📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

EY تعلن عن وظيفة مدير استشارات تقنية - الأتمتة السيبرانية وهندسة الكشف والذكاء الاصطناعي في الرياض

Manager - Tech Consulting - Cyber Automation, Detection Engineering / AI - Riyadh
🏢 EY
🕒 نُشرت: (منذ 25 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة EY عن فرصة وظيفية لشغل منصب مدير - استشارات تقنية - الأمن السيبراني، تخصص أتمتة السايبر، هندسة الكشف، والذكاء الاصطناعي، في مدينة الرياض.

نبذة عن الوظيفة

نبحث عن مديرين ذوي خبرة في هندسة SOC الذاتية والأتمتة والذكاء الاصطناعي لقيادة تصميم وبناء ونشر وتحسين قدرات عمليات الأمن من الجيل التالي. سيكون المرشح مسؤولاً عن تمكين الانتقال من عمليات SOC التقليدية التي يقودها المحللون إلى نموذج تشغيل SOC شبه ذاتي مدعوم بالذكاء الاصطناعي، يجمع بين أتمتة الأمن وAI/GenAI وهندسة الكشف والتنسيق والتحليلات الأمنية المتقدمة. يتطلب الدور خبرة عملية قوية في أتمتة الأمن وعمليات الأمن المدعومة بالذكاء الاصطناعي وهندسة الكشف، مع القدرة على ترجمة حالات استخدام SOC إلى قدرات إنتاجية قابلة للتطوير.

المهام والمسؤوليات

  • قيادة التصميم التقني ونشر قدرات SOC الذاتية المدعومة بالذكاء الاصطناعي.
  • تحديد عمليات SOC المناسبة للأتمتة والتنفيذ الذاتي عبر فرز التنبيهات والتحقيق والإثراء والاحتواء والاستجابة.
  • تصميم وتنفيذ سير عمل تحقيق أمني مدعوم بالذكاء الاصطناعي ودعم اتخاذ القرار.
  • تطوير ودمج قدرات SOC قائمة على LLM/GenAI، بما في ذلك المساعدين الرقميين للمحللين والتحقيق الآلي وتلخيص الحوادث وتحليل التهديدات وتوصيات الاستجابة.
  • تصميم ضوابط مناسبة لحلقة الإنسان في الحلقة وبوابات الموافقة وحواجز الحماية وآليات التصعيد للإجراءات الأمنية الذاتية.
  • تقييم دقة وموثوقية وأمان وفعالية حالات استخدام SOC المدعومة بالذكاء الاصطناعي.
  • دعم تطوير خارطة طريق SOC الذاتي وزيادة مستوى الأتمتة تدريجياً عبر عمليات الأمن.
  • تصميم وبناء وصيانة سير عمل أمني آلي وplaybooks للتنسيق.
  • أتمتة أنشطة SOC المتكررة مثل إثراء التنبيهات والتحقيق في مؤشرات الاختراق وتحليل التصيد والتحقيق في نقاط النهاية والتحقيق في الهوية وإثراء معلومات التهديدات وتحليل البرامج الضارة وإنشاء الحالات وإدارتها والاحتواء والمعالجة.
  • تطوير التكاملات بين SIEM وSOAR وEDR/XDR ومعلومات التهديدات وأمن البريد الإلكتروني والهوية وأمن الشبكات وأمن السحابة وإصدار التذاكر ومنصات الأمن الأخرى.
  • بناء الأتمتة باستخدام Python وREST APIs وwebhooks وSDKs والبرمجة النصية ومنصات التنسيق.
  • تطوير مكونات أتمتة قابلة لإعادة الاستخدام وأنماط تكامل موحدة.
  • تنفيذ آليات معالجة الأخطاء والتسجيل والمراقبة والاختبار والاسترجاع للإجراءات الأمنية الآلية.
  • قيادة تطوير وتحسين قدرة هندسة الكشف في SOC بشكل مستمر.
  • تصميم وتطوير واختبار وضبط وصيانة قواعد الكشف الأمني عبر SIEM وEDR/XDR والسحابة والهوية والشبكات وتقنيات الأمن الأخرى.
  • ترجمة معلومات التهديدات وتقنيات الهجوم ونتائج الحوادث ونتائج صيد التهديدات إلى اكتشافات قابلة للتنفيذ.
  • رسم تغطية الكشف مقابل MITRE ATT&CK وتحديد فجوات الكشف.
  • تطوير نهج الكشف كرمز بما في ذلك التحكم في الإصدارات والاختبار ومراجعة الأقران والنشر وإدارة دورة الحياة.
  • تحديد مقاييس جودة الكشف بما في ذلك الدقة ومعدلات الإيجابية الكاذبة والتغطية وفعالية الكشف.
  • العمل مع مهندسي الأتمتة لربط الاكتشافات مباشرة بسير عمل التحقيق والاستجابة الآليين.
  • دمج القياسات عن بعد من منصات متعددة في سير عمل التحقيق والأتمتة المدعومة بالذكاء الاصطناعي.
  • تطوير آليات لأنظمة الذكاء الاصطناعي لاسترداد وربط السياق الأمني ذي الصلة بشكل آمن.
  • تصميم prompts منظمة وسير عمل ومنطق وكيل وتكاملات أدوات لحالات استخدام الأمن.
  • دعم تكامل مصادر المعرفة المؤسسية ومعلومات التهديدات والحوادث التاريخية ومحتوى الكشف وإجراءات SOC في سير العمل المدعومة بالذكاء الاصطناعي.
  • تطبيق الضوابط الأمنية المناسبة حول خصوصية البيانات والتحكم في الوصول واستخدام النموذج وقابلية التدقيق والقرارات الناتجة عن الذكاء الاصطناعي.
  • مراقبة مخرجات الذكاء الاصطناعي بحثاً عن الهلوسة والاستنتاجات الخاطئة والإجراءات غير الآمنة والمخاطر التشغيلية الأخرى.
  • تقييم عمليات SOC الحالية وتحديد فرص تحسين الكفاءة من خلال الهندسة والأتمتة.
  • تقليل عبء العمل اليدوي للمحللين وتحسين متوسط الوقت للكشف والتحقيق والاستجابة.
  • وضع معايير هندسية للأتمتة والتكاملات ومحتوى الكشف وسير العمل المدعومة بالذكاء الاصطناعي.
  • إجراء الاختبار والتحقق قبل نشر الإجراءات الآلية للاستجابة في الإنتاج.
  • تتبع فعالية قدرات SOC الذاتية من خلال مؤشرات أداء رئيسية قابلة للقياس.
  • توجيه محللي ومهندسي SOC في مجال الأتمتة وهندسة الكشف والتحقيقات المدعومة بالذكاء الاصطناعي والتقنيات الأمنية الجديدة.
  • العمل مع قيادة SOC والهندسة المعمارية والبنية التحتية والسحابة وIAM وفرق هندسة الأمن لتقديم قدرات متكاملة.

الشروط والمتطلبات

  • خبرة لا تقل عن 7 سنوات في مجال الأمن السيبراني، مع خبرة كبيرة في هندسة SOC وهندسة الكشف وأتمتة الأمن والاستجابة للحوادث أو عمليات الأمن.
  • خبرة عملية قوية في تقنيات SIEM مثل Microsoft Sentinel أو Splunk ES أو Google SecOps أو ما يعادلها.
  • خبرة قوية في SOAR ومنصات التنسيق الأمني.
  • خبرة في تطوير أتمتة الأمن باستخدام Python وREST APIs.
  • فهم قوي لسير عمل SOC وفرز التنبيهات والتحقيق والاستجابة للحوادث.
  • خبرة مثبتة في تصميم وهندسة اكتشافات أمنية.
  • معرفة قوية بـ MITRE ATT&CK والدفاع القائم على التهديدات.
  • خبرة في دمج منصات الأمن من خلال APIs وتطوير سير عمل تحقيق أو استجابة آليين.
  • خبرة في EDR/XDR وأمن الهوية وأمن البريد الإلكتروني وأمن الشبكات وأمن السحابة ومنصات معلومات التهديدات.
  • فهم إدارة دورة حياة الكشف، والكشف كرمز، وGit/التحكم في الإصدارات، وCI/CD، والاختبار الآلي.
  • معرفة قوية أو خبرة عملية في GenAI ونماذج اللغة الكبيرة وعوامل الذكاء الاصطناعي وسير عمل الوكيل وLLM APIs ومنصات الذكاء الاصطناعي المؤسسية وهندسة prompts وRAG واستدعاء الأدوات ووكلاء AI المدعومين بـ API والتحقيقات المدعومة بالذكاء الاصطناعي والتحليلات الأمنية وتقييم الذكاء الاصطناعي واختبار الدقة وإدارة الهلوسة والحواجز الواقية والتنفيذ الآمن للذكاء الاصطناعي في بيئات الأمن السيبراني المؤسسية (لا يشترط أن يكون المرشح باحثاً في تعلم الآلة؛ التركيز على التطبيق العملي للذكاء الاصطناعي في عمليات الأمن).

المهارات المطلوبة

  • خبرة عملية في هندسة SOC الذاتي وأتمتة الأمن والتنسيق.
  • إتقان استخدام Microsoft Sentinel وSplunk ES أو Google SecOps.
  • مهارات متقدمة في Python وتطوير REST APIs.
  • خبرة في دمج SOAR مع EDR/XDR ومعلومات التهديدات وأمن البريد الإلكتروني والهوية والشبكات والسحابة.
  • قدرة على تصميم وتطوير playbooks أتمتة معقدة مع معالجة الأخطاء والمراقبة.
  • خبرة في هندسة الكشف وتطوير قواعد الكشف كرمز.
  • معرفة متعمقة بـ MITRE ATT&CK وتطبيقه في تغطية الكشف.
  • مهارات تحليلية قوية لتقييم فعالية الكشف وجودة التنبيهات.
  • خبرة في تقنيات الذكاء الاصطناعي التوليدي (GenAI) ونماذج LLM وتطبيقاتها في SOC.
  • دراية بـ RAG (Retrieval-Augmented Generation) وهندسة prompts وأدوات استدعاء الوظائف.
  • فهم تقييم الذكاء الاصطناعي والهلوسة والحواجز الواقية والأمان في تطبيقات AI.
  • القدرة على العمل ضمن فريق متعدد التخصصات وتوجيه المهندسين والمحللين.
  • خبرة مفضلة مع تقنيات Microsoft (في إطار الأمن السيبراني).
عرض النص الأصلي للإعلان
Role Summary

We are seeking experienced Managers Autonomous SOC Engineering, AI & Automation to lead the design, engineering, deployment, and continuous improvement of next-generation Security Operations capabilities.

The role will be responsible for enabling the transition from traditional analyst-led SOC operations toward an AI-assisted and increasingly autonomous SOC operating model, combining security automation, AI/GenAI, detection engineering, orchestration, and advanced security analytics.

The successful candidates will be technically hands-on and will work across SIEM, SOAR, EDR/XDR, threat intelligence, case management, APIs, AI/LLM platforms, and security data sources to automate security workflows, develop use cases and improve detection quality, accelerate investigations and response, and reduce repetitive analyst effort.

The role requires strong experience across automation engineering, AI-enabled security operations, and detection engineering, with the ability to translate SOC use cases into scalable production capabilities.

Key Responsibilities

Autonomous SOC & AI Engineering

  • Lead the technical design and deployment of AI-driven and autonomous SOC capabilities.
  • Identify SOC processes suitable for automation and autonomous execution across alert triage, investigation, enrichment, containment, and response.
  • Design and implement AI-assisted security investigation and decision-support workflows.
  • Develop and integrate LLM/GenAI-based SOC capabilities, including analyst copilots, automated investigation, incident summarisation, threat intelligence analysis, and response recommendations.
  • Design appropriate human-in-the-loop controls, approval gates, guardrails, and escalation mechanisms for autonomous security actions.
  • Evaluate the accuracy, reliability, security, and operational effectiveness of AI-enabled SOC use cases.
  • Support the development of an Autonomous SOC roadmap and progressively increase the level of automation across security operations.

Security Automation & Orchestration

  • Design, build, and maintain automated security workflows and orchestration playbooks.
  • Automate repetitive SOC activities including:
  • Alert enrichment
  • IOC investigation
  • Phishing analysis
  • Endpoint investigation
  • Identity investigation
  • Threat intelligence enrichment
  • Malware analysis
  • Case creation and management
  • Containment and remediation
  • Develop integrations between SIEM, SOAR, EDR/XDR, threat intelligence, email security, identity, network security, cloud security, ticketing, and other security platforms.
  • Build automation using Python, REST APIs, webhooks, SDKs, scripting, and orchestration platforms.
  • Develop reusable automation components and standardized integration patterns.
  • Implement error handling, logging, monitoring, testing, and rollback mechanisms for automated security actions.

Detection Engineering

  • Lead the development and continuous improvement of the SOC’s detection engineering capability.
  • Design, develop, test, tune, and maintain security detection rules across SIEM, EDR/XDR, cloud, identity, network, and other security technologies.
  • Translate threat intelligence, attack techniques, incident findings, and threat hunting results into actionable detections.
  • Map detection coverage against MITRE ATT&CK and identify detection gaps.
  • Develop detection-as-code approaches including version control, testing, peer review, deployment, and lifecycle management.
  • Define detection quality metrics including precision, false-positive rates, coverage, and detection effectiveness.
  • Work with automation engineers to connect detections directly to automated investigation and response workflows.

AI & Security Data Integration

  • Integrate security telemetry from multiple platforms into AI-driven investigation and automation workflows.
  • Develop mechanisms for AI systems to securely retrieve and correlate relevant security context.
  • Design structured prompts, workflows, agent logic, and tool integrations for security use cases.
  • Support integration of enterprise knowledge sources, threat intelligence, historical incidents, detection content, and SOC procedures into AI-enabled workflows.
  • Apply appropriate security controls around data privacy, access control, model usage, auditability, and AI-generated decisions.
  • Monitor AI outputs for hallucinations, incorrect conclusions, unsafe actions, and other operational risks.

SOC Engineering & Continuous Improvement

  • Assess existing SOC processes and identify opportunities to improve efficiency through engineering and automation.
  • Reduce manual analyst workload and improve mean time to detect, investigate, and respond.
  • Establish engineering standards for automation, integrations, detection content, and AI-enabled workflows.
  • Conduct testing and validation before deploying automated response actions into production.
  • Track the effectiveness of Autonomous SOC capabilities through measurable operational KPIs.
  • Mentor SOC analysts and engineers on automation, detection engineering, AI-assisted investigations, and new security technologies.
  • Work with SOC leadership, architecture, infrastructure, cloud, IAM, and security engineering teams to deliver integrated capabilities.

Required Skills & Experience

Candidates should have strong hands-on experience across several of the following areas:

  • 7+ years of cybersecurity experience, with significant experience in SOC engineering, detection engineering, security automation, incident response, or security operations.
  • Strong hands-on experience with SIEM technologies such as Microsoft Sentinel, Splunk ES, Google SecOps or equivalent.
  • Strong experience with SOAR and security orchestration platforms.
  • Experience developing security automation using Python and REST APIs.
  • Strong understanding of SOC workflows, alert triage, investigation and incident response.
  • Demonstrated experience designing and engineering security detections.
  • Strong knowledge of MITRE ATT&CK and threat-informed defence.
  • Experience integrating security platforms through APIs and developing automated investigation or response workflows.
  • Experience with EDR/XDR, identity security, email security, network security, cloud security, and threat intelligence platforms.
  • Understanding of detection lifecycle management, detection-as-code, Git/version control, CI/CD, and automated testing.

AI / GenAI Experience

Strong knowledge or practical experience in:

  • Generative AI and Large Language Models.
  • AI agents and agentic workflows.
  • LLM APIs and enterprise AI platforms.
  • Prompt and context engineering.
  • Retrieval-Augmented Generation (RAG).
  • Tool/function calling and API-enabled AI agents.
  • AI-assisted investigation and security analytics.
  • AI evaluation, accuracy testing, hallucination management, and guardrails.
  • Secure implementation of AI within enterprise cybersecurity environments.

Candidates do not need to be machine-learning researchers, the emphasis is on applying AI practically within security operations.

Preferred Experience

Experience with technologies such as:

  • Microsoft Sentinel / Security Copilot
  • Splunk ES / Splunk SOAR
  • Cortex XSOAR / XSIAM
  • Microsoft Defender XDR
  • CrowdStrike
  • ServiceNow SecOps
  • Threat intelligence platforms
  • Git / GitLab / GitHub
  • Python
  • REST APIs
  • Azure OpenAI / OpenAI APIs or equivalent enterprise LLM platforms
  • Cloud security platforms across Azure, AWS or GCP

Experience building or deploying AI-enabled SOC, Autonomous SOC, hyperautomation, or security-agent solutions would be highly advantageous.

Expected Outcomes

The role will be expected to deliver measurable improvements including:

  • Increased percentage of SOC activities automated.
  • Reduced manual analyst intervention.
  • Improved detection coverage and quality.
  • Reduced false-positive rates.
  • Reduced Mean Time to Triage and Mean Time to Respond.
  • Increased automated enrichment and investigation coverage.
  • Deployment of AI-assisted and autonomous investigation workflows.
  • Increased integration between detection, investigation, and automated response.
المصدر: LinkedIn - أُضيفت للموقع في 14 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465244373