Senior SOC Analyst

Salla

Jeddah

On-site

SAR 240,000 - 360,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Salla is seeking a Senior SOC Analyst in Jeddah to lead security monitoring, investigations, and incident response across cloud, edge, and on‑prem environments. You will mentor junior analysts and collaborate with security, cloud, and engineering teams.

The role operates at L2/L3, escalating incidents, tuning SIEM rules, and improving detection coverage using MITRE ATT&CK. Strong scripting and communication skills are essential for success.

Qualifications

  • 5+ years as a SOC Analyst (L2/L3)
  • Hands-on with SIEM platforms (Splunk, Graylog, or similar)
  • Experience in alert triage, incident investigation, and escalation
  • Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/HTTPS)
  • Experience analyzing AWS security logs (CloudTrail, CloudWatch)
  • Experience with container security (Kubernetes/EKS)
  • Hands-on with Cloudflare security tools (WAF, DDoS, Zero Trust)
  • Familiarity with MITRE ATT&CK and NIST IR standards
  • Knowledge of scripting (Python/PowerShell/Bash)
  • Strong analytical and incident handling skills
  • Ability to communicate technical findings to non-technical stakeholders
  • Relevant certifications preferred (GCIA, GCIH, CySA+, AWS Security Specialty)

Responsibilities

  • Perform advanced L2/L3 alert triage and investigations across endpoint, network, cloud, and edge security platforms
  • Lead investigations using SIEM tools to validate incidents, reduce noise, and determine impact
  • Analyze and respond to edge security events including WAF, DDoS, bot activity, and Zero Trust alerts
  • Escalate confirmed incidents and support containment and response actions
  • Conduct root cause analysis and threat investigations identifying attacker behavior and scope
  • Design, tune, and maintain detection rules and logic across SIEM platforms
  • Improve detection coverage by aligning rules with the MITRE ATT&CK framework
  • Mentor junior SOC analysts and contribute to skill development
  • Help build and maintain investigation playbooks and incident response runbooks
  • Collaborate with SOC leadership, Cloud Security, and DevOps teams to improve security controls and visibility

Skills

SIEM Tools
Incident investigation
Alert triage
Networking protocols
AWS logs
Kubernetes security
Cloudflare security
MITRE ATT&CK
Scripting (Python)
Communication skills
Certifications
AWS Security Specialty

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Splunk
Graylog
Kubernetes
Amazon EKS
Cloudflare

Job description

About The Role

We are looking for a Senior SOC Analyst to lead advanced security monitoring, investigation, and response across our cloud, endpoint, network, and edge environments. This role sits at the L2/L3 level and plays a critical part in incident escalation, detection engineering, and strengthening our overall security posture. You will also act as a mentor to junior analysts and collaborate closely with security, cloud, and engineering teams.

Key Responsibilities
  • Perform advanced L2/L3 alert triage and investigations across endpoint, network, cloud, and edge security platforms
  • Lead investigations using SIEM tools to validate incidents, reduce noise, and determine impact
  • Analyze and respond to edge security events including WAF, DDoS, bot activity, and Zero Trust alerts
  • Act as an escalation point for confirmed incidents and support containment and response actions
  • Conduct root cause analysis and threat investigations, identifying attacker behavior and scope of impact
  • Design, tune, and maintain detection rules and logic across SIEM platforms
  • Improve detection coverage by aligning rules with the MITRE ATT&CK framework
  • Mentor and guide junior SOC analysts and contribute to skill development across the team
  • Help build and maintain investigation playbooks and incident response runbooks
  • Collaborate with SOC leadership, Cloud Security, and DevOps teams to improve security controls and visibility
What Success Looks Like
  • Security alerts are accurately triaged with reduced false positives and faster response times
  • Incidents are thoroughly investigated with clear root cause analysis and actionable remediationDetection coverage improves continuously across cloud, endpoint, and edge environments
  • Junior analysts demonstrate stronger investigation and escalation capabilities
  • Cross-functional teams are supported with clear, timely security insights and recommendations
Requirements
  • 5+ years of experience as a SOC Analyst (L2/L3)
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience
  • Hands‑on experience with SIEM platforms (Splunk, Graylog, or similar)
  • Experience performing alert triage, incident investigation, and escalation
  • Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/HTTPS, BGP)
  • Experience analyzing AWS security logs (CloudTrail, CloudWatch, VPC Flow Logs)
  • Experience with container and Kubernetes runtime security (Kubernetes, Amazon EKS)
  • Hands‑on experience with Cloudflare security tools (WAF, DDoS, Bot Management, Zero Trust)
  • Strong understanding of IDS/IPS, firewalls, proxies, and DLP technologies
  • Experience conducting root cause analysis and post‑incident reviews
  • Familiarity with MITRE ATT&CK framework and NIST incident response standards
  • Experience developing and tuning SIEM detection rules
  • Knowledge of scripting or automation (Python, PowerShell, or Bash)
  • Foundational understanding of AI/ML security concepts and LLM‑related risks
  • Strong analytical, investigation, and incident handling skills
  • Ability to communicate technical findings to non‑technical stakeholders
  • Relevant certifications preferred (GCIA, GCIH, CompTIA CySA+, AWS Security Specialty)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Senior Analyst at Accenture
SOC Senior Analyst at Accenture

Accenture • Riyadh

On-site
SAR 180,000 - 260,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
Cybersecurity Threat Monitoring and Response Analyst
Cybersecurity Threat Monitoring and Response Analyst

Jobs for Humanity • Riyadh

On-site
SAR 167,000 - 279,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Join Solutions • Jeddah

On-site
SAR 180,000 - 300,000
Senior SOC Analyst: Lead Incident Response & Mentorship
Senior SOC Analyst: Lead Incident Response & Mentorship

Salla • Jeddah

On-site
SAR 240,000 - 360,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

Deepsource Technologies • Riyadh

On-site
SAR 250,000 - 390,000
System Security Analyst
System Security Analyst

Accenture Middle East • Riyadh

On-site
SAR 120,000 - 180,000
Senior Network Administrator
Senior Network Administrator

TAWANTECH • Riyadh

On-site
SAR 120,000 - 170,000
Cloud SQL and Security
Cloud SQL and Security

Fircroft • Riyadh

On-site
SAR 80,000 - 100,000