📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

Socium تعلن عن وظيفة مهندس عمليات أمن SIEM في الرياض

SIEM Security Operations Engineer (Saudi Nationals)
🕒 نُشرت: (منذ 24 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Socium - Teams Done Differently عن توفر وظيفة مهندس عمليات أمن معلومات متخصص في SIEM (للجنسية السعودية) في الرياض، للعمل على مراقبة التهديدات الإلكترونية وتحليل الحوادث وإدارة الثغرات في بيئة سحابية عالية الأمان.

المهام والمسؤوليات

  • المساعدة في نشر وتكوين وتشغيل منصة SIEM الخاصة بالمؤسسة.
  • دمج سجلات الأمان من حلول أمان المؤسسة مثل WAF و HIDS وأنظمة حماية DDoS والمنصات السحابية والتقنيات الأمنية الأخرى.
  • تكوين وتحسين قواعد الربط (correlation rules) ومنطق التنبيه ولوحات المعلومات وحالات استخدام الكشف عن التهديدات.
  • مراقبة الأحداث الأمنية والتحقيق في التنبيهات وإجراء الفرز الأولي للحوادث الأمنية المحتملة.
  • تحليل السجلات لتحديد الأنشطة المشبوهة ومؤشرات الاختراق (IOCs) والتهديدات الأمنية الناشئة.
  • رفع الحوادث الأمنية المؤكدة إلى فرق الأمن أو الهندسة المختصة لاتخاذ الإجراءات التصحيحية.
  • إدارة وتتبع تذاكر الثغرات الأمنية للخدمات السحابية والمنصات المؤسسية.
  • التحقق من الثغرات المبلغ عنها والتنسيق مع فرق الهندسة لمعالجتها والتحقق من الإصلاح.
  • المساعدة في تحسين قدرات الكشف عن التهديدات عبر ضبط قواعد التنبيه وتقليل النتائج الإيجابية الخاطئة.
  • دعم مبادرات الامتثال الأمني والحفاظ على الوثائق التشغيلية.
  • إجراء عروض توضيحية تقنية وشرح حلول الأمن السيبراني أثناء المراجعات التنظيمية أو عمليات التدقيق أو engagements العملاء.
  • التعاون مع فرق السحابة والبنية التحتية والتطبيقات والأمن لتحسين الوضع الأمني للمؤسسة باستمرار.
  • البقاء على اطلاع دائم بالتهديدات الإلكترونية الناشئة وتقنيات الهجوم وأفضل ممارسات الأمن.

الشروط والمتطلبات

  • الشروط الأساسية: - درجة البكالوريوس في الأمن السيبراني، علوم الحاسب، تقنية المعلومات، أمن المعلومات، أو مجال ذي صلة. - خبرة مهنية لا تقل عن سنتين في عمليات أمن SIEM، عمليات مركز عمليات الأمن (SOC)، مراقبة الأمن السيبراني، أو أمن المعلومات. - الجنسية السعودية. - خبرة عملية في تشغيل منصات SIEM في بيئات مؤسسية. - خبرة في جمع سجلات الأمن، الربط، التحليل، والتحقيق في التنبيهات. - فهم جيد للتهديدات السيبرانية، تقنيات الهجوم، مؤشرات الاختراق (IOCs)، ومراقبة الأمن. - خبرة في إدارة الثغرات وسير العمل المتعلق بالمعالجة. - الإلمام بتقنيات الأمن المؤسسية مثل: جدار حماية تطبيقات الويب (WAF)، أنظمة كشف التسلل للمضيفين (HIDS)، حماية DDoS، منصات الأمن السحابية. - مهارات تحليلية قوية وقدرة على حل المشكلات. - مهارات تواصل جيدة باللغة الإنجليزية (كتابة وتحدثاً).
  • المؤهلات المفضلة: - خبرة في العمل داخل مركز عمليات الأمن (SOC). - معرفة بمفاهيم الأمن السحابي وخدمات الأمن السحابية الأصلية. - فهم تقنيات أمن الذكاء الاصطناعي أو أمن السحابة. - معرفة بلوائح الأمن السيبراني السعودية وأطر الامتثال (مثل NCA ECC، إطار SAMA للأمن السيبراني، PDPL). - خبرة في تقديم مفاهيم أمنية تقنية للمدققين أو الجهات التنظيمية أو العملاء. - مشاركة أو تميز في مسابقات الأمن السيبراني (مثل CTFs، مسابقات الاختراق). - شهادات أمن سيبراني ذات صلة مثل: CompTIA Security+، CompTIA CySA+، شهادات GIAC، CEH، Splunk Core Certified User/Power User، Microsoft SC-200، Google Professional Cloud Security Engineer (ميزة إضافية)، ISC2 CC أو CISSP (ميزة إضافية).
عرض النص الأصلي للإعلان

We are seeking experienced SIEM Security Operations Engineers to support enterprise cybersecurity monitoring, threat detection, incident analysis, and vulnerability management initiatives within a highly secure cloud environment.


The successful candidates will play a key role in deploying and operating the organization's Security Information and Event Management (SIEM) platform, integrating security products, monitoring security events, investigating alerts, and coordinating vulnerability remediation activities across cloud services and enterprise infrastructure.


This role is ideal for cybersecurity professionals with hands-on experience in SIEM operations, Security Operations Center (SOC) environments, log analysis, security monitoring, and vulnerability management who are passionate about strengthening enterprise cyber resilience.

You will work closely with cybersecurity engineers, cloud teams, product development teams, and regulatory stakeholders to enhance security monitoring capabilities, improve threat detection, and ensure timely response to security incidents.


Key Responsibilities

  • Assist in the deployment, configuration, and ongoing operation of the enterprise SIEM platform.
  • Integrate security logs from enterprise security solutions including WAF, HIDS, DDoS protection systems, cloud platforms, and other security technologies.
  • Configure and optimize SIEM correlation rules, alert logic, dashboards, and detection use cases.
  • Monitor security events, investigate alerts, and perform initial triage of potential security incidents.
  • Analyze logs to identify suspicious activities, indicators of compromise (IOCs), and emerging security threats.
  • Escalate validated security incidents to the appropriate cybersecurity or engineering teams for remediation.
  • Manage and track security vulnerability tickets for cloud services and enterprise platforms.
  • Validate reported vulnerabilities, coordinate remediation with engineering teams, and perform post-remediation verification.
  • Assist in improving detection capabilities by tuning alert rules and reducing false positives.
  • Support security compliance initiatives and maintain operational documentation.
  • Conduct technical demonstrations and explain cybersecurity solutions during regulatory reviews, audits, or customer engagements.
  • Collaborate with cloud, infrastructure, application, and security teams to continuously improve enterprise security posture.
  • Stay up to date with emerging cyber threats, attack techniques, and security best practices.


Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Security, or a related field.
  • Minimum 2 years of professional experience in SIEM Security Operations, SOC Operations, Cybersecurity Monitoring, or Information Security.
  • Saudi National.
  • Hands-on experience operating SIEM platforms in enterprise environments.
  • Experience with security log collection, correlation, analysis, and alert investigation.
  • Good understanding of cybersecurity threats, attack techniques, indicators of compromise (IOCs), and security monitoring.
  • Experience in vulnerability management and remediation workflows.
  • Familiarity with enterprise security technologies such as:
  • Web Application Firewall (WAF)
  • Host Intrusion Detection Systems (HIDS)
  • DDoS Protection
  • Cloud Security Platforms
  • Strong analytical and troubleshooting skills.
  • Good written and verbal communication skills in English.


Preferred Qualifications

  • Experience working within a Security Operations Center (SOC).
  • Knowledge of cloud security concepts and cloud-native security services.
  • Understanding of AI Security or Cloud Security technologies.
  • Knowledge of Saudi Arabia cybersecurity regulations and compliance frameworks (e.g., NCA ECC, SAMA Cybersecurity Framework, PDPL).
  • Experience presenting technical security concepts to auditors, regulators, or customers.
  • Participation or recognition in cybersecurity competitions (e.g., CTFs, hacking competitions).
  • Relevant cybersecurity certifications such as:
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Certifications
  • CEH
  • Splunk Core Certified User/Power User
  • Microsoft SC-200
  • Google Professional Cloud Security Engineer (advantage)
  • ISC2 CC or CISSP (advantage)
المصدر: LinkedIn - أُضيفت للموقع في 15 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465531015