About the Role
EY is seeking a Senior Manager/Manager to lead the Cyber Defence function for a critical client in the Eastern Region of Saudi Arabia. This role, within the Consulting - Cybersecurity service line, involves overseeing 24/7 Security Operations Centre (SOC) activities and ensuring the implementation and maintenance of advanced cyber defence capabilities. A key focus will be on compliance with KSA regulatory frameworks, including NCA and CST, while meeting all contractual commitments. This position offers the opportunity to contribute significantly to safeguarding critical infrastructure and national cybersecurity initiatives.
Key Responsibilities
- Lead and manage 24/7 Security Operations Centre (SOC) operations, ensuring continuous monitoring and effective incident response through an "eyes-on-glass" model.
- Oversee, optimize, and ensure the effective utilization of cyber defence technologies, including SIEM, SOAR, TIP, EDR, and Vulnerability Management platforms.
- Drive all aspects of incident detection, triage, response, and recovery activities to minimize cyber threats and their impact.
- Ensure strict adherence to and compliance with all relevant KSA cybersecurity regulations, specifically the NCA and CST frameworks.
- Establish, document, and maintain robust SOC processes, playbooks, and automation strategies to enhance operational efficiency and effectiveness.
- Monitor, report on, and ensure the achievement of Service Level Agreements (SLAs), Key Performance Indicators (KPIs), and other operational metrics to meet contractual obligations.
- Lead client governance, manage reporting structures, and oversee escalation management processes.
- Manage, mentor, and develop SOC teams operating across 24/7 shifts, fostering a high-performance culture.
- Drive continuous improvement initiatives within the SOC, including proactive threat hunting, advanced detection engineering, and use case optimization.
Qualifications and Requirements
- Bachelor's degree in Cybersecurity, Information Technology, or a related field.
- Proven experience leading 24/7 SOC operations.
- Hands-on experience with SIEM, SOAR, EDR, TIP, and Vulnerability Management platforms.
- Strong knowledge of KSA cybersecurity frameworks, including NCA and CST.
- Experience managing SLAs, KPIs, and client contracts.
- 5-10 years of relevant experience.
Required Skills
- Strong leadership capabilities, particularly in high-pressure, mission-critical environments.
- Deep expertise in SOC operations and the cyber defence lifecycle.
- Ability to effectively communicate complex cybersecurity topics to executive stakeholders.
- Experience in delivering managed security services at scale.
- A strong analytical mindset with a focus on risk reduction and operational excellence.
- Proficiency in threat hunting, detection engineering, and automation strategies.
Additional Information
The role is based in Al Khobar, Saudi Arabia, and is a full-time position. Ideal qualifications include professional certifications such as CISSP, CISM, GCIA, GCIH, CEH, or relevant vendor certifications. Experience in threat intelligence and exposure to critical national infrastructure or high-security environments are also beneficial.