Senior SOC Analyst

Posted 9 Days Ago
Be an Early Applicant
Jeddah, SAU
In-Office
Senior level
Cloud • eCommerce • Information Technology • Software
The Role
Leads advanced L2/L3 security monitoring, alert triage, incident investigation, containment, root cause analysis, and detection engineering across cloud, endpoint, network, and edge environments. Tunes SIEM rules, aligns detection coverage with MITRE ATT&CK, maintains response playbooks, mentors junior analysts, and collaborates with cloud, DevOps, and security teams to improve controls and incident response.
Summary Generated by Built In

About the role
We are looking for a Senior SOC Analyst to lead advanced security monitoring, investigation, and response across our cloud, endpoint, network, and edge environments. This role sits at the L2/L3 level and plays a critical part in incident escalation, detection engineering, and strengthening our overall security posture. You will also act as a mentor to junior analysts and collaborate closely with security, cloud, and engineering teams.

Key responsibilities

  • Perform advanced L2/L3 alert triage and investigations across endpoint, network, cloud, and edge security platforms
  • Lead investigations using SIEM tools to validate incidents, reduce noise, and determine impact
  • Analyze and respond to edge security events including WAF, DDoS, bot activity, and Zero Trust alerts
  • Act as an escalation point for confirmed incidents and support containment and response actions
  • Conduct root cause analysis and threat investigations, identifying attacker behavior and scope of impact
  • Design, tune, and maintain detection rules and logic across SIEM platforms
  • Improve detection coverage by aligning rules with the MITRE ATT&CK framework
  • Mentor and guide junior SOC analysts and contribute to skill development across the team
  • Help build and maintain investigation playbooks and incident response runbooks
  • Collaborate with SOC leadership, Cloud Security, and DevOps teams to improve security controls and visibility

What success looks like

  • Security alerts are accurately triaged with reduced false positives and faster response times
  • Incidents are thoroughly investigated with clear root cause analysis and actionable remediation
  • Detection coverage improves continuously across cloud, endpoint, and edge environments
  • Junior analysts demonstrate stronger investigation and escalation capabilities
  • Cross-functional teams are supported with clear, timely security insights and recommendations

Requirements
  • 5+ years of experience as a SOC Analyst (L2/L3)
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience
  • Hands-on experience with SIEM platforms (Splunk, Graylog, or similar)
  • Experience performing alert triage, incident investigation, and escalation
  • Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/HTTPS, BGP)
  • Experience analyzing AWS security logs (CloudTrail, CloudWatch, VPC Flow Logs)
  • Experience with container and Kubernetes runtime security (Kubernetes, Amazon EKS)
  • Hands-on experience with Cloudflare security tools (WAF, DDoS, Bot Management, Zero Trust)
  • Strong understanding of IDS/IPS, firewalls, proxies, and DLP technologies
  • Experience conducting root cause analysis and post-incident reviews
  • Familiarity with MITRE ATT&CK framework and NIST incident response standards
  • Experience developing and tuning SIEM detection rules
  • Knowledge of scripting or automation (Python, PowerShell, or Bash)
  • Foundational understanding of AI/ML security concepts and LLM-related risks
  • Strong analytical, investigation, and incident handling skills
  • Ability to communicate technical findings to non-technical stakeholders
  • Relevant certifications preferred (GCIA, GCIH, CompTIA CySA+, AWS Security Specialty)

Skills Required

  • 5+ years of experience as a SOC Analyst at the L2/L3 level
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience
  • Hands-on experience with SIEM platforms such as Splunk, Graylog, or similar
  • Experience with alert triage, incident investigation, and escalation
  • Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, and BGP
  • Experience analyzing AWS CloudTrail, CloudWatch, and VPC Flow Logs
  • Experience with container and Kubernetes runtime security, including Amazon EKS
  • Hands-on experience with Cloudflare WAF, DDoS, Bot Management, and Zero Trust tools
  • Strong understanding of IDS/IPS, firewalls, proxies, and DLP technologies
  • Experience conducting root cause analysis and post-incident reviews
  • Familiarity with MITRE ATT&CK and NIST incident response standards
  • Experience developing and tuning SIEM detection rules
  • Knowledge of Python, PowerShell, or Bash scripting or automation
  • Foundational understanding of AI/ML security concepts and LLM-related risks
  • Strong analytical, investigation, incident handling, and stakeholder communication skills
  • Relevant certifications such as GCIA, GCIH, CompTIA CySA+, or AWS Security Specialty
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Year Founded: 2016

What We Do

Salla is the leading commerce platform in the GCC, built in Saudi Arabia, providing tools and services for merchants to build, run, and grow their online stores.

Similar Jobs

Capco Logo Capco

Business Consulting Opportunities - Middle East

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Cloud & Cyber Security Opportunities - Qatar

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Data & AI Opportunities - Middle East

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Immersive Logo Immersive

Senior Solutions Architect

Enterprise Web • HR Tech • Information Technology • Software • Cybersecurity
Remote or Hybrid
Saudi Arabia
330 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account