Senior IT Security Operation- Saudi National- Riyadh, KSA
Summary
Hands-on Senior IT Security Operations Engineer safeguarding IT infrastructure, networks, and cloud environments through threat detection, incident response, IAM governance, and security compliance. Core tech: SIEM (Splunk, QRadar, Sentinel), EDR (CrowdStrike, Defender), Next-Gen Firewalls (Palo Alto, Fortinet), IAM (Active Directory, Entra ID, PAM), and Azure/AWS.
The Senior IT Security Operations Engineer safeguards corporate IT infrastructure, networks, enterprise data, and cloud environments against operational security risks and threats.
This hands-on role bridges infrastructure management with threat detection, incident response, IAM governance, and security standard compliance across enterprise systems.
Key Responsibilities Infrastructure & Network Defense: Configure, manage, and audit enterprise firewalls, VPNs, Endpoint Detection and Response (EDR) agents, and web proxy controls.
Security Monitoring & Incident Response: Lead Tier-2/Tier-3 security event investigations, analyze SIEM logs, and mitigate security incidents to limit operational downtime.
Identity & Access Governance: Enforce strict identity and access management (IAM) controls, privileged access management (PAM), multi-factor authentication, and role-based access policies.
Vulnerability & Patch Management: Direct routine infrastructure vulnerability scans, prioritize critical patching schedules with IT infrastructure teams, and verify system hardening.
Backup Integrity & System Audits: Ensure secure backup configurations, system disaster recovery readiness, and adherence to security standards (ITIL, ISO 27001, NCA-ECC).
1. Minimum 6+ years of hands-on experience in IT security administration, SOC engineering, or network security operations.
2. Advanced proficiency with core security solutions including SIEM tools (Splunk, QRadar, Sentinel), EDR platforms (CrowdStrike, Defender), and Next-Gen Firewalls (Palo Alto, Fortinet) .
3. Strong expertise in Identity & Access Management (Active Directory, Entra ID, PAM solutions) , multi-factor authentication, and network access controls.
4. Proven track record in threat detection, incident response, log analysis, and system hardening across Windows/Linux servers and cloud platforms (Azure/AWS).
5. Hold at least one active industry certification such as CompTIA Security+, CISSP, CEH, CCSP, or ITIL4 .
This hands-on role bridges infrastructure management with threat detection, incident response, IAM governance, and security standard compliance across enterprise systems.
Key Responsibilities Infrastructure & Network Defense: Configure, manage, and audit enterprise firewalls, VPNs, Endpoint Detection and Response (EDR) agents, and web proxy controls.
Security Monitoring & Incident Response: Lead Tier-2/Tier-3 security event investigations, analyze SIEM logs, and mitigate security incidents to limit operational downtime.
Identity & Access Governance: Enforce strict identity and access management (IAM) controls, privileged access management (PAM), multi-factor authentication, and role-based access policies.
Vulnerability & Patch Management: Direct routine infrastructure vulnerability scans, prioritize critical patching schedules with IT infrastructure teams, and verify system hardening.
Backup Integrity & System Audits: Ensure secure backup configurations, system disaster recovery readiness, and adherence to security standards (ITIL, ISO 27001, NCA-ECC).
1. Minimum 6+ years of hands-on experience in IT security administration, SOC engineering, or network security operations.
2. Advanced proficiency with core security solutions including SIEM tools (Splunk, QRadar, Sentinel), EDR platforms (CrowdStrike, Defender), and Next-Gen Firewalls (Palo Alto, Fortinet) .
3. Strong expertise in Identity & Access Management (Active Directory, Entra ID, PAM solutions) , multi-factor authentication, and network access controls.
4. Proven track record in threat detection, incident response, log analysis, and system hardening across Windows/Linux servers and cloud platforms (Azure/AWS).
5. Hold at least one active industry certification such as CompTIA Security+, CISSP, CEH, CCSP, or ITIL4 .