Cybersecurity Operations Expert (Saudi) - Riyadh, KSA
DeepSource Technologies Riyadh, Riyadh Region, Saudi Arabia
IT Services and IT Consulting · 51-200 employees
About the role
The Cybersecurity Operations Expert is responsible for monitoring security alerts, investigating incidents, and coordinating vulnerability remediation across enterprise IT environments. They also maintain operational security controls, support identity and access management, and ensure the effectiveness of security integrations.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess at least 5 years of experience in cybersecurity operations or incident response. Proficiency in enterprise security technologies and a strong understanding of cybersecurity frameworks and attack techniques are required.
Full description
Cybersecurity Operations Expert responsible for supporting the first line of defense through the day-to-day execution, monitoring, and improvement of operational security controls across enterprise IT environments. The role focuses on protecting systems, networks, endpoints, applications, and users by detecting threats, responding to security events, coordinating remediation activities, and maintaining effective cybersecurity operations.
Key responsibilities include continuous monitoring of security alerts and events, email security, and other operational security platforms, and ensuring timely containment and recovery actions. The role also supports vulnerability management by tracking findings, coordinating remediation with infrastructure and application teams, and validating closure of identified risks.
The Cybersecurity Operations Expert works closely with IT operations, network, cloud, server, endpoint, and application teams to ensure security controls are implemented and functioning effectively as part of daily business and technology operations.
Responsibilities also include supporting identity and access security operations, reviewing privileged access activities, enforcing security baselines, maintaining playbooks and operational procedures, and contributing to security awareness from an operational perspective.
This position is part of the first line of defense and is therefore focused on operating and executing controls rather than performing independent oversight, policy governance, regulatory compliance assurance, or internal audit activities associated with the second or third lines of defense.
Rsponsibilities:
- Monitor and analyze cybersecurity alerts, events, and incidents.
- Perform initial triage, investigation, containment support, and escalation of security incidents.
- Support endpoint, network, cloud, and email security operations.
- Coordinate vulnerability remediation with relevant technical teams.
- Execute and maintain operational security controls and monitoring use cases.
- Monitor and support security-related patching, platform upgrades, and operational technology refresh activities to ensure minimal security exposure and service disruption.
- Support security activities during system, tool, and infrastructure migrations, including validation of controls, configuration reviews, and post-migration security checks.
- Review and validate security integrations between cybersecurity tools, IT systems, cloud platforms, and third-party solutions to ensure proper logging, alerting, connectivity, and control effectiveness.
- Support access control reviews, privileged access monitoring, and identity-related security operations.
- Maintain incident response procedures, runbooks, and operational documentation.
- Track remediation actions and follow up on risk reduction activities.
- Contribute to continuous improvement of cybersecurity activities and processes.
- Support business resilience by reducing operational cyber risk exposure.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- 5+ years of experience in cybersecurity operations, security monitoring, incident response, vulnerability management, or security engineering functions.
- Hands-on experience with enterprise security technologies, including SIEM, EDR/XDR, email security, identity and access management, network security, cloud security, and vulnerability management platforms.
- Strong understanding of cybersecurity frameworks, attack techniques, threat detection methodologies, and security operations best practices.
- Experience working in hybrid environments spanning on-premises infrastructure, cloud platforms, and third-party services.
Preferred Certifications
Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Similar roles
-
Lead Security Engineer, GRC
Anduril Industries Boston, Massachusetts, United States · $166K–$253K/yr
-
Information Security Engineer (R14207)
Oportun Mexico
-
Principal Application Security Specialist
Global Relay Vancouver, British Columbia, Canada · CA$125K–CA$160K/yr
-
HSM & PKI Security Engineer
CCDS Dammam, Eastern Province, Saudi Arabia
-
Security Engineer
Warp New York, New York, United States · $230K–$290K/yr
-
Product Security Engineer
YipitData (Alternative) United States · $180K/yr