Overview
Security Operations Analyst Jobs in Riyadh, Saudi Arabia at Confidential
Title: Security Operations Analyst
Company: Confidential
Location: Riyadh, Saudi Arabia
The Security Operations Analyst/Admin is responsible for end-to-end cybersecurity operations across a multi-country, highly regulated enterprise environment. The role operates within a Security Operations Center (SOC) and leverages SIEM, SOAR, EDR, NDR, and XDR platforms to deliver real-time monitoring, advanced threat detection, automated response, and continuous security improvement.
The role ensures protection of enterprise infrastructure, cloud platforms, Microsoft 365, endpoints, and SAP S/4HANA systems while maintaining strict compliance with regulatory requirements across KSA, Middle East, Germany, and India. In addition, the position plays a critical role in vulnerability remediation, post-VAPT validation, audit readiness, and ensuring that all security operations are measurable, defensible, and aligned with enterprise governance frameworks
Key Job Responsibilities
Lead enterprise cybersecurity operations across a large multi-country regulated environment covering infrastructure, endpoints, Microsoft 365, networks, SAP, and business applications.
Monitor and administer SIEM, SOAR, EDR, NDR, and XDR platforms for threat detection, incident response, and security monitoring.
Manage Microsoft 365 E5 Security capabilities including Defender, Purview, DLP, MFA, Conditional Access, and identity security controls.
Investigate cybersecurity incidents, coordinate containment and remediation activities, and perform root cause analysis across enterprise systems.
Support vulnerability management, penetration testing remediation, patch governance, and security risk mitigation initiatives.
Monitor privileged access, segregation of duties, SAP security risks, and enterprise access governance controls.
Support ISO 27001, GDPR, NCA, ITGC, audit, compliance, and regulatory reporting requirements across multiple regions.
Coordinate with Infrastructure, SOC, SAP, GRC, Audit, vendors, and external security partners to strengthen enterprise cyber resilience.
Prepare dashboards, reports, audit evidence, and continuous improvement recommendations covering threats, vulnerabilities, controls, and remediation status.
Requires 8–10 years of cybersecurity operations experience with strong exposure to enterprise security platforms, incident response, Microsoft 365 security, DLP, and regulated environments.
Experience
8 to 10 years in cybersecurity or SOC operations
Strong experience in SIEM, SOAR, EDR, NDR, and XDR
Experience in incident response and threat hunting
Exposure to compliance and audit environments preferred
Education
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field
Master’s degree is an advantage
Preferred Certifications
CISSP, CISM, CEH, Security+, GIAC, SIEM platform certifications