SOC Engineer L3 (DFIR)

Accenture PLC

Riyadh

On-site

SAR 240,000 - 420,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Accenture PLC in Riyadh is seeking an experienced SOC L3 (DFIR) Engineer who will act as a senior escalation point, leading complex incident investigations, performing digital forensics, and driving SIEM engineering to enhance detection capabilities.

You will mentor junior SOC analysts, develop and maintain incident response playbooks, and collaborate with CTI to integrate threat intelligence into detection workflows.

Qualifications

  • 2–5 years of SOC experience at L3 level (DFIR).
  • Hands-on incident response and digital forensics experience.
  • Proficient with SIEM platforms and tuning (Splunk, Sentinel, QRadar).
  • Knowledge of network protocols and ATT&CK framework.

Responsibilities

  • Lead complex incident investigations from detection to remediation.
  • Perform digital forensics on endpoints, networks, and logs.
  • Develop and tune SIEM use cases, rules, and alerts.
  • Mentor L1/L2 analysts and prepare incident reports.

Skills

Incident response leadership
Digital forensics
SIEM engineering
Threat intelligence integration
Mentoring junior analysts
Analytical communication

Tools

Splunk
Microsoft Sentinel
QRadar

Job description

We are looking for an experienced SOC L3 (DFIR) Engineer to serve as a senior escalation point within our Security Operations Center. In this role, you will lead complex incident response investigations, perform digital forensics, and drive SIEM engineering and tuning efforts to enhance detection capabilities. You will play a critical role in protecting our clients' environments and mentoring junior SOC analysts.


  • Act as the primary escalation point for complex and high-severity security incidents escalated from L1 and L2 analysts
  • Lead end-to-end incident response investigations including containment, eradication, and recovery
  • Conduct digital forensics analysis on endpoints, networks, and logs to determine root cause and impact
  • Engineer, fine-tune, and optimize SIEM use cases, correlation rules, and alerting logic to reduce false positives and improve detection accuracy
  • Develop and maintain incident response playbooks and SOC procedures
  • Collaborate with the CTI team to integrate threat intelligence into detection and response workflows
  • Provide mentorship and technical guidance to L1 and L2 analysts
  • Prepare detailed incident reports and present findings to management and clients

  • 2–5 years of experience in a SOC environment, with hands‑on experience at L3 level(DFIR)
  • Strong expertise in incident response and digital forensics methodologies
  • Proven hands‑on experience with SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, or similar) including rule creation and tuning
  • Solid understanding of network protocols, attack techniques, and threat actor TTPs
  • Familiarity with MITRE ATT&CK framework and its application in detection engineering
  • Strong analytical, problem-solving, and communication skills
  • Saudi nationals only
Preferred
  • Relevant certifications are a plus (GCIH, GCFE, GCFA, Splunk Certified, Microsoft SC-200, or equivalent)
  • Knowledge of Saudi Arabia's NCA cybersecurity regulations and compliance requirements
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC DFIR Engineer - Incident Response & SIEM Tuning
Senior SOC DFIR Engineer - Incident Response & SIEM Tuning

Accenture PLC • Riyadh

On-site
SAR 240,000 - 420,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
Security Analyst
Security Analyst

Jobmaze FZ LLC • Al Khobar

On-site
SAR 180,000 - 240,000
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 31,000 - 43,000
Assistant Manager - Digital Forensics and Incident Response
Assistant Manager - Digital Forensics and Incident Response

Red Sea Global • Riyadh

On-site
SAR 600,000 - 1,000,000
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 31,000 - 62,000
Senior IT Security Operation- Saudi National- Riyadh, KSA
Senior IT Security Operation- Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 200,000 - 320,000
Senior IT Security Operation- Saudi National- Riyadh, KSA
Senior IT Security Operation- Saudi National- Riyadh, KSA

DeepSource Technologies • Riyadh

On-site
SAR 200,000 - 300,000
SOC Analyst L1 - Al-Khobar- Saudi National
SOC Analyst L1 - Al-Khobar- Saudi National

Itsecurityct • Al Khobar

On-site
SAR 60,000 - 80,000