📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

سلة تعلن عن وظيفة محلل SOC أول في جدة

Senior SOC Analyst
🏢 سلة (Salla)
🕒 نُشرت: (منذ 6 أشهر) 📍 جدة وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة سلة عن توفر وظيفة محلل SOC أول (L2/L3) في جدة، المملكة العربية السعودية، للانضمام إلى فريق الأمن السيبراني والقيادة بأعمال المراقبة المتقدمة والتحقيق والاستجابة للتهديدات في بيئات السحابة والأجهزة الطرفية والشبكات والحافة.

المهام والمسؤوليات

  • إجراء تحليلات متقدمة للتنبيهات (L2/L3) والتحقيقات عبر منصات الأمن الطرفية والشبكات والسحابة والحافة.
  • قيادة التحقيقات باستخدام أدوات SIEM للتحقق من الحوادث وتقليل الضوضاء وتحديد الأثر.
  • تحليل والاستجابة لأحداث أمن الحافة مثل WAF، DDoS، نشاط البوتات، وتنبيهات الثقة الصفرية.
  • العمل كنقطة تصعيد للحوادث المؤكدة ودعم إجراءات الاحتواء والاستجابة.
  • إجراء تحليل السبب الجذري وتحقيقات التهديدات وتحديد سلوك المهاجم ونطاق الأثر.
  • تصميم وضبط وصيانة قواعد الكشف والمنطق عبر منصات SIEM.
  • تحسين تغطية الكشف من خلال مواءمة القواعد مع إطار MITRE ATT&CK.
  • توجيه ودعم محللي SOC المبتدئين والإسهام في تطوير المهارات داخل الفريق.
  • المساعدة في بناء وصيانة أدلة التحقيق وكتيبات الاستجابة للحوادث.
  • التعاون مع قيادة SOC وفريق أمن السحابة وDevOps لتحسين الضوابط الأمنية والرؤية.
  • تحقيق تصنيف دقيق للتنبيهات مع تقليل النتائج الإيجابية الخاطئة وتسريع أوقات الاستجابة.
  • التحقيق الشامل في الحوادث مع تحليل واضح للسبب الجذري وتوصيات قابلة للتنفيذ.
  • تحسين مستمر لتغطية الكشف عبر بيئات السحابة والأجهزة الطرفية والحافة.
  • دعم الفرق متعددة الوظائف برؤى وتوصيات أمنية واضحة وفي الوقت المناسب.

الشروط والمتطلبات

  • خبرة لا تقل عن 5 سنوات كمحلل SOC (L2/L3).
  • درجة البكالوريوس في الأمن السيبراني أو تقنية المعلومات أو علوم الحاسب أو ما يعادلها من الخبرة.
  • شهادات مهنية ذات صلة (مثل GCIA، GCIH، CompTIA CySA+، AWS Security Specialty) - يُفضل.

المهارات المطلوبة

  • خبرة عملية مع منصات SIEM (مثل Splunk، Graylog أو ما يشابهها).
  • القدرة على تصنيف التنبيهات والتحقيق في الحوادث وتصعيدها.
  • معرفة قوية ببروتوكولات الشبكات (TCP/IP، DNS، HTTP/HTTPS، BGP).
  • خبرة في تحليل سجلات أمن AWS (CloudTrail، CloudWatch، VPC Flow Logs).
  • خبرة مع أمن وقت تشغيل الحاويات و Kubernetes (Kubernetes، Amazon EKS).
  • خبرة عملية مع أدوات أمن Cloudflare (WAF، DDoS، Bot Management، Zero Trust).
  • فهم قوي لأنظمة IDS/IPS، الجدران النارية، البروكسي، وتقنيات DLP.
  • خبرة في تحليل السبب الجذري ومراجعات ما بعد الحادث.
  • الإلمام بإطار MITRE ATT&CK ومعايير الاستجابة للحوادث NIST.
  • خبرة في تطوير وضبط قواعد الكشف على SIEM.
  • معرفة بالبرمجة أو الأتمتة (Python، PowerShell، أو Bash).
  • فهم أساسي لمفاهيم أمن الذكاء الاصطناعي/التعلم الآلي والمخاطر المرتبطة بـ LLM.
  • مهارات تحليلية وتحقيقية قوية في التعامل مع الحوادث.
  • القدرة على إيصال النتائج الفنية إلى الجهات غير الفنية.
عرض النص الأصلي للإعلان

About the role
We are looking for a Senior SOC Analyst to lead advanced security monitoring, investigation, and response across our cloud, endpoint, network, and edge environments. This role sits at the L2/L3 level and plays a critical part in incident escalation, detection engineering, and strengthening our overall security posture. You will also act as a mentor to junior analysts and collaborate closely with security, cloud, and engineering teams.

Key responsibilities

  • Perform advanced L2/L3 alert triage and investigations across endpoint, network, cloud, and edge security platforms
  • Lead investigations using SIEM tools to validate incidents, reduce noise, and determine impact
  • Analyze and respond to edge security events including WAF, DDoS, bot activity, and Zero Trust alerts
  • Act as an escalation point for confirmed incidents and support containment and response actions
  • Conduct root cause analysis and threat investigations, identifying attacker behavior and scope of impact
  • Design, tune, and maintain detection rules and logic across SIEM platforms
  • Improve detection coverage by aligning rules with the MITRE ATT&CK framework
  • Mentor and guide junior SOC analysts and contribute to skill development across the team
  • Help build and maintain investigation playbooks and incident response runbooks
  • Collaborate with SOC leadership, Cloud Security, and DevOps teams to improve security controls and visibility

What success looks like

  • Security alerts are accurately triaged with reduced false positives and faster response times
  • Incidents are thoroughly investigated with clear root cause analysis and actionable remediation
  • Detection coverage improves continuously across cloud, endpoint, and edge environments
  • Junior analysts demonstrate stronger investigation and escalation capabilities
  • Cross-functional teams are supported with clear, timely security insights and recommendations

Requirements

  • 5+ years of experience as a SOC Analyst (L2/L3)
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience
  • Hands-on experience with SIEM platforms (Splunk, Graylog, or similar)
  • Experience performing alert triage, incident investigation, and escalation
  • Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/HTTPS, BGP)
  • Experience analyzing AWS security logs (CloudTrail, CloudWatch, VPC Flow Logs)
  • Experience with container and Kubernetes runtime security (Kubernetes, Amazon EKS)
  • Hands-on experience with Cloudflare security tools (WAF, DDoS, Bot Management, Zero Trust)
  • Strong understanding of IDS/IPS, firewalls, proxies, and DLP technologies
  • Experience conducting root cause analysis and post-incident reviews
  • Familiarity with MITRE ATT&CK framework and NIST incident response standards
  • Experience developing and tuning SIEM detection rules
  • Knowledge of scripting or automation (Python, PowerShell, or Bash)
  • Foundational understanding of AI/ML security concepts and LLM-related risks
  • Strong analytical, investigation, and incident handling skills
  • Ability to communicate technical findings to non-technical stakeholders
  • Relevant certifications preferred (GCIA, GCIH, CompTIA CySA+, AWS Security Specialty)
المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 10 يونيو 2026

وظائف أخرى لدى سلة