Project Duration: 1 December 2026 – 28 February 2027
We are looking for an experienced L2 Security Monitoring Specialist to join a high-profile project in Saudi Arabia. The successful candidate will work as part of a 24/7 Security Operations Center (SOC), responsible for real-time security monitoring, alert triage, investigation, and escalation of potential security incidents.
This is a project-based, fixed-term opportunity running from 1 December 2026 to 28 February 2027.
Key Responsibilities
- Monitor SIEM/SOAR dashboards and alert queues as part of a rotating 24/7 shift pattern.
- Perform L1/L2 triage and investigation of security alerts to determine whether activity represents a genuine security incident.
- Correlate events across network, endpoint, identity, and cloud log sources.
- Analyze logs and security events to identify Indicators of Compromise (IOCs) and distinguish genuine threats from benign activity.
- Execute documented security detection use cases and incident response playbooks.
- Escalate confirmed or high-confidence incidents to the L3 Security team, ensuring a complete and accurate evidence trail.
- Maintain detailed and auditable case documentation within the ticketing/case management system.
- Track vulnerability and patch remediation activities and flag overdue items where required.
- Support incident response drills, tabletop exercises, and shift handovers.
- Assist with the onboarding and integration of new log sources into the SIEM environment.
- Follow established SOC procedures, incident response processes, and security escalation protocols.
Requirements
- 3+ years of experience in SOC, security monitoring, cybersecurity operations, or a closely related role.
- Hands-on experience with SIEM and/or SOAR platforms.
- Strong experience in security alert triage, incident investigation, and log analysis.
- Understanding of network, endpoint, identity, and cloud security events.
- Experience working with incident response processes and security playbooks.
- Ability to identify and investigate suspicious activity and potential indicators of compromise.
- Strong documentation and evidence-gathering skills.
- Comfortable working in a 24/7 shift-based SOC environment.
- Strong analytical and problem-solving skills.
- Ability to work effectively under time-sensitive conditions and elevate incidents appropriately.
Preferred Background
Candidates with experience using platforms such as Microsoft Sentinel, Splunk, IBM QRadar, SOAR platforms, EDR/XDR solutions, or similar security technologies are encouraged to apply.
- Project Duration: 1 December 2026 – 28 February 2027
- Contract Type: Project-Based / Fixed-Term
- (Saudi Nationals): Highly preferred
- Availability: Candidates who can start within 2 weeks or sooner will be strongly preferred.
- Candidates must be comfortable committing to a short-term project-based assignment and working a rotating 24/7 shift pattern.