📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة أخصائي عمليات أمنية شاغرة لدى تمكين التقنية بالرياض

Security Operations Specialist
🏢 Tamkeen Technologies
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

Tamkeen Technologies تبحث عن متخصص عمليات أمنية (SOC L3 Analyst) للانضمام إلى فريق عمليات الأمن في الرياض، السعودية. المرشح المثالي يمتلك خبرة قوية في عمليات الأمن، الاستجابة للحوادث، صيد التهديدات، والتحقيقات الأمنية المتقدمة.

المهام والمسؤوليات

  • قيادة التحقيق والاستجابة للحوادث السيبرانية عالية الشدة والتعقيد.
  • إجراء تحقيقات متقدمة في الاستجابة للحوادث عبر نقاط النهاية، الخوادم، الشبكات، البيئات السحابية والبنية التحتية للهوية.
  • تحليل البرمجيات الخبيثة، برمجيات الفدية، آليات الثبات، الحركة الجانبية، تصعيد الصلاحيات، وسرقة البيانات بالتفصيل.
  • إجراء صيد التهديدات عبر SIEM وEDR وNDR والشبكة وغيرها من تليمترية الأمن.
  • تحليل وربط الأحداث الأمنية من مصادر متعددة لتحديد الجدول الزمني للهجوم والسبب الجذري والنطاق والتأثير.
  • إجراء تحليل للبرمجيات الخبيثة والملفات المشبوهة باستخدام أدوات الطب الشرعي والأمن المناسبة.
  • تطوير وصيانة قواعد كشف متقدمة في SIEM، وبحوث الارتباط، وحالات الاستخدام الأمني.
  • تحسين قدرات الكشف الحالية بناءً على نتائج الحوادث والتهديدات الناشئة.
  • إجراء صيد استباقي للتهديدات بناءً على مؤشرات الاختراق (IOCs) وتقنيات MITRE ATT&CK.
  • تقديم دعم التصعيد الفني لمحللي SOC من المستوى الأول والثاني.
  • إعداد تقارير تحقيق مفصلة للحوادث، وتحليل السبب الجذري، وتوصيات المعالجة.
  • المشاركة في أنشطة الاستجابة للحوادث الكبرى والتنسيق مع فرق تقنية المعلومات والبنية التحتية والشبكات والأمن.
  • دعم أنشطة احتواء الحوادث والاستئصال والتعافي.
  • إجراء مراجعات ما بعد الحوادث وتحديد فرص تحسين الضوابط الأمنية وقدرات الكشف.
  • الحفاظ على إجراءات الاستجابة للحوادث ودفاتر اللعب ومنهجيات التحقيق وتطويرها.
  • دعم تحسين المراقبة الأمنية عبر SIEM وEDR وNDR وSOAR وجدار الحماية وWAF وغيرها.
  • تقديم توصيات فنية لتحسين نضج المراقبة الأمنية والاستجابة للحوادث بشكل عام.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو أمن المعلومات أو مجال ذي صلة.
  • خبرة لا تقل عن 5 سنوات في SOC أو الاستجابة للحوادث أو دور أمن سيبراني ذي صلة.
  • خبرة عملية قوية في عمليات SOC من المستوى الثالث والتحقيق في الحوادث.
  • فهم قوي لأنظمة تشغيل ويندوز ولينكس وأدلتها الجنائية.
  • خبرة في التحقيق في البرمجيات الخبيثة، برمجيات الفدية، التصيد، اختراق بيانات الاعتماد، الحركة الجانبية، الثبات، وتصعيد الصلاحيات.
  • خبرة قوية مع منصات SIEM وEDR.
  • خبرة مع أدوات الطب الشرعي والتحقيق مثل Volatility وKAPE وFTK وVelociraptor أو أدوات مماثلة.
  • خبرة مع خدمات الأمن المُدارة وإدارة العملاء الخارجيين مرغوب فيها بشدة.
  • الشهادات ذات الصلة مثل GIAC GCIH أو GCFA أو ما يعادلها مفضلة.
عرض النص الأصلي للإعلان

Job Summary

We are looking for an experienced SOC L3 Analyst to join our Security Operations team. The ideal candidate will have strong experience in Security Operations, Incident Response, Threat Hunting, and advanced security investigations.

The role will be responsible for handling complex and high-severity security incidents, conducting advanced investigations, performing digital forensics, developing detection capabilities, and providing technical guidance to SOC L1/L2 analysts.


Key Responsibilities:

  • Lead the investigation and response to high-severity and complex cybersecurity incidents.
  • Perform advanced "Incident Response" investigations across endpoints, servers, networks, cloud environments, and identity infrastructure.
  • Conduct detailed analysis of malware, ransomware, persistence mechanisms, lateral movement, privilege escalation, and data exfiltration.
  • Perform threat hunting across SIEM, EDR, NDR, network, and other security telemetry.
  • Analyze and correlate security events from multiple sources to determine the attack timeline, root cause, scope, and impact.
  • Conduct malware and suspicious-file analysis using appropriate forensic and security tools.
  • Develop and maintain advanced SIEM detection rules, correlation searches, and security use cases.
  • Improve existing detection capabilities based on incident findings and emerging threats.
  • Conduct proactive threat hunting based on IOCs, TTPs, threat intelligence, and MITRE ATT&CK techniques.
  • Provide technical escalation support to SOC L1 and L2 analysts.
  • Develop detailed incident investigation reports, root cause analysis, and remediation recommendations.
  • Participate in major incident response activities and coordinate with relevant IT, infrastructure, network, and security teams.
  • Support incident containment, eradication, and recovery activities.
  • Conduct post-incident reviews and identify opportunities to improve security controls and detection capabilities.
  • Maintain and improve IR procedures, playbooks, and investigation methodologies.
  • Support security monitoring improvements across SIEM, EDR, NDR, SOAR, firewall, WAF, and other security technologies.
  • Provide technical recommendations to improve overall security monitoring and incident response maturity.



Qualifications:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related field.
  • 5+ years of experience in SOC, Incident Response, or a related cybersecurity role.
  • Strong hands-on experience in SOC L3 operations and incident investigation.
  • Strong understanding of Windows and Linux operating systems and their forensic artifacts.
  • Experience investigating malware, ransomware, phishing, credential compromise, lateral movement, persistence, and privilege escalation.
  • Strong experience with SIEM/EDR platforms.
  • Experience with forensic and investigation tools such as Volatility, KAPE, FTK, Velociraptor, or similar tools.
  • Experience with managed security services and external customer management is highly desirable.
  • Relevant certifications such as GIAC GCIH, GCFA, or equivalent are preferred.


المصدر: LinkedIn - أُضيفت للموقع في 24 أغسطس 2026

وظائف أخرى لدى Tamkeen Technologies