Senior Information Security Engineer

Tabby

Riyadh, Saudi Arabia

Posted
Ref: PP000-20147

Job description / Role

Job Type
Full Time
Job Location
Riyadh, Saudi Arabia
Nationality
Any Nationality
Salary
Not Specified
Gender
Not Specified
Arabic Fluency
Not Specified
Job Function
IT - Software & Web Development
Company Industry
IT, Software & Internet Services

Description

We're looking for an experienced and proactive senior information security engineer to serve as a senior member of our cybersecurity operations team. You'll lead complex investigations, shape our detection capabilities, and provide strategic input into incident response and threat management. As a technical authority in the SOC, you'll mentor junior analysts, collaborate across teams, and help drive continuous improvement in our security posture.

Key responsibilities

Advanced threat detection & monitoring

  • Lead the analysis and triage of high-fidelity alerts and complex event correlations across firewalls, IDS/IPS, endpoints, servers, and cloud platforms.
  • Identify and investigate sophisticated threats, advanced persistent threats (APTs), and anomalous behavior patterns.
  • Continuously refine detection logic, SIEM rules, and alerting thresholds to optimize SOC effectiveness.
  • Design and maintain operational dashboards and KPIs to track security trends and SOC performance.
  • Incident response & forensics

  • Act as the primary incident commander for major security incidents, coordinating technical response and stakeholder communication.
  • Conduct root cause analysis, full-scope investigations, and forensic analysis using endpoint and network-based artifacts.
  • Drive post-incident reviews and deliver actionable recommendations to reduce future risk.
  • Oversee incident documentation quality and ensure consistency in reporting and knowledge transfer.
  • Detection engineering & threat intelligence

  • Research and operationalize threat intelligence into custom detection rules, threat hunting queries, and playbooks.
  • Develop and tune detection use cases aligned with MITRE ATT&CK and evolving threat actor techniques.
  • Contribute to the development and enhancement of SOAR workflows and automation to improve SOC efficiency.
  • Vulnerability & risk management

  • Collaborate with infrastructure and DevOps teams to assess and prioritize vulnerabilities in context with threat intelligence.
  • Support patch validation and track remediation efforts for critical exposures.
  • Guide vulnerability lifecycle processes, ensuring risks are addressed in a timely and measurable way.
  • Collaboration & mentorship

  • Serve as a technical mentor and escalation point for tier 1 and tier 2 SOC analysts.
  • Lead training initiatives and tabletop exercises to strengthen SOC readiness and maturity.
  • Work closely with IT, engineering, compliance, and risk teams to ensure alignment during investigations and threat mitigation efforts.
  • Communicate clearly and effectively with stakeholders, including drafting concise executive summaries during major incidents.
  • Skills, knowledge and expertise

  • 3-5+ years of hands-on experience in a SOC or cybersecurity operations role, including incident handling and threat detection.
  • Deep understanding of security operations, threat hunting, attack vectors, and cyber kill chains.
  • Proven expertise in log analysis, endpoint telemetry, and cloud-native security tools (e.g., AWS CloudTrail, Azure Sentinel).
  • Strong scripting experience (e.g., Python, PowerShell) for automation and detection engineering.
  • Experience with SIEMs (e.g., Splunk, Elastic, Sentinel), SOAR platforms, EDR/XDR tools, and threat intelligence platforms.
  • Familiarity with DevSecOps, APIs, microservices, and modern application architectures.
  • Security certifications such as GCIA, GCIH, CySA+, or equivalent (preferred).
  • Clear and confident communicator with the ability to lead during high-pressure situations and present findings to technical and non-technical audiences.
  • Similar jobs you may be interested in
    Senior Infra And Security Architect (Infrastructure, Security & GRC) Easy Apply
    Ashghal (Public Works Authority)
    Qatar 12 Nov
    Network Security Engineer - Illumio Easy Apply
    Vega International
    UAE 30 Sep
    DevSecOps Engineer Easy Apply
    Saudi Networkers Services
    Riyadh 25 Sep
    Cybersecurity Analyst Easy Apply
    Charterhouse
    Abu Dhabi 20 Oct
    Application Security Engineer - Emiratisation Easy Apply
    TGC Middle East
    Dubai 26 Nov
    Job Alerts by Email
    • Personalised updates on latest career opportunities
    • Insights on hiring and employment activity in your industry
    • Typically sent twice a month