Senior Cybersecurity Specialist (Splunk Architect)

Help AG

Riyadh

On-site

SAR 300,000 - 520,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Career progression
Training program
Team activities

Job summary

Help AG, the cybersecurity arm of the e&, is seeking a Senior Cybersecurity Specialist (Splunk Architect) to lead Splunk deployments, SIEM administration, and security operations for clients. Based in Riyadh, you will collaborate with SOC analysts, threat experts, and solution architects to deliver high-profile services within our managed security framework.

You will drive integration of technologies, refine detections, and support vulnerability management, EDR, and cloud security integrations

Qualifications

  • Minimum 3 years of professional experience supporting and maintaining Splunk SIEM & Enterprise Security.
  • 3-5 years of experience with advanced tuning of Splunk SIEM content.
  • Professional experience working with networks and network architecture.
  • Bachelor's degree or equivalent training with experience in a Security Operations Center, Managed Security, or client network environment.
  • Information security knowledge in one or more areas such as EDR.
  • Hands-on experience with EDR (e.g., Carbon Black), Vectra, and Microsoft Azure.
  • Security certifications on Splunk Admin, Splunk Architect, Splunk Consultant are a plus.
  • Knowledge of Linux and Windows operating systems.
  • Experience with other SIEM solutions such as QRadar and LogRhythm is highly preferred.
  • Experience working with clients in a service delivery function.
  • Shift flexibility, including after-hours support when needed.
  • Experience with incident/problem tracking and knowledge bases.

Responsibilities

  • Administering Splunk and Splunk Apps to develop or extend apps for specialized functionality.
  • Integrating Splunk with a wide variety of legacy data sources.
  • Adapt to learn new SOC technologies from different vendors.
  • Collaborate with application and infrastructure teams to establish best practices for Splunk data and visuals.
  • Design and support Microsoft security technologies (Azure, O365 ATP, Defender ATP) and their integrations.
  • Handle deployment and mitigation of vulnerability scanners with SLA.
  • Document vulnerabilities and mitigation actions.
  • Manage EDR sensors including deployment, operations, updates, and patching.
  • Create watchlists to detect IoCs and new threats.
  • Assess customer needs, design solutions, and implement the design.
  • Quickly build and test new technology viability.
  • Serve as primary responder for MSS customer systems and client configurations.
  • Work with SOC to enhance service quality and processes.
  • Fine tune false positives and improve MSS processes.
  • Develop content for SOC technologies (e.g., Splunk use cases) in cooperation with SOC.

Skills

Splunk SIEM
Splunk tuning
Network architecture
EDR experience
Linux
Windows
Azure
QRadar
LogRhythm
SOC experience

Education

Bachelor's degree in IT/Security

Tools

Splunk Apps

Job description

Help AG is looking for a talented and experienced Senior Cybersecurity Specialist (Splunk Architect) who will be responsible for the creation of procedures, implementation of process development, and maintenance of security systems across internal and client environments. The Senior Cybersecurity Specialist (Splunk Architect) will work closely with Management, Security Operation Center Analysts, Threat Analysts, Solution Architects, other Security Engineers, and clients to complete high profile, critical services to existing Managed Security Service clients.

This position will be based in Riyadh, KSA under the Cyber Engineering department and will be responsible for the administration, maintenance, and integration of SOC technologies including SIEM, EDR, NDR, VA, SOAR, and other platforms.

Responsibilities
  • Administering Splunk and Splunk Apps to include developing new or extending existing Apps to perform specialized functionality.
  • Integrating Splunk with a wide variety of legacy data sources.
  • Adapt to learn new SOC technologies from different vendors.
  • Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations.
  • Design, implement, and support solutions with Microsoft security technologies such as Azure Cloud Access Security Broker, Office 365 Advanced Threat Protection (O365 ATP), Microsoft Defender ATP, and their integrations used to deliver internet-scale intelligence and managed security products.
  • Handle the implementation/deployment/support of Vulnerability scan engines with Engineering, SOC, and IR Document vulnerabilities and work on vulnerability mitigation with agreed SLA.
  • Document vulnerabilities and work on vulnerability mitigation with agreed SLA.
  • Managing EDR sensors including deployment, operation, management, maintenance, update, upgrade, patching, and administration.
  • Should be able to create watchlists to detect Indicators of Compromise (IoCs) and malicious behavior of new threats.
  • Assess customer needs and expectations, design solutions to meet those needs, and then implement the design.
  • Quickly build and solve a problem using a new technology to determine viability.
  • Serve as a primary responder for Managed Security customer systems, taking ownership of client configuration issues and tracking through resolution.
  • Work closely with SOC team members to work on operational tasks/initiative to enhance the service quality.
  • Proactively work on fine tuning false positives and enhancing the process along with other MSS teams.
  • Develop content for SOC technologies (e.g., use cases for Splunk) in cooperation with SOC.
Qualifications & Skills
  • Experience and knowledge of Splunk SIEM is essential.
  • Minimum 3 years of professional experience supporting and maintaining Splunk SIEM & Enterprise Security.
  • 3-5 years of experience with advanced tuning of Splunk SIEM content.
  • Professional experience working with networks and network architecture.
  • Bachelor's degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.
  • Information security knowledge in one or more areas such as EDR.
  • Practical hands-on experience in EDR (e.g., Carbon Black), Vectra, and Microsoft Azure.
  • General security knowledge, certificates on Splunk Admin, Splunk Architect, Splunk Consultant is must.
  • Knowledge of Linux and Windows Operating Systems.
  • Experience with other SIEM solutions such as QRadar & LogRhythm is highly preferred.
  • Experience working with clients in a service delivery function.
  • Shift flexibility, including the ability to provide after-hours support when needed.
  • Experience working with internal and client ticketing and knowledge base systems for Incident and Problem tracking as well as procedures.
Benefits
  • Health insurance with one of the leading global providers for medical insurance.
  • Career progression and growth through challenging projects and work.
  • Employee engagement activities throughout the year.
  • Tailored training & development program.
About Us

Help AG, the cybersecurity arm of e&, is the Middle East's trusted cybersecurity partner, enabling governments, enterprises and critical industries to innovate with confidence. Combining strategic consulting, advanced managed security services and deep technology expertise, Help AG helps organisations strengthen cyber resilience, secure AI adoption and build trusted sovereign digital environments. With regional expertise and a customer-first approach, Help AG delivers end-to-end cybersecurity capabilities designed to protect critical operations, manage evolving risks and support secure digital transformation. Through continuous innovation, trusted partnerships and measurable outcomes, Help AG enables organisations to remain resilient, prepared and confident in a complex digital world.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Riyadh-Based Senior Splunk Architect | Cybersecurity
Riyadh-Based Senior Splunk Architect | Cybersecurity

Help AG • Riyadh

On-site
SAR 300,000 - 520,000
Health insurance
Career progression
Training program
+1
Senior Cybersecurity Solutions Engineer - Splunk (Saudi Arabia)
Senior Cybersecurity Solutions Engineer - Splunk (Saudi Arabia)

Cisco • Riyadh

Hybrid
SAR 300,000 - 480,000
Healthcare and Insurance
Employee Stock Purchase
Flexible Spending
+1
Solution Architect Presales
Solution Architect Presales

Help AG, an e& enterprise company • Riyadh

On-site
SAR 240,000 - 420,000
Health insurance
Career progression
Training & development program
+1
Security Delivery Consultant
Security Delivery Consultant

Accenture • Jeddah

On-site
SAR 300,000 - 520,000
Cybersecurity Specialist Senior - Metro
Cybersecurity Specialist Senior - Metro

Egis • Riyadh

On-site
SAR 300,000 - 600,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
Senior IT Security Operation Architect - Saudi National- Riyadh, KSA
Senior IT Security Operation Architect - Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 450,000 - 750,000
SIEM Admin at Innovative Solutions
SIEM Admin at Innovative Solutions

Innovative Solutions • Riyadh

On-site
SAR 167,000 - 301,000
Senior IT Security Operation- Saudi National- Riyadh, KSA
Senior IT Security Operation- Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 200,000 - 320,000