Senior SOC Analyst L2 - Saudi National - Jeddah, KSA

Reposted 10 Days Ago
Be an Early Applicant
Jeddah, SAU
In-Office
Senior level
Artificial Intelligence • Computer Vision • Software
The Role
The Senior SOC Analyst L2 will lead threat detection, incident response, and investigation activities, mentoring junior analysts and tuning detection mechanisms in a SOC environment.
Summary Generated by Built In

Position Overview

We are seeking a highly skilled Senior SOC Analyst – Layer 2 (L2) to join our Cybersecurity Operations Center (SOC) in Jeddah. The selected candidate will play a critical role in advanced threat detection, in-depth incident investigation, containment, and response activities across enterprise environments.

This position requires strong hands-on operational experience in SOC environments, with proven capability in analyzing complex security events, leading incident response activities, tuning detection use cases, and mentoring junior analysts (L1).

________________________________________

Key Responsibilities

1. Advanced Threat Monitoring & Analysis

• Perform in-depth analysis of security alerts escalated from L1 analysts.

• Investigate complex incidents using SIEM, EDR, NDR, and other security tools.

• Validate and classify security events to eliminate false positives.

• Conduct log correlation and behavioral analysis across multiple data sources.

• Identify Indicators of Compromise (IOCs) and map them to the MITRE ATT&CK framework.

2. Incident Response & Containment

• Lead incident triage, containment, eradication, and recovery efforts.

• Coordinate with IT, network, cloud, and system teams during active incidents.

• Perform root cause analysis and recommend corrective security controls.

• Develop and update Incident Response playbooks and runbooks.

• Support digital evidence preservation and forensic readiness.

3. SIEM & Detection Engineering Support

• Create and tune correlation rules and detection use cases in Splunk Enterprise Security, IBM QRadar, or equivalent SIEM platforms.

• Enhance alert logic to reduce false positives and improve detection accuracy.

• Develop advanced queries (e.g., SPL, AQL, KQL) for threat hunting.

• Ensure log sources are properly normalized and mapped to data models.

4. Threat Hunting & Proactive Defense

• Conduct proactive threat hunting using EDR, SIEM, and threat intelligence feeds.

• Investigate suspicious anomalies and lateral movement indicators.

• Integrate threat intelligence into detection logic.

• Participate in purple team exercises and attack simulations.

5. Endpoint & Network Security Operations

• Perform deep investigations using EDR solutions such as Microsoft Defender for Endpoint, CrowdStrike Falcon, or equivalent.

• Analyze firewall, proxy, VPN, IDS/IPS logs (e.g., Palo Alto, Fortinet, Cisco).

• Monitor and investigate suspicious email threats (phishing, malware, BEC).

6. Escalation & Reporting

• Prepare detailed incident reports with technical findings and executive summaries.

• Escalate high-severity incidents to SOC Manager and CISO when required.

• Provide weekly and monthly security incident metrics.

• Support compliance and audit reporting requirements (SAMA CSF, NCA ECC, ISO 27001, PCI DSS).

On-Call Support

• Participate in 24x7 on-call rotation for critical incident handling.

• Respond to high-severity incidents outside business hours when required.


Requirements

Candidates must demonstrate proven hands-on experience in:

• Minimum 5–7 years of experience in SOC operations.

• At least 3 years in an L2 role or equivalent advanced SOC position.

• Hands-on experience with enterprise SIEM platforms (Splunk, QRadar, ArcSight, Sentinel).

• Advanced log analysis and event correlation.

• Incident response lifecycle management.

• EDR investigation and containment.

• Malware analysis fundamentals (hash analysis, sandboxing, behavior analysis).

• Network traffic analysis (PCAP, NetFlow, TCP/IP fundamentals).

• Strong understanding of Windows/Linux security events.

• Experience working in regulated environments (Banking, Government, Critical Infrastructure preferred).

• Familiarity with cloud security monitoring (Azure/AWS logs preferred).

Preferred Technical Knowledge

• MITRE ATT&CK framework mapping.

Skills Required

  • Minimum 5-7 years of experience in SOC operations
  • At least 3 years in an L2 role or equivalent advanced SOC position
  • Hands-on experience with enterprise SIEM platforms (Splunk, QRadar, ArcSight, Sentinel)
  • Advanced log analysis and event correlation
  • Incident response lifecycle management
  • EDR investigation and containment
  • Malware analysis fundamentals (hash analysis, sandboxing, behavior analysis)
  • Network traffic analysis (PCAP, NetFlow, TCP/IP fundamentals)
  • Strong understanding of Windows/Linux security events
  • Experience working in regulated environments
  • Familiarity with cloud security monitoring (Azure/AWS logs preferred)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Berlin
10 Employees
Year Founded: 2020

What We Do

DeepSource stands as a trusted partner for businesses seeking cutting-edge AI services in computer vision, natural language processing, and predictive analytics. With a particular focus on Arabic NLP and ChatGPT bot development, DeepSource is dedicated to empowering companies with groundbreaking solutions that streamline operations, optimize workflows, and enhance user experiences. Our commitment to excellence is evident in our approach to addressing a wide range of AI needs, from hiring top talent and managing end-to-end AI projects to providing tailored consulting and comprehensive training programs. DeepSource's team of experts is equipped with extensive knowledge and experience in various AI technologies, which enables them to develop and deploy advanced solutions across multiple industries. Our adaptive strategies and innovative methodologies allow businesses to stay competitive in today's rapidly evolving digital landscape

Similar Jobs

Capco Logo Capco

Scrum Master

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Capital Markets - BA- Arabic Speaker - Riyadh

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

CrowdStrike Logo CrowdStrike

Regional Sales Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Saudi Arabia
10000 Employees

Capco Logo Capco

Information Technology Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account