img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Accenture Saudi Arabia is seeking a Security Delivery Senior Analyst to join their team in Riyadh. This full-time role involves taking ownership of security events escalated from L1 analysts, performing in-depth triage and investigation, and contributing to the continuous improvement of security operations.

Key Responsibilities

  • Take ownership of security incidents and events escalated from L1 analysts, handling them according to defined SOC processes and procedures.
  • Perform detailed triage, validation, and investigation of detected and escalated security events.
  • Analyze and categorize events of interest based on agreed severity levels, escalation criteria, and runbooks.
  • Correlate available security information to determine the nature, scope, and potential impact of suspicious activity.
  • Escalate complex or high-risk incidents through appropriate response channels when required.
  • Maintain accurate investigation findings, evidence, and incident documentation.

SIEM and Detection Support

  • Collaborate with SIEM administrators and security engineering teams to support the creation and enhancement of security-monitoring use cases.
  • Provide investigation insights to identify opportunities for improving existing detection logic.
  • Support testing and refinement of SIEM use cases based on operational security requirements.
  • Identify potential detection gaps observed during incident investigations and raise them with relevant security teams.

SOC Procedures and Continuous Improvement

  • Develop, maintain, and continuously improve Standard Operating Procedures (SOPs), investigation playbooks, and Incident Response plans.
  • Help standardize investigation and triage practices to promote consistent incident handling across the SOC.
  • Capture lessons learned from investigations and contribute to improvements in operational processes.
  • Collaborate with L1 analysts and other security teams to support effective incident handling and knowledge sharing.

Qualifications and Experience

  • Experience working within a Security Operations Center (SOC) or cybersecurity monitoring environment.
  • Hands-on experience with security event triage, investigation, and incident escalation.
  • Good understanding of Incident Response processes, SOC procedures, and security runbooks.
  • Experience using Security Information and Event Management (SIEM) technologies.
  • Ability to investigate and correlate security events and identify potentially malicious activity.
  • Understanding of security alerts, event severity classification, and escalation processes.
  • Experience creating or maintaining SOPs, playbooks, and Incident Response documentation.
  • Understanding of SIEM detection use cases and correlation rules.
  • Strong analytical, troubleshooting, and problem-solving capabilities.
  • Strong written and verbal communication skills with attention to detail.

Preferred Skills

  • Experience supporting SIEM use-case development or detection tuning.
  • Exposure to EDR, SOAR, endpoint security, or other security-monitoring technologies.
  • Familiarity with MITRE ATT&CK and common attack techniques.
  • Experience with threat hunting or deeper incident investigation.
  • Relevant cybersecurity or SOC certifications.

Requirements

  • No experience required

Similar Jobs