Cybersecurity Threat Intelligence Analyst (Saudi Only)

Dar Al Tamleek

Jeddah

On-site

SAR 180,000 - 300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A financial services company in Jeddah seeks a Cybersecurity Threat Intelligence Analyst. The role involves analyzing cybersecurity threats, monitoring activities, and ensuring compliance with security frameworks. A Bachelor's degree in Cybersecurity or IT is required, along with 1-2 years of relevant experience. This position offers an opportunity to significantly impact the organization's security landscape.

Qualifications

  • 1-2 years of relevant post-qualification experience preferred.
  • Bachelor’s degree in Cybersecurity, Computer Science, or IT required.

Responsibilities

  • Collect and analyze cybersecurity threat information.
  • Conduct research on cybersecurity threats.
  • Monitor and report on validated threat activities.
  • Provide real-time cyber threat intelligence.
  • Identify information gaps and assess implications for the organization.
  • Prepare and deliver briefs on specific threats to the organization.
  • Evaluate threat decision-making processes.
  • Identify principal threats to known vulnerabilities.
  • Monitor changes in threat dispositions, tactics, and objectives.
  • Monitor validated threat activities and report findings.
  • Monitor open-source sources for hostile content related to interests.
  • Provide real-time intelligence during incidents and exercises.
  • Support planning of cybersecurity strategy and resources.

Skills

Cybersecurity analysis
Threat intelligence
Incident handling
Network analysis
Compliance knowledge

Education

Bachelor’s degree in Cybersecurity or related discipline

Tools

SIEM
EDR
SOAR
Packet analysis tools

Job description

Job overview

Cybersecurity Threat Intelligence Analyst (Saudi Only) — Jeddah

Job summary

Collects and analyzes multi-source information about cybersecurity threats to develop deep understanding and awareness of cyber threats and actors’ Tactics, Techniques and Procedures (TTPs), and to derive and report indicators that help organizations detect and predict cyber incidents and protect systems and networks from cyber threats. Proactively searches for undetected threats in networks and systems, identifies Indicators of Compromise (IOCs), and recommends mitigation plans. Monitor, validate, and report threat activities, and continuously ensure compliance with SAMA CSF, SAMA CTIP, and NCA-related controls.

Responsibilities
  • Conduct research and analysis with regard to cybersecurity/information security threats.
  • Track the status of requests for information in line with the organization’s policies.
  • Use knowledge of threat actor’s activities to inform the organization’s response to a cyber-incident, and to build a common understanding of the organization’s current cyber risk profile.
  • Coordinate, validate, and manage the organization’s cyber threat intelligence sources and feeds.
  • Identify information gaps in threat intelligence and assess their implications for the organization.
  • Prepare and deliver briefs on specific threats to the organization.
  • Evaluate threat decision-making processes.
  • Identify the principal threats to the organization’s known vulnerabilities.
  • Identify threat tactics and methodologies.
  • Monitor and report changes in threat dispositions, activities, tactics, capabilities, and objectives.
  • Monitor and report on validated threat activities.
  • Monitor open-source websites for hostile content directed towards organizational or partner interests.
  • Monitor and report on threat actor activities to fulfill the organization’s threat intelligence and reporting requirements.
  • Use expertise on threat actors and activities to support activities to plan and develop the organization’s cybersecurity strategy and resources.
  • Provide information and assessments of threat actors to assist stakeholders in planning and executing cybersecurity activities.
  • Provide real-time cyber threat intelligence analysis and support during cybersecurity incidents and exercises.
  • Monitor cyber threat intelligence feeds and report significant network events and intrusions.
  • Provide current intelligence support to critical internal/external stakeholders as appropriate.
  • Provide evaluation and feedback necessary for improving intelligence production, intelligence reporting, collection requirements, and operations.
  • Provide timely notice of imminent or hostile intentions or activities that may impact organization objectives, resources, or capabilities.
  • Utilize the existing related security tools, SIEM, SOAR, EDR, NDR, Threat Management solutions, and Sandboxing, for day-to-day activities and prepare knowledge base articles for investigation cases.
  • Monitor and report on validated threat activities.
  • Use packet analysis tools to validate intrusion detection system alerts.
  • Provide timely detection, identification, and alerting of possible attacks, anomalous activities, and misuse activities and distinguish them from benign activities.
  • Perform incident handling, event triage, network analysis, threat detection, trend analysis, metric development, and vulnerability information dissemination.
  • Maintain an updated repository of YARA & Sigma rules.
  • Maintain an updated repository of sanitized IOCs.
Compliance
  • Ensure compliance with SAMA CSF Framework, with regard to function-related domains/controls.
  • Ensure compliance with SAMA Financial Sector CTIP Framework.
  • Ensure compliance with NCA Frameworks, with regard to function-related domains/controls.
  • Conduct reviews annually on function-related policies and procedures and provide corrective changes accordingly.
  • Conduct GAP assessment regularly, to identify gaps, and recommend action plans for implementation.
  • Defined Framework function-related KPIs and monitored them quarterly.
  • Ensure the Frameworks-related domains/controls evidence folder is updated quarterly.
  • Provide a report quarterly to the direct manager with regard to the Framework compliance status.
  • On a monthly basis prepare a threat advisory based on “SAMA Guideline on Cyber Security Sharing of Incidents and Imminent Threats with SAMA” and “SAMA Threat Advisory guidelines” to the direct manager.
Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline.
  • Preferably 1-2 years of relevant post-qualification experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Responder
Cyber Incident Responder

Join Solutions • Jeddah

On-site
SAR 180,000 - 300,000
Cybersecurity Engineer
Cybersecurity Engineer

PrimeGate Company • Saudi Arabia

On-site
SAR 120,000 - 180,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Leading Edge • Riyadh

On-site
Information Security Analyst
Information Security Analyst

Work in USA • Ar Rass

On-site
Information Security Engineer
Information Security Engineer

KK People • Riyadh

On-site
Competitive remuneration and benefits package
Access to cutting-edge security technologies
Information Security & Incident Response Specialist
Information Security & Incident Response Specialist

Al Tamimi • Al Khobar

On-site
SAR 120,000 - 180,000
Cybersecurity Engineer (Saudi National)
Cybersecurity Engineer (Saudi National)

Astek Middle East • Riyadh

On-site
SAR <240,000
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Join Solutions • Dammam

On-site
Security Analyst for Cybersecurity and Network Defense
Security Analyst for Cybersecurity and Network Defense

Jing Hau • Jeddah

On-site
SAR 34,000 - 41,000
Accommodation provided
Information Security Specialist
Information Security Specialist

Al Tamimi • Al Khobar

On-site
SAR 120,000 - 180,000