We are looking for an experienced SOC L3 (DFIR) Engineer to serve as a senior escalation point within our Security Operations Center. In this role, you will lead complex incident response investigations, perform digital forensics, and drive SIEM engineering and tuning efforts to enhance detection capabilities. You will play a critical role in protecting our clients' environments and mentoring junior SOC analysts.
- Act as the primary escalation point for complex and high-severity security incidents escalated from L1 and L2 analysts
- Lead end-to-end incident response investigations including containment, eradication, and recovery
- Conduct digital forensics analysis on endpoints, networks, and logs to determine root cause and impact
- Engineer, fine-tune, and optimize SIEM use cases, correlation rules, and alerting logic to reduce false positives and improve detection accuracy
- Develop and maintain incident response playbooks and SOC procedures
- Collaborate with the CTI team to integrate threat intelligence into detection and response workflows
- Provide mentorship and technical guidance to L1 and L2 analysts
- Prepare detailed incident reports and present findings to management and clients
- 2–5 years of experience in a SOC environment, with hands‑on experience at L3 level(DFIR)
- Strong expertise in incident response and digital forensics methodologies
- Proven hands‑on experience with SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, or similar) including rule creation and tuning
- Solid understanding of network protocols, attack techniques, and threat actor TTPs
- Familiarity with MITRE ATT&CK framework and its application in detection engineering
- Strong analytical, problem-solving, and communication skills
- Saudi nationals only
Preferred
- Relevant certifications are a plus (GCIH, GCFE, GCFA, Splunk Certified, Microsoft SC-200, or equivalent)
- Knowledge of Saudi Arabia's NCA cybersecurity regulations and compliance requirements