تفاصيل الوظيفة
شركة NourNet تبحث عن محلّل أمن سيبراني من المستوى الأول (CDC L1 SOC Analyst) للانضمام إلى مركز الدفاع السيبراني في الرياض. سيشغل المرشح خط الدفاع الأول ضد التهديدات السيبرانية، مع التركيز على المراقبة الأمنية اللحظية، فرز التنبيهات، التحقيق الأولي، تنفيذ إجراءات الاستجابة الأولية، وإحالة الحوادث بشكل مناسب.
المهام والمسؤوليات
- مراقبة التنبيهات الأمنية عبر منصات SIEM، XDR، EDR، الجدار الناري، IDS/IPS، WAF، أمن البريد الإلكتروني وغيرها من الأنظمة الأمنية.
- إجراء الفرز الأولي للتنبيهات، التحقق من الأحداث، تحديد النتائج الإيجابية الكاذبة، وتصنيف مستوى الخطورة المناسب.
- إجراء التحقيق الأساسي وإثراء مؤشرات الاختراق (IOC) باستخدام مصادر استخبارات التهديدات.
- تنفيذ إجراءات الاستجابة الأولية المصرح بها مثل عزل نقطة النهاية، إنهاء الجلسات، والحظر المؤقت.
- إحالة الحوادث المؤكدة أو المشبوهة إلى فريق المستوى الثاني / فريق الاستجابة للحوادث وفق الإجراءات المعتمدة.
- توثيق خطوات التحقيق والنتائج والإجراءات بدقة في نظام التذاكر.
- اتباع أدلة تشغيل SOC وخطط الاستجابة وإجراءات الإحالة.
- إعداد تقارير تسليم المناوبة دقيقة تغطي الحوادث الجارية والملاحظات والتحديثات التشغيلية.
- المشاركة في محاكاة الاختراقات الأمنية والتدريبات وأنشطة التحسين المستمر.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو أمن المعلومات أو مجال ذي صلة.
- خبرة عملية مع منصات SIEM مثل XSIAM أو Splunk أو QRadar.
- خبرة أساسية في التعامل مع الحوادث وفرز التصيد وإثراء IOC.
- فهم عمليات SOC والعمل بنظام المناوبات.
- القدرة على العمل بفعالية في بيئة تعمل على مدار الساعة (24/7).
- الجنسية السعودية.
المهارات المطلوبة
- مهارات تحليلية قوية وحل المشكلات.
- اهتمام ممتاز بالتفاصيل والانضباط في التوثيق.
- التقنيات المفضلة:
- SIEM: XSIAM، Splunk، QRadar
- EDR/XDR: Microsoft Defender، CrowdStrike، SentinelOne
- أمن البريد الإلكتروني: Proofpoint، Mimecast، Microsoft 365 Defender
- أنظمة التذاكر: ServiceNow، JIRA، Remedy
عرض النص الأصلي للإعلان
We’re Hiring: CDC L1 SOC Analyst (Tier 1)
NourNet is looking for a CDC L1 SOC Analyst to join our Cyber Defense Center and serve as the first line of defense against cyber threats.
The role focuses on real-time security monitoring, alert triage, initial investigation, first-response actions, and timely escalation of potential security incidents.
Key Responsibilities
- Monitor security alerts across SIEM, XDR, EDR, Firewall, IDS/IPS, WAF, Email Security, and other security platforms.
- Perform initial alert triage, validate events, identify false positives, and assign appropriate severity.
- Conduct basic investigation and IOC enrichment using threat intelligence sources.
- Perform authorized first-response actions, including endpoint isolation, session termination, and temporary blocking.
- Escalate confirmed or suspicious incidents to Tier 2 / Incident Response teams based on established procedures.
- Document investigation steps, findings, and actions accurately in the ticketing system.
- Follow SOC runbooks, playbooks, and escalation procedures.
- Maintain accurate shift handover reports covering ongoing incidents, watch items, and operational updates.
- Participate in security simulations, training, and continuous improvement activities.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
- Hands-on exposure to SIEM platforms, such as XSIAM, Splunk, or QRadar.
- Basic experience in incident handling, phishing triage, and IOC enrichment.
- Understanding of SOC operations and shift-based monitoring.
- Strong analytical and problem-solving skills.
- Excellent attention to detail and documentation discipline.
- Ability to work effectively in a 24×7 shift environment.
- Saudi Citizen
Preferred Technologies
SIEM: XSIAM, Splunk, QRadar
EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne
Email Security: Proofpoint, Mimecast, Microsoft 365 Defender
Ticketing: ServiceNow, JIRA, Remedy
If you have a strong interest in cybersecurity, threat detection, and SOC operations and are looking to grow your career within a Cyber Defense Center, we’d like to hear from you.
رقم الإعلان لدى المصدر: 4472418997