أكسنتشر تعلن عن وظيفة Security Delivery Consultant في الرياض
تفاصيل الوظيفة
أكسنتشر في الرياض تبحث عن مستشار أمني متخصص (Security Delivery Consultant) ليكون خبيرًا في عمليات الأمن والاستجابة للحوادث و SIEM و EDR و NDR.
المهام والمسؤوليات
- تطوير وصيانة وتحسين خطط الاستجابة للحوادث، وسياسات SOC، والعمليات والإجراءات والأدلة التشغيلية.
- قيادة اكتشاف وفرز وتحقيق واحتواء والاستجابة للأحداث والاختراقات الأمنية المعقدة.
- تحليل الأحداث الأمنية والقياسات عن بعد لتحديد طبيعتها ونطاقها وخطورتها وتأثيرها المحتمل على الأعمال.
- تقديم التوجيه الفني والإرشاد لأعضاء الفريق أثناء التحقيقات وأنشطة الاستجابة.
- تنسيق التصعيد وضمان التعامل مع الحوادث وفقًا للإجراءات المقررة ومتطلبات الخدمة.
- المشاركة في الدعم الأمني عند الطلب وخارج ساعات العمل عند الحاجة.
- استخلاص الدروس المستفادة من الحوادث الأمنية وترجمتها إلى تحسينات في الأشخاص والعمليات والتقنيات.
- العمل بشكل وثيق مع مهندسي SIEM وفرق الأمن السيبراني الأخرى لتطوير وتحسين حالات استخدام المراقبة الأمنية.
- إنشاء وضبط قواعد الربط والكشف باستخدام القياسات عن بعد من SIEM و EDR و NDR وغيرها من التقنيات الأمنية.
- تحليل التنبيهات والسجلات والأحداث الأمنية لتحديد النشاط الخبيث والشذوذ السلوكي والتهديدات الناشئة.
- مراجعة منطق الكشف الحالي وتقديم توصيات لزيادة فعالية الكشف وتقليل النتائج الإيجابية الخاطئة.
- تحديد فجوات المراقبة ودعم تطوير سيناريوهات كشف جديدة.
- دعم دمج منصات EDR و NDR مع تقنيات SIEM المؤسسية.
- إدارة وتحسين تقنيات الكشف والاستجابة لنقاط النهاية (EDR) المؤسسية.
- نشر وترقية وصيانة وكلاء EDR عبر بيئات Windows و macOS و Linux.
- مراقبة صحة الوكلاء وتغطيتهم واتصالهم، واستكشاف أخطاء نقاط النهاية التي لا تعمل بشكل صحيح وإصلاحها.
- تطوير وتنفيذ وصيانة سياسات وتكوينات EDR.
- دمج منصات EDR مع SIEM وتقنيات الأمن السيبراني الأخرى.
- مراجعة تكوينات EDR بشكل دوري وتقديم توصيات لتحسين تغطية أمان نقاط النهاية وقدرات الكشف.
- إدارة تذاكر الدعم المتعلقة بالمنصة والتنسيق مع موردي التقنيات حتى الحل.
- إدارة وتحسين تقنيات الكشف والاستجابة للشبكات (NDR) المؤسسية.
- تطوير وتنفيذ وصيانة سياسات وتكوينات وضوابط مراقبة NDR.
- دمج منصات NDR مع SIEM والنظام البيئي الأوسع لتقنيات الأمن.
- تطوير وصيانة قواعد الربط المخصصة باستخدام EDR و NDR وغيرها من القياسات عن بعد.
- مراقبة صحة المنصة واستكشاف المشكلات الفنية ومشكلات الاتصال والتقارير وإصلاحها.
- تقييم تكوينات NDR الحالية بشكل دوري وتقديم توصيات لتعزيز رؤية الشبكة وكشف التهديدات.
- إدارة حالات الدعم الفني مع موردي NDR ومتابعة المشكلات المحددة حتى الحل.
- إنتاج تقارير واضحة وقابلة للتنفيذ حول الاستخبارات السيبرانية والحوادث والعمليات.
- إيصال النتائج الفنية والمخاطر الأمنية وتأثير الأعمال والإجراءات الموصى بها لجماهير متنوعة.
- تقديم الأمور الأمنية السيبرانية المعقدة بوضوح لفرق أمن المعلومات وممثلي الأعمال غير الفنيين والإدارة العليا.
- تقديم القيادة الفنية والتوجيه والتدريب ونقل المعرفة لأعضاء فريق الأمن السيبراني.
- التعاون عبر فرق SOC وهندسة الأمن والبنية التحتية والشبكات والتطبيقات والأعمال.
- دعم مبادرات التحسين المستمر التي تعزز النضج العام وفعالية عمليات الأمن.
الشروط والمتطلبات
- خبرة قوية في عمليات الأمن والاستجابة للحوادث.
- خبرة مثبتة في تطوير أو صيانة خطط الاستجابة للحوادث وسياسات SOC والعمليات والإجراءات والأدلة التشغيلية.
- خبرة عملية في استخدام الأدوات والتقنيات الأمنية للكشف والتحقيق والاستجابة.
- معرفة قوية بتقنيات إدارة الأحداث والمعلومات الأمنية (SIEM).
- خبرة في تطوير وصقل وضبط قواعد الربط أو الكشف لـ SIEM.
- خبرة عملية في إدارة منصات EDR و NDR المؤسسية.
- خبرة في نشر وصيانة وكلاء EDR عبر أنظمة Windows و macOS و Linux.
- خبرة في دمج منصات EDR و NDR مع SIEM وتقنيات الأمن الأخرى.
- فهم قوي لتحليل الأحداث الأمنية وفرز التنبيهات والتحقيق في الحوادث والاستجابة.
- قدرات تحليلية واستكشافية وتنظيمية قوية.
- القدرة على قيادة التحقيقات الفنية وتقديم إرشادات واضحة لأعضاء الفريق.
- مهارات تواصل شفهية وكتابية ممتازة.
- القدرة على إيصال الأمور الأمنية السيبرانية الفنية والاستراتيجية لجماهير متنوعة.
- قدرات قوية في التوثيق وإعداد تقارير الاستخبارات السيبرانية وإدارة أصحاب المصلحة.
- القدرة على المشاركة في الدعم عند الطلب أو خارج ساعات العمل عند الحاجة.
المهارات المطلوبة
- شهادة GIAC Incident Handler (GCIH).
- شهادة GIAC Continuous Monitoring (GMON).
- شهادة GIAC Forensic Analyst (GCFA).
- شهادات معادلة في الاستجابة للحوادث أو عمليات SOC أو التحقيق الرقمي أو المراقبة الأمنية.
- خبرة في دعم بيئة مؤسسية كبيرة أو خدمات الأمن المُدارة.
- الإلمام بمطاردة التهديدات أو استخبارات التهديدات السيبرانية أو التحقيق الرقمي.
- الإلمام بإطار MITRE ATT&CK ومنهجيات هندسة الكشف.
- خبرة مع منصات مثل Splunk أو Microsoft Sentinel أو IBM QRadar أو Microsoft Defender أو CrowdStrike.
عرض النص الأصلي للإعلان
As a Security Delivery Specialist, you will act as a subject-matter expert across Security Operations, Incident Response, SIEM, Endpoint Detection and Response, and Network Detection and Response. You will lead complex security investigations, enhance detection capabilities, administer critical security platforms and guide team members in delivering effective cybersecurity operations.
You will work with security engineering, infrastructure, network and business stakeholders to continuously improve cyber defense processes, technologies and reporting.
What You’ll Do
Incident Response & SOC Operations
- Develop, maintain and continuously improve Incident Response plans, SOC policies, processes, procedures and operational playbooks.
- Lead the detection, triage, investigation, containment and response to complex cybersecurity events and incidents.
- Analyze security events and telemetry to determine their nature, scope, severity and potential business impact.
- Provide technical direction and guidance to team members throughout investigations and response activities.
- Coordinate escalations and ensure incidents are handled according to established procedures and service requirements.
- Participate in on-call and after-hours security support when required.
- Identify lessons learned from security incidents and translate them into improvements across people, process and technology.
SIEM & Detection Engineering
- Work closely with SIEM engineers and other cybersecurity teams to develop, refine and optimize security-monitoring use cases.
- Create and tune correlation and detection rules using telemetry from SIEM, EDR, NDR and other security technologies.
- Analyze alerts, logs and security events to identify malicious activity, behavioral anomalies and emerging threats.
- Review existing detection logic and recommend improvements to increase detection effectiveness and reduce false positives.
- Identify monitoring gaps and support the development of new detection scenarios.
- Support the integration of EDR, NDR and other security platforms with enterprise SIEM technologies.
EDR Administration
- Administer and optimize enterprise Endpoint Detection and Response technologies.
- Deploy, upgrade and maintain EDR agents across Windows, macOS and Linux environments.
- Monitor agent health, coverage and connectivity, and troubleshoot endpoints that are not reporting correctly.
- Develop, implement and maintain EDR policies and configurations.
- Integrate EDR platforms with SIEM and other cybersecurity technologies.
- Review EDR configurations periodically and recommend enhancements to improve endpoint security coverage and detection capabilities.
- Manage platform-related support tickets and coordinate with technology vendors through resolution.
NDR Administration
- Administer and optimize enterprise Network Detection and Response technologies.
- Develop, implement and maintain NDR policies, configurations and monitoring rules.
- Integrate NDR platforms with SIEM and the broader security technology ecosystem.
- Develop and maintain custom correlation rules using EDR, NDR and other security telemetry.
- Monitor platform health and troubleshoot technical, connectivity and reporting issues.
- Periodically assess existing NDR configurations and recommend improvements to enhance network visibility and threat detection.
- Manage technical support cases with NDR vendors and follow identified issues through to resolution.
Cyber Intelligence, Reporting & Leadership
- Produce clear, actionable cyber intelligence, incident and operational reports.
- Communicate technical findings, security risks, business impact and recommended actions to varied audiences.
- Present complex cybersecurity matters clearly to information security teams, non-technical business representatives and senior management.
- Provide technical leadership, coaching and knowledge-sharing to cybersecurity team members.
- Collaborate across SOC, security engineering, infrastructure, network, application and business teams.
- Support continuous improvement initiatives that strengthen the overall maturity and effectiveness of security operations.
What You’ll Need
- Strong experience in Security Operations and Incident Response.
- Demonstrated experience developing or maintaining Incident Response plans, SOC policies, processes, procedures and playbooks.
- Hands-on experience using security tools and technologies for detection, investigation and response.
- Strong knowledge of Security Information and Event Management technologies.
- Experience developing, refining and tuning SIEM correlation or detection rules.
- Hands-on experience administering enterprise EDR and NDR platforms.
- Experience deploying and maintaining EDR agents across Windows, macOS and Linux.
- Experience integrating EDR and NDR platforms with SIEM and other security technologies.
- Strong understanding of security-event analysis, alert triage, incident investigation and response.
- Strong analytical, troubleshooting and organizational capabilities.
- Ability to lead technical investigations and provide clear guidance to team members.
- Excellent verbal and written communication skills.
- Ability to communicate both technical and strategic cybersecurity matters to diverse audiences.
- Strong documentation, cyber intelligence reporting and stakeholder-management capabilities.
- Ability to participate in on-call or after-hours support when required.
Bonus Points If You Have
- GIAC Certified Incident Handler (GCIH)
- GIAC Continuous Monitoring Certification (GMON)
- GIAC Certified Forensic Analyst (GCFA)
- Equivalent certifications in Incident Response, SOC operations, digital forensics or security monitoring.
- Experience supporting a large-scale enterprise or Managed Security Services environment.
- Exposure to threat hunting, cyber threat intelligence or digital forensics.
- Familiarity with MITRE ATT&CK and detection-engineering methodologies.
- Experience with platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Microsoft Defender or CrowdStrike.
About Accenture
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us at
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.
رقم الإعلان لدى المصدر: 14715395