Enable job alerts via email!

Senior Manager- Technology Consulting -MSOC & DFIR Services

Ernst & Young Advisory Services Sdn Bhd

Riyadh

On-site

SAR 300,000 - 400,000

Full time

Today
Be an early applicant

Job summary

A global consulting firm is seeking a Senior SOC Manager in Riyadh to lead Managed SOC operations and Digital Forensics & Incident Response. The ideal candidate will have 8–10 years of experience in SOC leadership or DFIR roles, with expertise in incident response and forensic analysis. Certifications such as GCFA or GCIH are mandatory. This role ensures effective threat detection and incident handling, requiring strong technical leadership.

Qualifications

  • 8–10 years in SOC leadership or DFIR roles.
  • Hands-on with incident response, malware analysis, SIEM triage.
  • Experience with forensic tools.

Responsibilities

  • Oversee SOC operations across L1, L2, and L3 tiers.
  • Define alert thresholds, escalation matrices, and incident runbooks.
  • Coordinate threat hunts and root cause analysis (RCA).
  • Manage DFIR tooling and evidence handling procedures.
  • Liaise with vendors for out-of-hours incident support.

Skills

SOC leadership
Incident response
Malware analysis
SIEM triage
Forensic analysis

Education

Certifications: GCFA, GCIH, or equivalent

Tools

FTK
EnCase
Job description
Overview

Location: Riyadh

Other locations: Primary Location Only

Date: 10 Sept 2025

Requisition ID: 1642149

Role Purpose

Lead the Managed SOC and Digital Forensics & Incident Response stream, ensuring timely threat detection, incident handling, escalation protocols, and forensic investigations.

Key Responsibilities
  • Oversee SOC operations across L1, L2, and L3 tiers.
  • Define alert thresholds, escalation matrices, and incident runbooks.
  • Coordinate threat hunts and root cause analysis (RCA).
  • Manage DFIR tooling and evidence handling procedures.
  • Liaise with vendors for out-of-hours incident support.
Requirements
  • 8–10 years in SOC leadership or DFIR roles.
  • Hands-on with incident response, malware analysis, SIEM triage.
  • Experience with forensic tools (e.g., FTK, EnCase).
  • Certifications: GCFA, GCIH, or equivalent.

If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.