img
Contract TypeFull-time
Workplace typeOn-site
LocationMakkah

Job Description

About the Role

Teslm is seeking a SIEM/SOC Engineer to establish and manage its central SIEM/SOC capability. This full-time position, based in Makkah, requires a hands-on engineer with 2-5 years of experience who will take end-to-end ownership of the SIEM/SOC pipeline, working directly with the CEO and CISO.

Role Context and Objectives

The successful candidate will be responsible for designing and implementing the SIEM/SOC infrastructure. Within 12 months, key objectives include onboarding all relevant log sources from the AWS environment and applications, normalizing data into a common schema, and ensuring monthly health reporting. The role also involves developing and tuning priority detections, establishing a trusted alert queue, documenting triage workflows, and ensuring compliance with log retention requirements for PCI DSS v4 Requirement 10, PDPL, NCA ECC-2:2024, and ISO/IEC 27001 *** and **** Day-to-day technical direction will also be provided to an L1 SOC Analyst.

Key Responsibilities

  • Manage log-source onboarding, including CloudTrail, GuardDuty, Security Hub findings, infrastructure logs, and application security events, ensuring parsing into a common schema.
  • Develop, version, and tune high-value detection rules aligned with top risks, and conduct weekly reviews of false positives.
  • Monitor and maintain the health of all log sources to identify gaps proactively.
  • Lead daily triage and containment efforts, investigating related events by host, user, and IP, and documenting each case.
  • Oversee log retention and evidence management, including an immutable log archive, compliance-aligned retention, and quarterly evidence packs.
  • Create and maintain runbooks, saved queries, and escalation paths for the L1 SOC Analyst, and set daily priorities for the analyst.

Required Qualifications and Skills

  • 2–4 years of hands-on SIEM/SOC experience, including personal involvement in log source onboarding, detection rule writing/tuning, and alert triage.
  • Demonstrated experience building or maintaining a SIEM (*, Wazuh, Elastic, Splunk, CrowdStrike) with the ability to articulate design choices.
  • Working knowledge of AWS security logging, including CloudTrail, GuardDuty, and Security Hub, and their integration into a SIEM.
  • Proficiency in log parsing, normalization, query languages, and Linux administration for system components.
  • Ability to write clear runbooks and incident documentation.
  • This is a practitioner role focused on building and running tooling, not an architect or leadership position.

Preferred Qualifications

  • CompTIA Security+ or CySA+ certification.
  • AWS Certified Security – Specialty.
  • Wazuh, Elastic, or Splunk vendor training.
  • GIAC certifications (GCIA, GCIH, or GMON).
  • Experience with file-integrity monitoring, vulnerability detection, or PCI DSS dashboards within a SIEM.

Additional Information

This is a permanent, full-time position with an immediate start. The role reports directly to the CEO & CISO and covers Teslm's AWS environment and applications. International candidates are encouraged to apply.


Requirements

  • No experience required

Similar Jobs