Skip to Content

Senior SOC Operations Analyst – Level 3 (L3)

Job Purpose

The Senior SOC Operations Analyst (L3) plays a key technical and leadership role in delivering 24×7 Managed Security Operations Center services (aiSOCaaS), including leading complex investigations, proactive threat hunting, improving detection and response systems, serving as the final escalation point, and ensuring compliance with local (NCA and SAMA) and international (NIST and ISO 27001) regulatory frameworks.

Qualifications

Bachelor's degree in Cybersecurity, Computer Science, or a related field (Master's degree is a plus).

Key Responsibilities

Own major P1/P2 incidents end-to-end, from scoping and forensic investigation through containment, eradication, recovery, and communication with executive management.

Conduct digital forensic analysis of endpoints, networks, and cloud environments using EDR, network packet captures, memory and log analysis.

Plan and execute hypothesis-driven proactive threat hunting and turn findings into new detection rules.

Develop and maintain custom detection rules and SOAR playbooks, validating them through Purple Team exercises.

Tune and optimize SIEM/XDR analytics and enrich alerts with threat intelligence sources.

Lead continuous improvement of data onboarding and integrate new log sources and APIs.

Review compliance with NCA MSOC requirements, map incidents to NCA and SAMA frameworks, and brief CISOs and auditors.

Train and mentor L1/L2 analysts, run tabletop exercises, and update playbooks and procedures.

Evaluate emerging attack techniques and AI/ML technologies as part of the SOC roadmap.

Requirements

Fluency in Arabic and English.

Saudi national – mandatory.

Minimum 5 years of experience in SOC .

At least two advanced professional certifications  (e.g., GCFA, GCIH, GREM, OSCP, CISSP, CCSP).

Hands-on experience with SIEM/XDR (Splunk, Sentinel, QRadar), SOAR (Cortex XSOAR), EDR/NDR (CrowdStrike, SentinelOne), and digital forensics.

Knowledge of MITRE ATT&CK and NIST 800-61 frameworks, plus local frameworks (NCA ECC/CCC/MSOC, SAMA CSF).

Scripting proficiency (Python, PowerShell, Bash) for SOC automation.

Experience with cloud environments (AWS/Azure/GCP) and Zero Trust concepts.

Strong crisis management skills and ability to prepare executive-level reports.

الرياض, Saudi Arabia