سلة تعلن عن وظيفة محلل SOC أول في جدة
Senior SOC Analyst
🏢 سلة (Salla)
تفاصيل الوظيفة
تعلن شركة سلة عن توفر وظيفة محلل SOC أول (L2/L3) في جدة، المملكة العربية السعودية، للانضمام إلى فريق الأمن السيبراني والقيادة بأعمال المراقبة المتقدمة والتحقيق والاستجابة للتهديدات في بيئات السحابة والأجهزة الطرفية والشبكات والحافة.
المهام والمسؤوليات
- إجراء تحليلات متقدمة للتنبيهات (L2/L3) والتحقيقات عبر منصات الأمن الطرفية والشبكات والسحابة والحافة.
- قيادة التحقيقات باستخدام أدوات SIEM للتحقق من الحوادث وتقليل الضوضاء وتحديد الأثر.
- تحليل والاستجابة لأحداث أمن الحافة مثل WAF، DDoS، نشاط البوتات، وتنبيهات الثقة الصفرية.
- العمل كنقطة تصعيد للحوادث المؤكدة ودعم إجراءات الاحتواء والاستجابة.
- إجراء تحليل السبب الجذري وتحقيقات التهديدات وتحديد سلوك المهاجم ونطاق الأثر.
- تصميم وضبط وصيانة قواعد الكشف والمنطق عبر منصات SIEM.
- تحسين تغطية الكشف من خلال مواءمة القواعد مع إطار MITRE ATT&CK.
- توجيه ودعم محللي SOC المبتدئين والإسهام في تطوير المهارات داخل الفريق.
- المساعدة في بناء وصيانة أدلة التحقيق وكتيبات الاستجابة للحوادث.
- التعاون مع قيادة SOC وفريق أمن السحابة وDevOps لتحسين الضوابط الأمنية والرؤية.
- تحقيق تصنيف دقيق للتنبيهات مع تقليل النتائج الإيجابية الخاطئة وتسريع أوقات الاستجابة.
- التحقيق الشامل في الحوادث مع تحليل واضح للسبب الجذري وتوصيات قابلة للتنفيذ.
- تحسين مستمر لتغطية الكشف عبر بيئات السحابة والأجهزة الطرفية والحافة.
- دعم الفرق متعددة الوظائف برؤى وتوصيات أمنية واضحة وفي الوقت المناسب.
الشروط والمتطلبات
- خبرة لا تقل عن 5 سنوات كمحلل SOC (L2/L3).
- درجة البكالوريوس في الأمن السيبراني أو تقنية المعلومات أو علوم الحاسب أو ما يعادلها من الخبرة.
- شهادات مهنية ذات صلة (مثل GCIA، GCIH، CompTIA CySA+، AWS Security Specialty) - يُفضل.
المهارات المطلوبة
- خبرة عملية مع منصات SIEM (مثل Splunk، Graylog أو ما يشابهها).
- القدرة على تصنيف التنبيهات والتحقيق في الحوادث وتصعيدها.
- معرفة قوية ببروتوكولات الشبكات (TCP/IP، DNS، HTTP/HTTPS، BGP).
- خبرة في تحليل سجلات أمن AWS (CloudTrail، CloudWatch، VPC Flow Logs).
- خبرة مع أمن وقت تشغيل الحاويات و Kubernetes (Kubernetes، Amazon EKS).
- خبرة عملية مع أدوات أمن Cloudflare (WAF، DDoS، Bot Management، Zero Trust).
- فهم قوي لأنظمة IDS/IPS، الجدران النارية، البروكسي، وتقنيات DLP.
- خبرة في تحليل السبب الجذري ومراجعات ما بعد الحادث.
- الإلمام بإطار MITRE ATT&CK ومعايير الاستجابة للحوادث NIST.
- خبرة في تطوير وضبط قواعد الكشف على SIEM.
- معرفة بالبرمجة أو الأتمتة (Python، PowerShell، أو Bash).
- فهم أساسي لمفاهيم أمن الذكاء الاصطناعي/التعلم الآلي والمخاطر المرتبطة بـ LLM.
- مهارات تحليلية وتحقيقية قوية في التعامل مع الحوادث.
- القدرة على إيصال النتائج الفنية إلى الجهات غير الفنية.
عرض النص الأصلي للإعلان
About the role
We are looking for a Senior SOC Analyst to lead advanced security monitoring, investigation, and response across our cloud, endpoint, network, and edge environments. This role sits at the L2/L3 level and plays a critical part in incident escalation, detection engineering, and strengthening our overall security posture. You will also act as a mentor to junior analysts and collaborate closely with security, cloud, and engineering teams.
Key responsibilities
- Perform advanced L2/L3 alert triage and investigations across endpoint, network, cloud, and edge security platforms
- Lead investigations using SIEM tools to validate incidents, reduce noise, and determine impact
- Analyze and respond to edge security events including WAF, DDoS, bot activity, and Zero Trust alerts
- Act as an escalation point for confirmed incidents and support containment and response actions
- Conduct root cause analysis and threat investigations, identifying attacker behavior and scope of impact
- Design, tune, and maintain detection rules and logic across SIEM platforms
- Improve detection coverage by aligning rules with the MITRE ATT&CK framework
- Mentor and guide junior SOC analysts and contribute to skill development across the team
- Help build and maintain investigation playbooks and incident response runbooks
- Collaborate with SOC leadership, Cloud Security, and DevOps teams to improve security controls and visibility
What success looks like
- Security alerts are accurately triaged with reduced false positives and faster response times
- Incidents are thoroughly investigated with clear root cause analysis and actionable remediation
- Detection coverage improves continuously across cloud, endpoint, and edge environments
- Junior analysts demonstrate stronger investigation and escalation capabilities
- Cross-functional teams are supported with clear, timely security insights and recommendations
Requirements
- 5+ years of experience as a SOC Analyst (L2/L3)
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience
- Hands-on experience with SIEM platforms (Splunk, Graylog, or similar)
- Experience performing alert triage, incident investigation, and escalation
- Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/HTTPS, BGP)
- Experience analyzing AWS security logs (CloudTrail, CloudWatch, VPC Flow Logs)
- Experience with container and Kubernetes runtime security (Kubernetes, Amazon EKS)
- Hands-on experience with Cloudflare security tools (WAF, DDoS, Bot Management, Zero Trust)
- Strong understanding of IDS/IPS, firewalls, proxies, and DLP technologies
- Experience conducting root cause analysis and post-incident reviews
- Familiarity with MITRE ATT&CK framework and NIST incident response standards
- Experience developing and tuning SIEM detection rules
- Knowledge of scripting or automation (Python, PowerShell, or Bash)
- Foundational understanding of AI/ML security concepts and LLM-related risks
- Strong analytical, investigation, and incident handling skills
- Ability to communicate technical findings to non-technical stakeholders
- Relevant certifications preferred (GCIA, GCIH, CompTIA CySA+, AWS Security Specialty)
المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 10 يونيو 2026
وظائف أخرى لدى سلة