img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Tabby | تابي is seeking an Information Security Engineer (SOC L ) to join their team in Riyadh, Saudi Arabia. This full-time role is crucial for monitoring and defending the company's infrastructure, applications, and cloud environments against cyber threats. The engineer will lead incident response efforts, develop and tune detection rules, investigate security events, and collaborate with cross-functional teams to enhance the overall security posture.

Key Responsibilities

  • Monitor and analyze logs and alerts from various sources, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
  • Perform correlation of events from multiple sources to identify advanced threats and unusual patterns of behavior.
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve the signal-to-noise ratio.
  • Maintain dashboards and reporting to provide real-time visibility into the security posture.

Incident Response and Investigation

  • Serve as a frontline responder for security incidents, managing them through their lifecycle: detection, containment, eradication, recovery, and lessons learned.
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
  • Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
  • Maintain detailed incident documentation and contribute to post-mortem analysis and reports.

Threat Intelligence and Detection Rule Development

  • Research emerging threats and trends.
  • Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms, including cloud environments.
  • Maintain the Cyber Threat Intelligence (CTI) Platform and integrate CTI feeds with security controls for active CTI-driven detections.

Collaboration and Communication

  • Communicate effectively with cross-functional teams, including IT, DevOps, Risk, and Compliance, during incidents and investigations.
  • Provide concise and clear updates during incident handling to stakeholders and management.
  • Mentor junior analysts and assist in training efforts within the SOC team.

Experience Required

Candidates should possess 2-5 years of relevant experience in information security.


Requirements

  • Requires 5-10 Years experience

Similar Jobs