{bc}
bayt

SOC Analyst – Level 3 Technical Lead

Unknown
Riyadh Region, KSA
Director
Onsite
Discovered 3 weeks ago
Advanced incident responseThreat huntingSIEM administration and detection rule tuningSOAREDR/XDR investigationsMITRE ATT&CK
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Advanced incident responseThreat huntingSIEM administration and detection rule tuning
Smart Apply

Full Job Posting

Role Overview

Lead advanced incident response, detection engineering, automation strategy, and operational governance in a 24/7 Security Operations Center.

Hold technical escalation authority and operational responsibility for monitoring coverage, roster planning, and shift management.

Mandatory Regulatory Requirements

  • A valid NCA Category A Certificate held for a minimum of three years is mandatory.
  • Meet SCyWF competencies for advanced incident handling, threat analysis, and monitoring and detection engineering.
  • Certification authenticity must be verifiable and documented.
  • Support 24/7 SOC operations, including on-call escalation.
  • Comply with NCA ECC, incident management and reporting, continuous monitoring, and workforce regulatory controls.

Incident Response and Detection

  • Lead high-severity and critical incident handling, deep forensic investigations, and root cause analysis.
  • Approve containment, eradication, and recovery strategies and provide executive technical summaries.
  • Lead threat hunting and develop, tune, and optimize SIEM detection rules aligned with MITRE ATT&CK.
  • Reduce false positives and improve detection efficiency.

Automation and SOC Governance

  • Design, review, and approve SOAR playbooks under the approved Incident Response Plan.
  • Oversee SIEM, EDR, threat intelligence, and SOAR integrations to improve MTTR.
  • Create SOC rosters, manage scheduling and workload distribution, and maintain 24/7 coverage.
  • Ensure shift handovers, alert and log health reviews, staffing controls, and monitoring continuity.

Leadership and Compliance

  • Mentor and technically supervise SOC L1 and L2 analysts and review investigation quality and documentation.
  • Participate in hiring, performance evaluation, and technical knowledge-sharing.
  • Keep incident cases audit-ready, validate evidence retention, and support internal and external audits.
  • Ensure continuous adherence to NCA monitoring, workforce, staffing, and documentation requirements.

Experience and Qualifications

  • Bachelor's or master's degree in cybersecurity, IT, or computer science.
  • Five to eight years of SOC or cybersecurity operations experience.
  • Proven critical incident investigation leadership and prior SOC shift or operational oversight experience.
  • Demonstrated automation and detection engineering experience.

Technical Skills

  • Expert SIEM administration and rule tuning, strong SOAR experience, and advanced EDR/XDR investigation capabilities.
  • Knowledge of network security monitoring, threat intelligence integration, malware analysis fundamentals, and cloud security monitoring.
  • PowerShell or Python scripting experience is preferred.
  • Experience with Microsoft Sentinel, Splunk, or IBM QRadar is required; the source lists these as example platforms.

Preferred Certifications

  • GCIH, GCIA, CISSP, advanced incident response, and SOAR-related certifications are preferred.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Unknown