Security Operations & Monitoring Engineer
- CCDS
- Dammam, Saudi Arabia
- SAR 144,000 – SAR 216,000
Location: Dammam, Saudi Arabia
Employment Type: Full-Time | Onsite
Project Duration: Long-term project assignment
About the Role
We are seeking a Security Operations & Monitoring Engineer to provide continuous monitoring and security-event analysis across encryption, KMS, HSM, database security, and related infrastructure.
The successful candidate will work closely with the SOC/SIEM and technical teams to identify suspicious activities, triage security events, support incident response, and ensure timely escalation and reporting.
Key Responsibilities
- Perform continuous monitoring of cybersecurity systems and infrastructure.
- Monitor encryption, KMS, HSM, database security, and other security-related events.
- Review and analyze system, security, audit, and application logs.
- Monitor security alerts through SIEM/SOC platforms.
- Perform first-level investigation and triage of cybersecurity events.
- Correlate alerts from multiple security technologies to identify potential incidents.
- Escalate critical or suspicious activities according to established procedures.
- Support incident-response investigations and evidence collection.
- Coordinate with engineering teams during security incidents and service-impacting events.
- Support the tuning of monitoring rules and alert thresholds.
- Prepare operational, security, and incident reports.
- Maintain incident records, monitoring procedures, and operational documentation.
- Participate in shift, maintenance, and on-call activities when required.
Requirements
Required Qualifications & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.
- 4+ years of experience in SOC, SIEM, security monitoring, incident triage, or cybersecurity operations.
- Hands-on experience with SIEM and security monitoring platforms.
- Good understanding of security events, logs, alerts, incident handling, and escalation procedures.
- Experience integrating security solutions with central SOC/SIEM platforms.
- Strong analytical and troubleshooting skills.
- Must be available full-time onsite in Dammam.
Required Certification
- CompTIA Security+.
Preferred Certifications
- CompTIA CySA+.
- Splunk Core Certified Power User.
- Splunk Certified Cybersecurity Defense Analyst.
- Equivalent recognized SIEM/SOC certification.
Core Competencies
SOC | SIEM | Security Monitoring | Incident Triage | Log Analysis | Incident Response | Alert Management | Threat Detection | Reporting
Candidates should include the SIEM/SOC platforms they have used, the type of monitoring environments they supported, and their relevant certifications.
Skills
- SIEM
- Security Monitoring
- Incident Response
- Log Analysis
- Encryption
- KMS
- HSM




