Information Security Engineer – SOC Level 2
Tabby | تابي · Riyad
Job description
About the role
As an Information Security Engineer you’ll play a key part in monitoring and defending Tabby’s infrastructure, applications, and cloud environments from cyber threats. You’ll lead incident response efforts, develop and tune detection rules, investigate security events, and collaborate with cross‑functional teams to strengthen the company’s security posture.
Key responsibilities
- Monitor and analyze logs and alerts from firewalls, IDS/IPS, endpoints, servers and cloud platforms.
- Correlate events from multiple sources to identify advanced threats and unusual behavior.
- Fine‑tune alert thresholds and detection logic to reduce false positives and improve signal‑to‑noise ratio.
- Maintain dashboards and reporting to provide real‑time visibility into the security posture.
- Serve as the frontline responder for security incidents, managing detection, containment, eradication, recovery and lessons learned.
- Coordinate with internal stakeholders and external vendors during high‑severity incidents or data breaches.
- Perform root‑cause analysis and forensic investigations using endpoint and network artifacts.
- Research emerging threats and trends and contribute to the creation and tuning of detection rules, threat‑hunting queries and use cases.
- Maintain the CTI platform and integrate threat‑intelligence feeds with security controls.
- Mentor junior analysts and assist in training efforts within the SOC team.
Required profile
- 2–3 years of experience in a SOC or cybersecurity operations role, preferably in a fast‑paced fintech or enterprise environment.
- Strong knowledge of security best practices, incident handling, alert triage, log analysis and threat modeling.
- Understanding of online technologies, REST APIs, microservices and modern application architectures.
- Familiarity with DLP, AV and anti‑malware systems from an operational monitoring perspective.
- Experience with phishing detection, user‑behavior analytics and security awareness campaigns.
- Security certifications such as Security+, CySA+, eCIR, eCTHPv2, GCIA or GMON (preferred).
- Excellent communication skills for coordinating incident response and writing clear reports.
Required skills
- Python scripting
- SIEM platforms
- SOAR tools
- EDR/XDR solutions
- Threat Intelligence platforms
- Cloud‑native logging and monitoring tools
- DLP systems
- AV/anti‑malware solutions
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 12 hours ago
Expires 1 month from now
6 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Tabby | تابي
Riyad
Related job offers
-
AI Engineer
Confidential Riyad -
DT Project Management Senior Specialist
Lenovo Riyad -
Senior Jira Consultant – Enterprise Solutions
TestCrew | Quality Engineering & Software Testing Riyad -
أخصائي أمن سيبراني – الرياض
وظيفتك الأولى جول الرياض -
Technician – Communications
Le Méridien Hotels & Resorts Médine