img
نوع العقددوام كامل
طبيعة الوظيفةعن بُعد
الموقعالرياض

وصف الوظيفة

About the Role

TawanTech is seeking a Senior Specialist - Cybersecurity Production Support to join our team in Riyadh, Riyadh Province. This is a full-time position focused on maintaining robust cybersecurity operations within enterprise environments.

Role Purpose

The Senior Specialist will be responsible for providing critical support and maintenance for various cybersecurity platforms. The primary objective is to ensure high availability, operational stability, and effective security monitoring across the organization's systems.

Key Responsibilities

  • Provide production support for cybersecurity platforms, including SIEM, SOAR, VPN, and security monitoring solutions.
  • Monitor cybersecurity platforms, dashboards, alerts, and operational activities to identify and address issues proactively.
  • Support Splunk SIEM use cases, log ingestion, correlation rules, and performance optimization efforts.
  • Manage and maintain SOAR workflows, playbooks, and automation processes to enhance incident response capabilities.
  • Support VPN infrastructure, ensuring secure remote access and reliable site-to-site connectivity.
  • Perform Incident, Problem, and Change Management activities in adherence to ITIL practices.
  • Conduct Root Cause Analysis (RCA) for security incidents and platform-related issues.
  • Support Cyber Incident Response activities, including investigation and remediation efforts.
  • Participate in Disaster Recovery (DR) and Business Continuity Planning (BCP) initiatives.
  • Maintain comprehensive security documentation, runbooks, Standard Operating Procedures (SOPs), and operational reports.
  • Collaborate with security teams, infrastructure teams, and external vendors for effective issue resolution.

Qualifications and Experience

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a closely related field.
  • 4–8 years of experience in cybersecurity production support, preferably within enterprise or financial environments.

Required Technical Skills and Knowledge

  • Hands-on experience with SIEM platforms (Splunk Enterprise / Splunk ES preferred).
  • Hands-on experience with SOAR platforms (Cortex XSOAR, Splunk SOAR, or similar).
  • Hands-on experience with VPN technologies (IPSec / SSL VPN).
  • Demonstrated experience in security monitoring and incident response.
  • Strong understanding of cybersecurity operations, threat detection methodologies, and log analysis.
  • Experience with ITIL Incident, Problem, and Change Management processes.
  • Knowledge of SAMA Cybersecurity Framework, NCA ECC, PDPL, and NDMO is preferred.
  • Basic scripting knowledge (Python, PowerShell, or similar) is preferred.

Application Process

Candidates who meet the above qualifications are encouraged to apply.


متطلبات الوظيفة

  • تتطلب ٢-٥ سنوات خبرة

وظائف مشابهة