تفاصيل الوظيفة
تسعى شركة Teslm إلى تعيين مهندس SIEM/SOC للعمل في مكة المكرمة (حضوري). سيتولى المهندس مسؤولية بناء وإدارة قدرة SIEM/SOC المركزية بالكامل، بدءاً من إعداد خط أنابيب البيانات ووصولاً إلى كتابة قواعد الكشف وإجراء التصفيف اليومي، والعمل مباشرة مع الرئيس التنفيذي ومسؤول أمن المعلومات (CISO).
المهام والمسؤوليات
- إدارة عملية إدراج مصادر السجلات: CloudTrail وGuardDuty وSecurity Hub وسجلات البنية التحتية وأحداث أمن التطبيقات، وتحليلها إلى مخطط موحد.
- إدارة مجموعة قواعد الكشف: كتابة وضبط عدد محدود من القواعد عالية القيمة المرتبطة بالمخاطر الرئيسية، ومراجعة النتائج الإيجابية الخاطئة أسبوعياً.
- مراقبة صحة كل مصدر سجل لاكتشاف الثغرات الصامتة قبل أن يكتشفها المدقق أو المهاجم.
- إجراء التصفيف اليومي والاحتواء: التحقيق في الأحداث المرتبطة حسب المضيف والمستخدم وعنوان IP، والاحتواء بعد الحصول على موافقة قبل أي إجراء إنتاجي مدمر، وتوثيق كل حالة.
- إدارة الاحتفاظ بالسجلات والأدلة: أرشفة ثابتة للسجلات، والاحتفاظ المتوافق مع الالتزامات التنظيمية، وحزم أدلة ربع سنوية.
- إدارة دفاتر التشغيل والاستعلامات المحفوظة ومسار التصعيد للمحلل L1، وتحديد أولوياته اليومية.
الشروط والمتطلبات
- خبرة عملية من 2-4 سنوات في مجال SIEM/SOC، مع قيامك شخصياً بإدراج مصادر السجلات وكتابة/ضبط قواعد الكشف وتصفية التنبيهات الناتجة.
- بناء أو صيانة نظام SIEM بنفسك (Wazuh، Elastic، Splunk، CrowdStrike أو ما شابه) مع القدرة على شرح الخيارات التصميمية.
- معرفة عملية بتسجيل أمن AWS: CloudTrail وGuardDuty وSecurity Hub، وكيفية وصول أحداثها إلى SIEM.
- إلمام بتحليل السجلات وتوحيدها، ولغات الاستعلام، وإدارة Linux للمكونات التي تديرها.
- القدرة على كتابة دفاتر تشغيل ووثائق حوادث واضحة.
- هذا دور عملي تقني وليس معماريًا أو قياديًا - ستبني وتدير الأدوات بنفسك بالعمل مع الرئيس التنفيذي ومسؤول أمن المعلومات.
المهارات المطلوبة
- شهادة CompTIA Security+ أو CySA+.
- شهادة AWS Certified Security - Specialty.
- تدريب من بائع Wazuh أو Elastic أو Splunk.
- شهادات GIAC (GCIA أو GCIH أو GMON).
- خبرة في مراقبة تكامل الملفات أو كشف الثغرات أو لوحات تحكم PCI DSS داخل SIEM.
عرض النص الأصلي للإعلان
Teslm is establishing its central SIEM/SOC capability and needs one hands-on engineer to own it end to end. You will decide how the pipeline is assembled, bring the log sources in, write the detections and run the daily triage - working directly with the CEO & CISO. If you have built or run a SIEM with your own hands and want the whole thing to be your responsibility, this is that role.
***About the role***
12 months in, success looks like this: every relevant log source from our AWS environment and our applications is onboarded, normalised into a common schema and reported healthy every month; a focused set of priority detections is live and tuned so that the alert queue can be trusted; the triage workflow (alert → investigate → contain → document → close or escalate) is documented in runbooks that an L1 Analyst can follow; log retention and an immutable archive are in place; and the evidence an auditor asks for under PCI DSS v4 Requirement 10, PDPL, NCA ECC-2:2024 and ISO/IEC 27001 A.8.15 and A.8.16 can be produced on request. You will also give day-to-day technical direction to an L1 SOC Analyst.
We are deliberately not fixed on a vendor. You may build Wazuh from scratch, monitor and maintain CrowdStrike, or work with a Wazuh service provider - we are hiring for general SIEM competence, not for a product.
***What you'll do***
• Own log-source onboarding: CloudTrail, GuardDuty and Security Hub findings, infrastructure logs and application security events, each parsed into a common schema.
• Own the detection set: write, version and tune a small number of high-value rules mapped to our top risks, and review false positives every week.
• Own the health of every log source - spot silent gaps before an auditor or an attacker does.
• Own daily triage and containment: investigate related events by host, user and IP, contain with a second pair of eyes before any destructive production action, and document every case.
• Own retention and evidence: an immutable log archive, retention aligned to our compliance obligations, and quarterly evidence packs.
• Own the runbooks, saved queries and escalation path the L1 SOC Analyst works from, and set that analyst's daily priorities.
***Required***
• 2-4 years of hands-on SIEM/SOC work in which you personally onboarded log sources, wrote or tuned detection rules, and triaged the resulting alerts.
• You have built or maintained a SIEM yourself - Wazuh, Elastic, Splunk, CrowdStrike or similar - and can explain the design choices you made.
• Working knowledge of AWS security logging: CloudTrail, GuardDuty and Security Hub, and how their events end up in a SIEM.
• Comfortable with log parsing and normalisation, query languages, and Linux administration for the components you run.
• Able to write clear runbooks and incident documentation.
• This is a hands-on practitioner role, not an architect or leadership position - you will build and run the tooling yourself, working directly with the CEO & CISO. If you are looking for a team to manage, this is not the right fit.
***Nice to have***
• CompTIA Security+ or CySA+
• AWS Certified Security - Specialty
• Wazuh, Elastic or Splunk vendor training
• GIAC certifications (GCIA, GCIH or GMON)
• Experience with file-integrity monitoring, vulnerability detection or PCI DSS dashboards inside a SIEM
***Details***
• Location: Makkah, Saudi Arabia - on-site
• Employment: full-time, permanent, start as soon as possible
• Reports to: the CEO & CISO
• Scope: Teslm's AWS environment and applications
• International candidates are welcome to apply.
***How to apply***
Apply via LinkedIn.
رقم الإعلان لدى المصدر: 4464600981