C

Security Operations & Monitoring Engineer

CCDS Dammam, Eastern Province, Saudi Arabia

Civic and Social Organizations · 11-50 employees

7 h ago
Mid (2-5 yrs) Full-time Saudi Arabia
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Operations & Monitoring Engineer will perform continuous monitoring of cybersecurity infrastructure and analyze security events across encryption, KMS, and database systems. They will also triage security alerts, support incident response investigations, and coordinate with engineering teams to ensure timely escalation.

What they look for

Security Operations SIEM Security Monitoring Incident Triage Log Analysis Incident Response Alert Management Threat Detection Encryption KMS HSM Database Security Cybersecurity Troubleshooting Reporting

Requirements

Candidates must hold a bachelor's degree in a relevant field and possess at least 4 years of experience in SOC, SIEM, or cybersecurity operations. A CompTIA Security+ certification is required, along with strong analytical skills and the ability to work full-time onsite in Dammam.

Full description

Location: Dammam, Saudi Arabia Employment Type: Full-Time | Onsite Project Duration: Long-term project assignment

About the RoleWe are seeking a Security Operations & Monitoring Engineer to provide continuous monitoring and security-event analysis across encryption, KMS, HSM, database security, and related infrastructure.

The successful candidate will work closely with the SOC/SIEM and technical teams to identify suspicious activities, triage security events, support incident response, and ensure timely escalation and reporting.

Key Responsibilities• Perform continuous monitoring of cybersecurity systems and infrastructure.

  • Monitor encryption, KMS, HSM, database security, and other security-related events.
  • Review and analyze system, security, audit, and application logs.
  • Monitor security alerts through SIEM/SOC platforms.
  • Perform first-level investigation and triage of cybersecurity events.
  • Correlate alerts from multiple security technologies to identify potential incidents.
  • Escalate critical or suspicious activities according to established procedures.
  • Support incident-response investigations and evidence collection.
  • Coordinate with engineering teams during security incidents and service-impacting events.
  • Support the tuning of monitoring rules and alert thresholds.
  • Prepare operational, security, and incident reports.
  • Maintain incident records, monitoring procedures, and operational documentation.
  • Participate in shift, maintenance, and on-call activities when required.

Required Qualifications & Experience• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.

  • 4+ years of experience in SOC, SIEM, security monitoring, incident triage, or cybersecurity operations.
  • Hands-on experience with SIEM and security monitoring platforms.
  • Good understanding of security events, logs, alerts, incident handling, and escalation procedures.
  • Experience integrating security solutions with central SOC/SIEM platforms.
  • Strong analytical and troubleshooting skills.
  • Must be available full-time onsite in Dammam.

Required Certification• CompTIA Security+.

Preferred Certifications• CompTIA CySA+.

  • Splunk Core Certified Power User.
  • Splunk Certified Cybersecurity Defense Analyst.
  • Equivalent recognized SIEM/SOC certification.

Core CompetenciesSOC | SIEM | Security Monitoring | Incident Triage | Log Analysis | Incident Response | Alert Management | Threat Detection | Reporting

Candidates should include the SIEM/SOC platforms they have used, the type of monitoring environments they supported, and their relevant certifications.