Senior Specialist - Cybersecurity Production Support

TAWANTECH

Riyadh

On-site

SAR 180,000 - 280,000

Full time

27 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TAWANTECH is seeking a cybersecurity production support specialist in Riyadh to manage end-to-end platform support for Splunk SIEM, SOAR and VPN infrastructure. You will monitor platforms, respond to alerts, and apply ITIL-based incident/change management practices to ensure high availability.

You will perform root-cause analyses for outages and incidents, optimize log pipelines, automate playbooks, and ensure compliance with SAMA/NCA/PDPL/NDMO data governance.

Qualifications

  • Bachelor's degree in cybersecurity, information security, CS or related field.
  • 4–8 years of cybersecurity production support experience in banking or financial services.
  • Hands-on with Splunk Enterprise/ES, SOAR platforms, and VPN solutions.
  • Strong knowledge of SIEM use cases, log management and incident response workflows.
  • Experience with ITIL processes including Incident, Problem and Change Management.
  • Exposure to SAMA/NCA/PDPL/NDMO controls and data governance frameworks.
  • Familiar with DR/BCP planning, execution, and audit requirements.

Responsibilities

  • Provide end-to-end production support for cybersecurity platforms including Splunk SIEM, SOAR, and VPN infrastructure.
  • Monitor security platforms, dashboards and alerts for continuous operational effectiveness.
  • Manage Incident, Problem and Change processes per ITIL standards with timely resolution.
  • Perform root cause analysis for outages, performance issues, and security incidents.
  • Administer and optimize Splunk use cases, log ingestion pipelines and performance.
  • Operate SOAR playbooks, workflows and automation to reduce manual intervention.
  • Ensure compliance with SAMA, NCA ECC, PDPL and NDMO data governance requirements.
  • Execute DR/BCP activities with regular testing and validation.
  • Collaborate with security, infrastructure, and vendors for patching and enhancements.
  • Maintain runbooks, SOPs, playbooks, configurations and knowledge base articles.

Skills

ITIL processes
Incident Response
Root cause analysis
Scripting (Python/PowerShell)

Education

Bachelor's degree in Cybersecurity/Info Security/CS

Tools

Splunk Enterprise/ES
Splunk SOAR
Cortex XSOAR
VPN solutions (IPSec/SSL VPN)

Job description

  • Provide end-to-end production support for cybersecurity platforms including Splunk (SIEM), SOAR, and VPN infrastructure ensuring high availability and service reliability
  • Monitor security platforms, dashboards, and alerts to ensure continuous operational effectiveness and proactive issue detection
  • Manage Incident, Problem, and Change processes in accordance with ITIL standards, ensuring timely resolution and proper escalation
  • Perform root cause analysis (RCA) for system outages, performance degradation, and security incidents, ensuring corrective and preventive actions are implemented
  • Administer and support Splunk use cases, correlation rules, log ingestion pipelines, and performance optimization
  • Operate and maintain SOAR playbooks, workflows, and automation scripts to enhance incident response and reduce manual intervention
  • Support VPN technologies including secure remote access, site-to-site connectivity, authentication mechanisms, and encryption protocols
  • Ensure compliance with SAMA Cybersecurity Framework, NCA ECC, PDPL, and NDMO data governance and classification requirements
  • Execute Disaster Recovery (DR) and Business Continuity Plan (BCP) activities including regular testing, failover validation, and documentation updates
  • Collaborate with internal security teams, infrastructure teams, and external vendors for issue resolution, patching, upgrades, and system enhancements
  • Maintain operational documentation including runbooks, SOPs, playbooks, system configurations, and knowledge base articles
  • Implement monitoring, alert tuning, and automation to improve detection accuracy, reduce false positives, and increase operational efficiency
  • Provide end-to-end production support for cybersecurity platforms including Splunk (SIEM), SOAR, and VPN infrastructure ensuring high availability and service reliability
  • Monitor security platforms, dashboards, and alerts to ensure continuous operational effectiveness and proactive issue detection
  • Manage Incident, Problem, and Change processes in accordance with ITIL standards, ensuring timely resolution and proper escalation
  • Perform root cause analysis (RCA) for system outages, performance degradation, and security incidents, ensuring corrective and preventive actions are implemented
  • Administer and support Splunk use cases, correlation rules, log ingestion pipelines, and performance optimization
  • Operate and maintain SOAR playbooks, workflows, and automation scripts to enhance incident response and reduce manual intervention
  • Support VPN technologies including secure remote access, site-to-site connectivity, authentication mechanisms, and encryption protocols
  • Ensure compliance with SAMA Cybersecurity Framework, NCA ECC, PDPL, and NDMO data governance and classification requirements
  • Execute Disaster Recovery (DR) and Business Continuity Plan (BCP) activities including regular testing, failover validation, and documentation updates
  • Collaborate with internal security teams, infrastructure teams, and external vendors for issue resolution, patching, upgrades, and system enhancements
  • Maintain operational documentation including runbooks, SOPs, playbooks, system configurations, and knowledge base articles
  • Implement monitoring, alert tuning, and automation to improve detection accuracy, reduce false positives, and increase operational efficiency

Track KPIs, SLAs, and system performance metrics for cybersecurity platforms and produce operational reports.

Requirements
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field
  • 4-8 years of experience in cybersecurity production support within banking or financial services environments
  • Hands-on experience with Splunk (Enterprise / ES), SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR), and VPN solutions (e.g., IPSec, SSL VPN)
  • Strong understanding of SIEM use cases, log management, threat detection, and incident response workflows
  • Experience with ITIL processes including Incident, Problem, and Change Management
  • Exposure to SAMA regulations, NCA ECC controls, PDPL, and NDMO data governance frameworks
  • Experience working with vendors and managed service providers for cybersecurity tools and platforms
  • Familiarity with DR/BCP planning, execution, and audit requirements

Basic scripting or automation knowledge (Python, PowerShell, or similar) is preferred...

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Administrator
Senior Network Administrator

TAWANTECH • Riyadh

On-site
SAR 120,000 - 170,000
Cybersecurity Production Ops Lead (Splunk/SOAR)
Cybersecurity Production Ops Lead (Splunk/SOAR)

TAWANTECH • Riyadh

On-site
SAR 180,000 - 280,000
Information Security Specialist
Information Security Specialist

Tamimi Commercial • Al Khobar

On-site
SAR 150,000 - 200,000
System Security Analyst
System Security Analyst

Accenture Middle East • Riyadh

On-site
SAR 120,000 - 180,000
Sr. Splunk Engineer-KSA
Sr. Splunk Engineer-KSA

Itsecurityct • Saudi Arabia

On-site
SAR 120,000 - 150,000
Cybersecurity Specialist Senior - Metro
Cybersecurity Specialist Senior - Metro

Egis • Riyadh

On-site
SAR 300,000 - 600,000
Senior Lead - IT Security Delivery
Senior Lead - IT Security Delivery

Qiddiya • Riyadh

On-site
SAR 300,000 - 540,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

Deepsource Technologies • Riyadh

On-site
SAR 250,000 - 390,000
Cybersecurity Specialist - Senior
Cybersecurity Specialist - Senior

Parsons • Riyadh

On-site
SAR 400,000 - 640,000
IT and Enterprise Cybersecurity Engineer
IT and Enterprise Cybersecurity Engineer

Optimal • Dhahran Compound

On-site
SAR 80,000 - 120,000