Enable job alerts via email!

Senior Manager- Technology Consulting -MSOC & DFIR Services

WomenTech Network

Riyadh

On-site

SAR 299,000 - 450,000

Full time

Today
Be an early applicant

Job summary

A global professional services firm is seeking a lead for their Managed SOC and Digital Forensics & Incident Response stream. The ideal candidate will oversee SOC operations, define alert thresholds, manage incident response procedures, and coordinate threat analysis. Applicants should have 8-10 years of experience in SOC leadership or DFIR roles, with relevant certifications. This role is based in Riyadh, Saudi Arabia, and requires a proactive approach to incident handling and forensic investigations.

Qualifications

  • 8–10 years in SOC leadership or DFIR roles.
  • Hands-on with incident response, malware analysis, SIEM triage.
  • Experience with forensic tools.

Responsibilities

  • Oversee SOC operations across L1, L2, and L3 tiers.
  • Define alert thresholds, escalation matrices, and incident runbooks.
  • Coordinate threat hunts and root cause analysis (RCA).
  • Manage DFIR tooling and evidence handling procedures.
  • Liaise with vendors for out-of-hours incident support.

Skills

SOC leadership
Incident response
Malware analysis
SIEM triage
Forensic tools use

Education

Certifications: GCFA, GCIH, or equivalent

Tools

FTK
EnCase
Job description
Overview

MSOC & DFIR Services Tower Lead

Role Purpose

Lead the Managed SOC and Digital Forensics & Incident Response stream, ensuring timely threat detection, incident handling, escalation protocols, and forensic investigations.

Key Responsibilities
  • Oversee SOC operations across L1, L2, and L3 tiers.
  • Define alert thresholds, escalation matrices, and incident runbooks.
  • Coordinate threat hunts and root cause analysis (RCA).
  • Manage DFIR tooling and evidence handling procedures.
  • Liaise with vendors for out-of-hours incident support.
Requirements
  • 8–10 years in SOC leadership or DFIR roles.
  • Hands-on with incident response, malware analysis, SIEM triage.
  • Experience with forensic tools (FTK, EnCase).
  • Certifications : GCFA, GCIH, or equivalent.

If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

The exceptional EY experience. It’s yours to build.

EY | Building a better working world.

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the

capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow,

transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for

the complex issues facing our world today.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.