Manager - Tech Consulting - Cyber Automation, Detection Engineering / AI - Riyadh
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
The role leads design, engineering, deployment, and continuous improvement of next-generation Security Operations capabilities.
The position supports a transition from analyst-led SOC operations toward an AI-assisted and increasingly autonomous SOC model.
The work combines security automation, AI and GenAI, detection engineering, orchestration, and security analytics.
Key Skills for This Role
Full Job Posting
Role summary
The role leads design, engineering, deployment, and continuous improvement of next-generation Security Operations capabilities.
The position supports a transition from analyst-led SOC operations toward an AI-assisted and increasingly autonomous SOC model.
The work combines security automation, AI and GenAI, detection engineering, orchestration, and security analytics.
Autonomous SOC and AI engineering
- Lead the technical design and deployment of AI-driven and autonomous SOC capabilities.
- Automate alert triage, investigation, enrichment, containment, and response processes.
- Develop LLM or GenAI capabilities including analyst copilots, automated investigation, incident summaries, and response recommendations.
- Design human-in-the-loop controls, approval gates, guardrails, and escalation mechanisms.
- Evaluate AI use-case accuracy, reliability, security, and operational effectiveness.
Security automation and orchestration
- Design, build, and maintain automated security workflows and orchestration playbooks.
- Automate alert enrichment, IOC investigation, phishing analysis, endpoint and identity investigation, malware analysis, case management, containment, and remediation.
- Integrate SIEM, SOAR, EDR/XDR, threat intelligence, email, identity, network, cloud, ticketing, and other security platforms.
- Use Python, REST APIs, webhooks, SDKs, scripting, and orchestration platforms to build automation.
- Implement logging, monitoring, testing, error handling, and rollback mechanisms.
Detection engineering
- Develop, test, tune, and maintain detections across SIEM, EDR/XDR, cloud, identity, network, and other security technologies.
- Translate threat intelligence, attack techniques, incident findings, and threat hunting into actionable detections.
- Map detection coverage against MITRE ATT&CK and identify gaps.
- Use detection-as-code practices including version control, testing, peer review, deployment, and lifecycle management.
- Define detection quality metrics and connect detections to automated investigation and response workflows.
AI and security data integration
- Integrate security telemetry from multiple platforms into AI-driven investigation and automation workflows.
- Develop mechanisms for AI systems to retrieve and correlate relevant security context securely.
- Design prompts, workflows, agent logic, and tool integrations for security use cases.
- Integrate enterprise knowledge, threat intelligence, historical incidents, detection content, and SOC procedures.
- Apply controls for privacy, access, auditability, model usage, AI decisions, hallucinations, and unsafe actions.
SOC engineering and improvement
- Assess SOC processes and identify efficiency improvements through engineering and automation.
- Reduce manual analyst workload and improve mean time to detect, investigate, and respond.
- Establish engineering standards and validate automated response actions before production deployment.
- Track operational KPIs for autonomous SOC capabilities.
- Mentor SOC analysts and engineers and collaborate with SOC leadership, architecture, infrastructure, cloud, IAM, and security engineering teams.
Required experience
- Candidates need 7 or more years of cybersecurity experience with significant SOC engineering, detection engineering, security automation, incident response, or security operations experience.
- Strong hands-on experience is required with SIEM, SOAR, Python, REST APIs, SOC workflows, detection engineering, and security platform integrations.
- Strong knowledge is required of MITRE ATT&CK, threat-informed defence, detection lifecycle management, detection-as-code, version control, CI/CD, and automated testing.
- Experience is required with EDR/XDR, identity, email, network, cloud security, and threat intelligence platforms.
AI and GenAI experience
- Strong knowledge or practical experience is required with Generative AI, Large Language Models, AI agents, agentic workflows, LLM APIs, and enterprise AI platforms.
- Relevant experience includes prompt and context engineering, RAG, tool or function calling, AI-assisted investigation, security analytics, evaluation, accuracy testing, hallucination management, and guardrails.
- The role prioritises practical application of AI within security operations rather than machine-learning research.
Preferred experience
- Preferred technologies include Microsoft Sentinel, Security Copilot, Splunk ES or SOAR, Cortex XSOAR or XSIAM, Microsoft Defender XDR, CrowdStrike, ServiceNow SecOps, Git platforms, enterprise LLM platforms, and cloud security platforms.
- Experience building or deploying AI-enabled SOC, Autonomous SOC, hyperautomation, or security-agent solutions is highly advantageous.
Expected outcomes
Increase the percentage of SOC activities automated and reduce manual analyst intervention.
Improve detection coverage and quality while reducing false-positive rates.
Reduce mean time to triage and mean time to respond.
Increase automated enrichment, investigation coverage, and deployment of AI-assisted or autonomous investigation workflows.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at EY
Senior Consultant - Business Transformation - Financial Services
Sydney, AUS
Senior Manager - Supply Chain, Procurement Transformation (Defense and GPS Sector Focus) - Ottawa
Ottawa, CAN
Service Delivery Center-Full Stack Developer-Financial Services-Manager-Raleigh, Dallas, San Antonio
Dallas, USA
SDC Camunda Workflow Automation Engineer---Manager---Raleigh, NC or Dallas, TX
Raleigh, USA
SDC Camunda Workflow Automation Engineer---Analyst---Raleigh, NC or Dallas, TX
Raleigh, USA
SAP Security & GRC Senior Consultant
Melbourne, AUS
Senior Consultant - Business Transformation - Financial Services
Sydney, AUS
Senior Manager - Supply Chain, Procurement Transformation (Defense and GPS Sector Focus) - Ottawa
Ottawa, CAN
Service Delivery Center-Full Stack Developer-Financial Services-Manager-Raleigh, Dallas, San Antonio
Dallas, USA
SDC Camunda Workflow Automation Engineer---Manager---Raleigh, NC or Dallas, TX
Raleigh, USA
SDC Camunda Workflow Automation Engineer---Analyst---Raleigh, NC or Dallas, TX
Raleigh, USA
GPS - Azure Senior Platform Engineer - Assistant Director
Denver, USA
Secure Data Exchange Compliance SME
Kochi, IND