تفاصيل الوظيفة
تعلن شركة Ebryx LLC عن توفر 4 وظائف لمهندسي أمن سيبراني (SOC) في الرياض، بدوام كامل وحضوري. الوظائف مخصصة للسعوديين فقط، وتتطلب مستويات خبرة مختلفة في مجال عمليات أمن المعلومات (SOC).
نبذة عن الوظيفة
نبحث عن محللي SOC للانضمام إلى فريق الأمن السيبراني في الرياض. سيتولى المرشحون الناجحون مسؤولية مراقبة الأحداث الأمنية، والتحقيق في التنبيهات، وتحديد التهديدات المحتملة، ودعم أنشطة الاستجابة للحوادث داخل مركز عمليات الأمن (SOC).
المهام والمسؤوليات
- مراقبة التنبيهات والأحداث الأمنية باستخدام SIEM وأدوات المراقبة الأخرى.
- التحقيق في الحوادث الأمنية والأنشطة المشبوهة وفرزها.
- تحليل السجلات والأحداث الأمنية لتحديد التهديدات المحتملة ومؤشرات الاختراق.
- إجراء التحقيق الأولي للحوادث وتصعيدها وفق الإجراءات المحددة.
- دعم أنشطة الاستجابة للحوادث والاحتواء والمعالجة.
- إعداد وتحديث تقارير الحوادث والوثائق الأمنية.
- مراقبة مصادر استخبارات التهديدات وتحديد التهديدات الأمنية الناشئة.
- المساعدة في تحسين عمليات SOC وحالات الاستخدام وقواعد الكشف وقدرات المراقبة.
- التعاون مع فرق الأمن السيبراني وتقنية المعلومات الأخرى لحل الحوادث الأمنية.
- اتباع السياسات والإجراءات الأمنية وعمليات الاستجابة للحوادث المقررة.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني، علوم الحاسب، تقنية المعلومات، أو مجال ذي صلة.
- خبرة عملية ذات صلة في بيئة SOC / عمليات الأمن وفقًا لمستوى المنصب (1 سنة لمنصبين، 3 سنوات لمنصب واحد، 5 سنوات لمنصب واحد).
- فهم قوي لـ SIEM وعمليات SOC والاستجابة للحوادث وأمن الشبكات وأساسيات الأمن السيبراني.
- خبرة في المراقبة الأمنية وتحليل السجلات وفرز التنبيهات والتحقيق في الحوادث.
- فهم جيد لـ TCP/IP والشبكات وأمن Windows/Linux والتهديدات السيبرانية الشائعة.
- مهارات تحليلية قوية وحل المشكلات.
- مهارات تواصل كتابية وشفهية جيدة.
- الاستعداد للعمل في بيئة SOC موقعية، وعند الحاجة، في نوبات مدورة.
- شهادة معتمدة إلزامية: يجب أن يحمل المرشح شهادة واحدة على الأقل من الشهادات التالية في مجال SOC / الأمن السيبراني: CompTIA Security+، CompTIA CySA+، EC-Council Certified SOC Analyst (CSA)، Certified Cybersecurity Analyst (CySA+)، شهادات GIAC لعمليات الأمن / الاستجابة للحوادث، Microsoft Security Operations Analyst (SC-200)، أو أي شهادة أمنية/SOC معترف بها ذات صلة.
المهارات المطلوبة
- خبرة عملية مع منصات SIEM مثل Microsoft Sentinel، Splunk، IBM QRadar، أو ArcSight.
- معرفة بأدوات EDR/XDR، IDS/IPS، الجدران النارية، وأدوات إدارة الثغرات.
- الإلمام بإطار MITRE ATT&CK وتقنيات الهجوم الشائعة.
- فهم استخبارات التهديدات وتحليل مؤشرات الاختراق (IOC).
- خبرة في عمليات الاستجابة للحوادث والتحقيقات الأمنية.
عرض النص الأصلي للإعلان
CyberSecurity Engineers - SOC
Location: Riyadh, Saudi Arabia
Employment Type: Full-time, Onsite
Nationality: Saudi Nationals Only
Open Positions: 4
Experience Requirements
- 2 Positions: Minimum 1 year of relevant SOC experience
- 1 Position: Minimum 3 years of relevant SOC experience
- 1 Position: Minimum 5 years of relevant SOC experience
Role Overview:
We are looking for SOC Analysts to join our cybersecurity team in Riyadh. The successful candidates will be responsible for monitoring security events, investigating alerts, identifying potential threats, and supporting incident response activities within a Security Operations Center.
Key Responsibilities:
- Monitor security alerts and events using SIEM and other security monitoring tools.
- Investigate and triage security incidents and suspicious activities.
- Analyze logs and security events to identify potential threats and indicators of compromise.
- Perform initial incident investigation and escalation according to defined procedures.
- Support incident response, containment, and remediation activities.
- Prepare and maintain incident reports and security documentation.
- Monitor threat intelligence feeds and identify emerging security threats.
- Assist in improving SOC processes, use cases, detection rules, and monitoring capabilities.
- Collaborate with other cybersecurity and IT teams to resolve security incidents.
- Follow established security policies, procedures, and incident response processes.
Requirements:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Relevant hands-on experience in a SOC/Security Operations environment according to the position level.
- Strong understanding of SIEM, SOC operations, incident response, network security, and cybersecurity fundamentals.
- Experience with security monitoring, log analysis, alert triage, and incident investigation.
- Good understanding of TCP/IP, networking, Windows/Linux security, and common cyber threats.
- Strong analytical and problem-solving skills.
- Good written and verbal communication skills.
- Willingness to work in an onsite SOC environment and, where required, rotational shifts.
Certifications - Mandatory
Candidates must hold at least one relevant SOC/cybersecurity certification, such as:
- CompTIA Security+
- CompTIA CySA+
- EC-Council Certified SOC Analyst (CSA)
- Certified Cybersecurity Analyst (CySA+)
- GIAC Security Operations / Incident Response certifications
- Microsoft Security Operations Analyst (SC-200)
- Other recognized and relevant SOC/security certifications will also be considered.
Preferred Skills:
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, or ArcSight.
- Knowledge of EDR/XDR, IDS/IPS, firewalls, and vulnerability management tools.
- Familiarity with MITRE ATT&CK and common attack techniques.
- Understanding of threat intelligence and IOC analysis.
- Experience with incident response and security investigation processes.
رقم الإعلان لدى المصدر: 4466038768