Saudi Arabia
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Digital Transformation Expert
MENA Consultant,
Riyadh
4 hours ago
Location: Riyadh, KSA.Years of Experience: 5-7+ years of relevant experience.Project Duration: 1 year.Language Requirements: Fluency in English and Arabic (written and spoken).We are seeking a skilled and innovative Digital Transformation Expert to lead and support digital transformation initiatives over a one-year engagement. The ideal candidate will bring extensive experience in aligning digital strategies with business objectives, implementing IT governance and...
MENA Alumni Leader - Riyadh (KSA Nationals only)
EY,
Riyadh
9 hours ago
The opportunityWith so many offerings, you have the opportunity to develop your career through a broad scope of engagements, mentoring and formal learning. That’s how we develop outstanding leaders who team to deliver on our promises to all of our stakeholders, and in so doing, play a critical role in building a better working world for our people, for our...
Security Solutions Engineer - MEA
Cisco,
Riyadh
9 hours ago
What You’ll DoThe Cybersecurity Solutions Engineer’s prime responsibility is to provide technical sales support and recommendations to internal and external customers on the Cisco Security Solutions Portfolio. The successful candidate will have wide-ranging knowledge and experience across the information security domain. Through a consultative approach, the Cybersecurity Solutions Engineer will be expected to articulate the benefits of the Cisco Security...