Cybersecurity Defense Analyst

2 days ago


الرياض, Saudi Arabia Help AG Full time

This role requires:
1-4 years of experience in information security, in areas such as security operations, intrusion detection, incident analysis, incident handling, log analysis, or firewall administration.

1-4 years of experience in one of the following: Network operations or engineering or system administration on Unix, Linux, Windows.

**Responsibilities**
- Monitor multiple security technologies, such as IDS/IPS, Firewalls, Switches, VPNs, and other security threat data sources.
- Correlate and analyze events using SIEM tools to detect security incidents.
- Create, follow and present detailed operational process and procedures to appropriately analyze, escalate, and assist in remediation of critical information security incidents.
- Respond to inbound requests via phone and other electronic means for technical assistance with managed services.
- Respond in a timely manner (within documented SLA) to support, investigate, and other cases.
- Document actions in cases to effectively communicate information internally and to customers.
- Resolve problems independently and understand escalation procedure.
- Maintain a high degree of awareness of current threat landscape and cybersecurity intelligence.
- Spread the cybersecurity intelligence across the team of analysts and engage in threat hunting activities.
- Lead delivery, and support others in the delivery, of knowledge sharing with analysts and writing technical articles for Internal knowledge bases, blog posts and reports as requested.
- Perform other essential duties as assigned.
- Analysis of log files, includes forensic analysis of system resource access.
- Create, follow and present customer reports to ensure quality, accuracy, and value to clients.
- Creation of new content (Use Cases, Queries, Reports) within the SIEM platform.
- Education and training of other analysts in use and operation of SIEM platform.
- On-site work with clients as required.
- Engage with client Incident Response team as required.
- Generate cybersecurity Threat Intelligence reports.

**Qualifications and Skills**
- Saudi National will be preferrable.
- Bachelor’s or master’s degree in Cybersecurity, Computer Science, Information Systems, Electrical Engineering, or a closely related degree.
- An active interest and passion in cybersecurity, incident detection, network, and systems security.
- 1+ years of experience in cybersecurity, in areas such as security operations, intrusion detection, incident analysis, incident handling, log analysis, threat intelligence/hunting or digital forensics.
- A sound knowledge of IT security best practices, common attack types and detection / prevention methods.

Knowledge of the type of events that both Firewalls, IDS/IPS and other security related devices produce.
- Experience in using Splunk as an analyst for Threat and Incident Detection is required.
- Experience with ArcSight, LogRhythm, QRadar, is preferable but not mandatory.
- Strong understanding of Cyber Kill Chain and MITRE ATT&CK frameworks and techniques.
- Solid understanding of TCP/IP and network concepts and principles.
- Possible attack activities, such as scans, man in the middle, sniffing, DoS, DDoS.
- Professional certificates are highly preferred (e.g., CCIE, OSCP, CISSP, GSEC, GCIA, GCIH, GMON, GREM, GDAT, GCFE, etc.).
- An experienced Analyst who aspires to be a leader and is committed to learning the principles of leadership and the role of a leader.
- Outstanding organizational skills.
- Exclusive focus and vast experience in IT.
- Very good communication skills.
- Strong analytical and problem-solving skills.
- A motivated, self-managed, individual who can demonstrate exceptional analytical skills and work professionally with peers and customers even under pressure.
- Strong written and verbal skills.
- Strong interpersonal skills with the ability to collaborate well with others.
- Ability to speak and write in English is required; Ability to speak and write in both English and Arabic is preferred.
- Well-versed in developing content for SIEM (creating, fine tuning) use cases and rules.
- Experience with automation tools (SOAR) is preferred.
- Experience in Malware Analysis / Reverse Engineering is preferred.

**Benefits**
- Health insurance with one of the leading global providers for medical insurance.
- Career progression and growth through challenging projects and work.
- Employee engagement activities throughout the year.
- Tailored training & development program.

**About Us**

Help AG is the cyber security arm of e& enterprise and provides leading enterprise businesses across the Middle East with strategic consultancy combined with tailored information security solutions and services that address their diverse requirements, enabling them to evolve securely with a competitive edge.

Present in the Middle East since 2004, Help AG was strategically acquired by Etisalat group in Feb 2020, hence creating a cyber security and digital transformation powerhouse in



  • الرياض, Saudi Arabia Help AG Full time

    Help AG is looking for a talented and enthusiastic Associate Cybersecurity Defense Analyst to join our Cybersecurity Operations Center (CSOC) team as part of our client’s Managed Security Services (MSS) business unit. If you have solid knowledge, passion and interest in Cybersecurity, this position might be the right one for you. The Associate...


  • الرياض, Saudi Arabia Help AG Full time

    **Responsibilities** - Monitor multiple security technologies, such as IDS/IPS, Firewalls, Switches, VPNs, and other security threat data sources. - Correlate and analyze events using SIEM tools to detect security incidents. - Create, follow and present detailed operational process and procedures to appropriately analyze, escalate, and assist in remediation...


  • الرياض, Saudi Arabia Giza Systems EG Full time

    Responsible for implementing and managing security measures to protect CCC information systems and data. Actively monitor and respond to security incidents, investigate potential threats, and ensure compliance with various security standards and regulation **Personal Skills**: - Continuously monitor security alerts and logs for potential threats. -...

  • Cybersecurity Analyst

    2 weeks ago


    الرياض, Saudi Arabia Tabby Full time

    Cybersecurity Analyst **Cybersecurity Analyst** **Department**:Information Security Monitoring **Employment Type**:Full Time **Location**:KSA **Description** **Key Responsibilities** - Strong understanding of cloud services such as **Google Cloud Platform (GCP)**, **Terraform**, **CI/CD Security**, **Kubernetes Security**, **GitLab**, and **Product...


  • الرياض, Saudi Arabia Mozn Full time

    **Job Summary** Mozn is a rapidly growing technology firm revolutionizing the field of Artificial Intelligence and Data Science headquartered in Riyadh, Saudi Arabia and it’s working to realize Vision 2030 with a proven track record of excellence in supporting and growing the tech ecosystem in Saudi Arabia and the GCC region. Mozn is the trusted AI...


  • الرياض, Saudi Arabia IT Butler E-Services FZ LLC Full time

    **ob description** Are you passionate about cybersecurity and eager to gain hands-on experience in a dynamic Security Operations Center (SOC) environment? We have an exciting opportunity for a _**SOC Analyst Intern**_ to join our team and learn from some of the industry's top security professionals. **Company Description**: **IT Butler e Services** is a...

  • SOC Analyst Intern

    2 days ago


    الرياض, Saudi Arabia IT Butler Pvt Ltd Full time

    **ob Title**: SOC Analyst Intern **Location**: Riyadh, Saudi Arabia **Duration**: 3 Months (Onsite) **Monthly Stipend**: 1,000 SAR **About the Opportunity**: Are you passionate about cybersecurity and eager to kickstart your career in a Security Operations Center (SOC)? ITButler e Services is offering an **exciting onsite internship** for aspiring SOC...


  • الرياض, Saudi Arabia Help AG Full time

    Help AG is looking for a talented and experienced Offensive Security Consultant who will be involved in the opportunity to engage in a wide range of activities related to cybersecurity and penetration testing. Here are the key areas they will be involved in: - Source code review and software assurance maturity audits. - Red teaming and infrastructure...

  • SOC Analyst Intern

    1 week ago


    الرياض, Saudi Arabia IT Butler Pvt Ltd Full time

    **Job Title**: SOC Analyst Intern **Location**: Riyadh, Saudi Arabia **Duration**: 3 Months (Onsite) **Monthly Stipend**: 1,000 SAR **About the Opportunity**: Are you passionate about cybersecurity and eager to kickstart your career in a Security Operations Center (SOC)? ITButler e Services is offering an **exciting onsite internship** for aspiring SOC...


  • الرياض, Saudi Arabia Qiddiya Investment Company Full time

    Analyst - IT Security (COR - 624) Qiddiya Investment Company is seeking a dedicated and detail-oriented Analyst - IT Security to join our security team. In this role, you will be responsible for assessing and mitigating security risks, monitoring IT security systems, and supporting the implementation of security policies and procedures. As an Analyst, you...