أكسنتشر تعلن عن وظيفة Security Delivery Senior Analyst في الرياض
تفاصيل الوظيفة
أكسنتشر تبحث عن محلل أقدم لتسليم الأمن (Security Delivery Senior Analyst) للعمل في الرياض. ستتولى مسؤولية الأحداث الأمنية المحالة من محللي المستوى الأول، وإجراء تحليل متعمق والتحقيق فيها ضمن فريق عمليات الأمن.
نبذة عن الوظيفة
بصفتك محللاً أقدم لتسليم الأمن، ستؤدي دوراً رئيسياً ضمن عمليات الأمن، حيث تتولى مسؤولية الأحداث الأمنية المحالة من محللي المستوى الأول (L1) وتقوم بتحليل وتقصي وتحقيق أعمق. ستساعد في ضمان معالجة الحوادث باستمرار وفقاً للعمليات والأدلة الإجرائية المحددة، مع المساهمة في تطوير أدلة إجرائية أقوى وإجراءات الاستجابة للحوادث وحالات استخدام SIEM للكشف.
المهام والمسؤوليات
- تولي مسؤولية الحوادث والأحداث الأمنية المحالة من محللي L1 ومعالجتها وفقاً لعمليات وإجراءات SOC المحددة.
- إجراء تحليل وتقصي والتحقق المفصل للأحداث الأمنية المكتشفة والمحالة.
- تحليل وتصنيف الأحداث ذات الاهتمام وفقاً لمستويات الخطورة المتفق عليها ومعايير التصعيد والأدلة الإجرائية.
- ربط المعلومات الأمنية المتاحة لتحديد طبيعة ونطاق والتأثير المحتمل للنشاط المشبوه.
- تصعيد الحوادث المعقدة أو عالية الخطورة عبر قنوات الاستجابة المناسبة عند الضرورة.
- الحفاظ على نتائج التحقيق والأدلة ووثائق الحوادث بدقة.
- العمل بشكل وثيق مع مسؤولي SIEM وفرق هندسة الأمن لدعم إنشاء وتعزيز حالات استخدام مراقبة الأمن.
- تقديم رؤى من التحقيقات يمكن أن تساعد في تحديد فرص تحسين منطق الكشف الحالي.
- دعم اختبار وتحسين حالات استخدام SIEM بناءً على المتطلبات الأمنية التشغيلية.
- تحديد فجوات الكشف المحتملة التي تُلاحظ أثناء التحقيقات ورفعها إلى فرق الأمن المختصة.
- تطوير وصيانة وتحسين إجراءات التشغيل القياسية (SOPs) والأدلة الإجرائية للتحقيق وخطط الاستجابة للحوادث.
- المساعدة في توحيد ممارسات التحقيق والتحليل لتعزيز معالجة الحوادث بشكل متسق عبر SOC.
- توثيق الدروس المستفادة من التحقيقات والمساهمة في تحسين العمليات التشغيلية.
- التعاون مع محللي L1 وفرق الأمن الأخرى لدعم معالجة الحوادث الفعالة ومشاركة المعرفة.
الشروط والمتطلبات
- خبرة في العمل ضمن مركز عمليات أمن (SOC) أو بيئة مراقبة الأمن السيبراني.
- خبرة عملية في تحليل الأحداث الأمنية والتحقيق فيها وتصعيد الحوادث.
- فهم جيد لعمليات الاستجابة للحوادث وإجراءات SOC والأدلة الإجرائية الأمنية.
- خبرة في استخدام تقنيات SIEM.
- القدرة على التحقيق وربط الأحداث الأمنية وتحديد النشاط الخبيث المحتمل.
- فهم التنبيهات الأمنية وتصنيف خطورة الأحداث وعمليات التصعيد.
- خبرة في إنشاء أو صيانة SOPs والأدلة الإجرائية ووثائق الاستجابة للحوادث.
- فهم حالات استخدام SIEM للكشف وقواعد الربط.
- قدرات تحليلية قوية وحل المشكلات واستكشاف الأخطاء.
- مهارات تواصل كتابية وشفوية قوية مع الاهتمام بالتفاصيل.
المهارات الإضافية المرغوبة
- خبرة في دعم تطوير حالات استخدام SIEM أو ضبط الكشف.
- معرفة بتقنيات EDR و SOAR وأمن نقاط النهاية أو تقنيات مراقبة أمنية أخرى.
- الإلمام بإطار MITRE ATT&CK وتقنيات الهجوم الشائعة.
- خبرة في الصيد التهديدي أو التحقيق المتعمق في الحوادث.
- الشهادات ذات الصلة في الأمن السيبراني أو SOC.
عرض النص الأصلي للإعلان
As a Security Delivery Senior Analyst, you will play a key role within Security Operations, taking ownership of security events escalated from L1 analysts and performing deeper triage, investigation and analysis. You will help ensure incidents are handled consistently according to established processes and runbooks, while contributing to stronger playbooks, incident response procedures and SIEM detection use cases.
What You’ll Do
Incident Triage & Investigation
- Take ownership of security incidents and events escalated from L1 analysts and handle them according to defined SOC processes and procedures.
- Perform detailed triage, validation and investigation of detected and escalated security events.
- Analyze and categorize events of interest according to agreed severity levels, escalation criteria and runbooks.
- Correlate available security information to determine the nature, scope and potential impact of suspicious activity.
- Escalate complex or high-risk incidents through the appropriate response channels where required.
- Maintain accurate investigation findings, evidence and incident documentation.
SIEM & Detection Support
- Work closely with SIEM administrators and security engineering teams to support the creation and enhancement of security-monitoring use cases.
- Provide investigation insights that can help identify opportunities to improve existing detection logic.
- Support testing and refinement of SIEM use cases based on operational security requirements.
- Identify potential detection gaps observed during incident investigations and raise them with the appropriate security teams.
SOC Procedures & Continuous Improvement
- Develop, maintain and continuously improve Standard Operating Procedures (SOPs), investigation playbooks and Incident Response plans.
- Help standardize investigation and triage practices to promote consistent incident handling across the SOC.
- Capture lessons learned from investigations and contribute to improvements in operational processes.
- Collaborate with L1 analysts and other security teams to support effective incident handling and knowledge sharing.
What You’ll Need
- Experience working within a Security Operations Center (SOC) or cybersecurity monitoring environment.
- Hands-on experience with security event triage, investigation and incident escalation.
- Good understanding of Incident Response processes, SOC procedures and security runbooks.
- Experience using Security Information and Event Management (SIEM) technologies.
- Ability to investigate and correlate security events and identify potentially malicious activity.
- Understanding of security alerts, event severity classification and escalation processes.
- Experience creating or maintaining SOPs, playbooks and Incident Response documentation.
- Understanding of SIEM detection use cases and correlation rules.
- Strong analytical, troubleshooting and problem-solving capabilities.
- Strong written and verbal communication skills with attention to detail.
Bonus Points If You Have
- Experience supporting SIEM use-case development or detection tuning.
- Exposure to EDR, SOAR, endpoint security or other security-monitoring technologies.
- Familiarity with MITRE ATT&CK and common attack techniques.
- Experience with threat hunting or deeper incident investigation.
- Relevant cybersecurity or SOC certifications.
About Accenture
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us at
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.
رقم الإعلان لدى المصدر: 14715470