وظيفة محلل SOC أول L3 لدى TopNet في الرياض
Senior SOC Analyst L3
🏢 TopNet
تفاصيل الوظيفة
تقدم شركة TopNet فرصة للانضمام إلى فريقها كـ Senior SOC Analyst L3 (قائد فريق SOC) في الرياض. نحن نبحث عن خبير تقني عالي المهارة ليكون لاعبًا رئيسيًا في خدمات aiSOCaaS المُدارة على مدار الساعة.
المهام والمسؤوليات
- قيادة التحقيقات المعقدة، تحليل الأسباب الجذرية، والاستجابة للحوادث المنسقة عبر بيئات SOC متعددة المستأجرين مع سيناريوهات نشر متنوعة للعملاء.
- إدارة حملات الصيد الاستباقي للتهديدات وتمارين الفريق الأرجواني باستخدام MITRE ATT&CK والنمذجة الديناميكية للتهديدات لكشف أساليب الخصوم الناشئة.
- تصميم وضبط محتوى الكشف المتقدم، قواعد الاستجابة، والأتمتة لرفع كفاءة SOC وتقليل متوسط وقت الكشف/الاستجابة (MTTD/MTTR).
- توجيه رفع مهارات المحللين من المستويين L1/L2، والعمل كنقطة تصعيد نهائية وضابط جودة وخبير موضوعي (SME) في التحقيق الرقمي، تحليل البرمجيات الخبيثة، وحوادث أمن السحابة.
- قيادة التحسين المستمر، تكامل الأدوات، والمواءمة مع المتطلبات التنظيمية السعودية (NCA، SAMA) وأفضل الممارسات العالمية (NIST، ISO 27001).
- قيادة حوادث المستوى P1/P2 من البداية إلى النهاية: النطاق، الطب الشرعي، الاحتواء، الاستئصال، الاسترداد، والتواصل التنفيذي.
- إجراء تحليل جنائي شامل للمضيف، الشبكة، والسحابة باستخدام أدوات EDR، حزم البيانات، تحليل الذاكرة/السجل، وربط السجلات لتحديد التسلسل الزمني والأسباب الجذرية.
- التخطيط وتنفيذ عمليات صيد استباقية قائمة على الفرضيات عبر السجلات، التدفقات، UEBA، وبيانات VA؛ وتحويل النتائج إلى كشفيات وسرديات مخاطر جديدة.
- تطوير وصيانة قواعد مخصصة، نماذج DTM، خطوط أساس UEBA، وقواعد SOAR؛ والتحقق من الفعالية عبر اختبارات الوحدة ومحاكاة الفريق الأرجواني.
- ضبط تحليلات SIEM/XDR، إثراء التنبيهات بخلاصات ذكاء التهديدات، ودمج مصادر البيانات الخارجية (واجهات برمجة السحابة، IDS، VA، FIM، إلخ).
- القيادة المستمرة لتحسين استيعاب البيانات من خلال دمج مصادر سجلات وخلاصات أمنية جديدة، وضمان التكامل السلس مع منصة SOC وأدواتها الداعمة.
- تحسين وصيانة التكاملات الحالية، واجهات البرمجة (APIs)، والمجمعات لتعظيم الرؤية، إثراء السياق، وإخلاص الكشف.
- تدقيق والتحقق من أن جميع القياسات عن بُعد التي تم استيعابها تلبي متطلبات نطاق تسجيل السجلات والاحتفاظ بها وسلامتها وفقًا لـ NCA MSOC؛ وتنسيق المعالجة مع العميل وأصحاب المصلحة الداخليين.
- ربط النتائج مع ECC/CCC/MSOC الخاص بـ NCA و SAMA CSF والضوابط الدولية؛ وإيجاز رؤساء أمن المعلومات (CISOs) والمراجعين؛ وإعداد تقارير ما بعد الحدث التنفيذية والفنية.
- تقديم التوجيه الرسمي، تمار الطاولة، تحديثات قواعد التشغيل، ومختبرات تدريبية للمحللين المبتدئين؛ وقيادة مبادرات تحسين الخدمة المستمرة.
- تقييم ناقلات الهجمات الناشئة، أدوات الأمن، وتقنيات AI/ML؛ وبناء نماذج أولية وتجريب قدرات جديدة ضمن خارطة طريق TopNet لل SOC.
الشروط والمتطلبات
- إجادة اللغتين الإنجليزية والعربية تحدثًا وكتابة.
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو مجال ذي صلة (يفضّل الماجستير).
- شهادات مهنية متقدمة (اثنتان على الأقل) مع تقديم رموز التحقق: مثل GSE, GCFA, GNFA, GCIH, GCIA, GREM, GDAT, GMON, GXPN, OSCP, OSCE3, OSEP, CISSP-ISSAP, CISSP, CISM, CCISO, CCSK, CCSP وغيرها.
- خبرة لا تقل عن 5 سنوات في العمل المخصص في SOC/IR مع مهام محلل رئيسي موثقة في سجل التأمينات الاجتماعية (GOSI).
- خبرة مثبتة في استخدام مجموعة شاملة من أدوات SOC مثل SIEM/XDR (Splunk ES, Microsoft Sentinel, Elastic, Google Chronicle, IBM QRadar, LogRhythm)، SOAR (Cortex XSOAR, Swimlane, Siemplify)، EDR/NDR وIDS (CrowdStrike Falcon, SentinelOne, Carbon Black, Sophos, Trend Micro, Palo Alto Cortex XDR, Darktrace وغيرها)، جدران الحماية (Palo Alto NGFW, Fortinet FortiGate, ...)، أدوات التحقيق الجنائي (EnCase, FTK, Velociraptor, Autopsy, Volatility, ...)، تحليل البرمجيات الخبيثة والهندسة العكسية، ذكاء التهديدات وبيئة الحماية، إدارة الثغرات (Tenable.sc, Qualys VMDR, Rapid7 InsightVM)، وأمن السحابة/الحاويات.
- خبرة في تطوير أو ضبط محتوى الكشف، قواعد الاستجابة، الأتمتة، وتكاملات SOC.
- معرفة معمقة بدواخل أنظمة Windows وLinux وmacOS، وبروتوكولات TCP/IP وHTTP وDNS، وبروتوكولات المصادقة، ومنصات السحابة (AWS/Azure/GCP)، والحاويات، ومفاهيم الثقة صفرية.
- خبرة في تصميم منطق الكشف باستخدام Sigma وYARA واستعلامات Kusto/Elastic؛ وإتقان سير العمل الجنائي.
- مهارات قوية في كتابة النصوص البرمجية بلغة Python أو PowerShell أو Bash لأتمتة SOC وتحليل البيانات المخصص.
- إتقان تطبيق MITRE ATT&CK، سلسلة القتل السيبراني، NIST 800-61، والأطر السعودية المحلية.
- مهارات شخصية: إعداد التقارير والعروض التقديمية على المستوى التنفيذي، إدارة الأزمات، التعاون بين الفرق، التطوير المهني الذاتي.
المهارات المطلوبة
- خبرة عملية في نشر تقنيات الخداع / Honeypot (Thinkst Canary, Illusive, Acalvio) لتعزيز كشف الحركة الجانبية.
- المراقبة الأمنية للأجهزة المحمولة عبر منصات MDM/MTP (Jamf Protect, Microsoft Intune, CrowdStrike Mobile).
- خبرة في مراقبة أمن السحابة (AWS, Azure, GCP) والبيئات المحتواة.
- إلمام بأدوات DevSecOps / IaC (Terraform, Ansible, GitHub Actions, Jenkins) والتليمترية الأمنية الخاصة بها.
- خبرة في مراقبة أمن OT/ICS والبروتوكولات الصناعية الملكية.
- خبرة في استخدام خطوط أنابيب ML/UEBA (Jupyter/Spark, SageMaker, Vertex AI) للكشف عن التهديدات المستندة إلى الشذوذ.
- معرفة عملية بهندسة الثقة صفرية وأدوات ZTNA (Zscaler ZPA, Google BeyondCorp, Netskope Private Access).
- خبرة عمل مع الضوابط والأطر والمبادئ التوجيهية للأمن السيبراني مع التركيز على اللوائح المحلية مثل NCA ECC وNCA CCC وNCA MSOC وSAMA CSF وغيرها من التوجيهات الإقليمية، بالإضافة إلى المعايير الدولية (NIST, ISO/IEC 27001, PCI-DSS, HIPAA).
- كفاءة في ربط الحوادث بأنظمة الخصوصية والامتثال المحلية والعالمية للاستعداد للإخطار بالاختراق.
عرض النص الأصلي للإعلان
We are seeking a highly skilled subject‑matter expert Senior Analyst (L3, SOC Lead) to serve as a technical key player for our 24 × 7 managed aiSOCaaS offering. In this hands‑on leadership technical role, your tasks include:
- Lead complex investigations, root‑cause analysis, and coordinated incident response across multi‑tenant SOC solutions with client various deployment scenarios.
- Drive proactive threat‑hunting campaigns and purple‑team exercises that leverage MITRE ATT&CK and dynamic threat‑modeling to uncover emerging adversary tradecraft.
- Architect & tune advanced detection content, response playbooks, and automations to continually raise SOC efficacy and reduce MTTD/MTTR.
- Mentor and up‑skill L1/L2 analysts, acting as final escalation point, quality gate, and subject‑matter expert (SME) for digital forensics, malware analysis, and cloud security incidents.
- Champion continuous improvement, tooling integration, and governance alignment with Saudi regulatory mandates (NCA, SAMA) and global best practice (NIST, ISO 27001).
Responsibilities:
- Major‐Incident Command & Response - Own P1/P2 incidents end‑to‑end: scoping, forensics, containment, eradication, recovery, and executive communication.
- Deep‑Dive Forensics - Perform host, network, and cloud forensics leveraging EDR artifacts, packet captures, memory/registry analysis, and log correlation to establish timelines and root‑cause.
- Advanced Threat‑Hunting - Plan and execute hypothesis‑driven hunts across logs, flows, UEBA, and VA data; pivot findings into new detections and risk narratives.
- Detection Engineering - Develop/maintain custom rules, DTM models, UEBA baselines, and SOAR playbooks; validate efficacy through unit testing and purple‑team simulations.
- Content & Platform Optimization - Fine‑tune SIEM/XDR analytics, enrich alerts with relevant threat‑intelligence feeds, and integrate external data sources (cloud APIs, IDS, VA, FIM, etc.).
- Integration Enhancement & Onboarding - Drive continuous improvement of data ingestion by onboarding new log sources and security feeds, ensuring seamless integration with the SOC platform and supporting SOC tooling.
- Integration Optimization - Refine and maintain existing integrations, APIs, and collectors to maximize visibility, context enrichment, and detection fidelity.
- Log Source Compliance Governance - Audit and validate that all ingested telemetry meets NCA MSOC logging scope, retention, and integrity requirements; coordinate remediation with client and internal stakeholders.
- Regulatory & Client Advisory - Map findings to NCA ECC/CCC/MSOC, SAMA CSF, and international controls; brief CISOs and auditors; author executive and technical post‑mortems.
- Knowledge Leadership - Deliver formal mentorship, tabletop drills, run‑book updates, and training labs for junior analysts; spearhead continuous service‑improvement initiatives.
- Innovation & R&D - Evaluate emerging attack vectors, security tools, and AI/ML techniques; prototype and pilot new capabilities within TopNet’s SOC roadmap.
Required:
- Language: Fluent English & Arabic.
- Education: Bachelor’s in Cybersecurity, Computer Science, or related field (Master’s a plus).
- Certifications (provide verification codes): Minimum two advanced credentials such as GSE, GCFA, GNFA, GCIH, GCIA, GREM, GDAT, GMON, GXPN, OSCP, OSCE3, OSEP, CISSP-ISSAP, CISSP, CISM, CCISO, CCSK, CCSP, etc.
- Experience: 5+ years dedicated SOC/IR work with demonstrable lead‑analyst duties (visible in GOSI record).
- Platform Expertise: Demonstrated experience with a comprehensive suite of SOC tooling, such as but not limited to SIEM/XDR (Splunk ES, Microsoft Sentinel, Elastic, Google Chronicle, IBM QRadar, LogRhythm), SOAR & Automation (Cortex XSOAR, Swimlane, Siemplify), EDR/NDR & IDS (CrowdStrike Falcon, SentinelOne, Carbon Black, Sophos, Trend Micro, Palo Alto Cortex XDR, Darktrace, etc.), Firewalls & Network Security (Palo Alto NGFW, Fortinet FortiGate, ...), Forensics & IR (EnCase, FTK, Velociraptor, Autopsy, Volatility,...), Malware & Reverse‑Engineering, Threat‑Intel & Sandbox, Vulnerability & Exposure Management (Tenable.sc, Qualys VMDR, Rapid7 InsightVM), and Cloud/Container Security.
- Experience developing or tuning detection content, response playbooks, automations, SOC integrations.
- In‑depth knowledge of Windows, Linux, macOS internals, TCP/IP, HTTP, DNS, authentication protocols, cloud platforms (AWS/Azure/GCP), containers, and zero‑trust concepts, etc.
- Experience designing detection logic using Sigma, YARA, and Kusto/Elastic queries; proficiency with forensic workflows.
- Strong scripting ability in Python, PowerShell, or Bash for SOC automation and custom data‑parsing.
- Framework Fluency: Proven application of MITRE ATT&CK, cyber kill chain, NIST 800‑61, and local Saudi frameworks.
- Soft Skills: Executive‑level reporting & presentation, crisis management, cross‑team collaboration, self‑driven professional development.
Strong plus to have:
- Hands‑on experience deploying deception / honeypot technologies (Thinkst Canary, Illusive, Acalvio) to enhance lateral‑movement detection.
- Security monitoring of mobile endpoints via MDM/MTP platforms (Jamf Protect, Microsoft Intune, CrowdStrike Mobile).
- Exposure to cloud‑security monitoring (AWS, Azure, GCP) and containerized environments.
- Familiarity with DevSecOps / IaC toolchains (Terraform, Ansible, GitHub Actions, Jenkins) and their security telemetry.
- Exposure to OT/ICS security monitoring and proprietary industrial protocols.
- Experience leveraging ML/UEBA pipelines (Jupyter/Spark, SageMaker, Vertex AI) for anomaly‑driven threat detection.
- Practical knowledge of zero‑trust architecture & ZTNA tooling (Zscaler ZPA, Google BeyondCorp, Netskope Private Access).
- Work experience with cybersecurity controls, frameworks, and guidelines, with primary emphasis on local regulations such as NCA ECC, NCA CCC, NCA MSOC, SAMA CSF, and other regional directives, as well as international standards (e.g., NIST, ISO/IEC 27001, PCI‑DSS, HIPAA, etc).
- Competence mapping incidents to local and global privacy & compliance regimes for breach‑notification readiness.
If you thrive on dissecting sophisticated attacks, crafting elegant countermeasures, and elevating people and processes around you-join us and help redefine cyber‑resilience in the Kingdom.
المصدر: LinkedIn - أُضيفت للموقع في 20 أغسطس 2026