menajobs
  • Resume Tools
  • ATS Checker
  • Offer Checker
  • Features
  • Pricing
  • FAQ
LoginGet Started — Free
Home/Jobs/Senior SOC Analyst L3 - Saudi National - Jeddah, KSA
DeepSource Technologies logo
DeepSource Technologies

Senior SOC Analyst L3 - Saudi National - Jeddah, KSA

🇸🇦 Jeddah, Saudi Arabia🏢 On-site
DFIRCybersecurityIncident ResponseForensicsSIEMEDRMITRE ATT&CKThreat Intelligence
🌙 Saudi National
WhatsAppLinkedInX

Check Your Format

  • See if your CV format works for DeepSource Technologies
  • Get AI-rewritten bullet points
  • Download Gulf-ready CV
Check Formatting

60 seconds. $3.99 one-time.

✈️Flights🏥Medical💰Gratuity
🌙 Saudi National
DeepSource Technologies logo
DeepSource Technologies
employees

Position Overview

We are seeking a highly experienced Senior SOC Analyst – Layer 3 (DFIR) to lead advanced digital forensic investigations and incident response operations within our Cybersecurity Operations Center (SOC) in Jeddah.

The selected candidate will act as the highest technical escalation point for major security incidents, conduct in-depth forensic investigations, manage complex breach scenarios, and provide strategic guidance to SOC L1 and L2 teams. This role requires strong hands-on DFIR expertise in enterprise environments, including endpoint, network, cloud, and hybrid infrastructures.

Key Responsibilities

1. Advanced Incident Response Leadership

• Lead end-to-end handling of high-severity cybersecurity incidents (Ransomware, APT, data exfiltration, insider threats).

• Direct containment, eradication, and recovery strategies during critical incidents.

• Serve as primary escalation point for SOC L2 investigations.

• Coordinate with IT, Legal, Risk, Compliance, and executive leadership during crisis situations.

• Conduct post-incident reviews and lessons-learned workshops.

2. Digital Forensics Investigations

• Perform forensic acquisition and analysis of endpoints, servers, and cloud workloads.

• Conduct disk, memory, and network forensics using industry-standard tools.

• Preserve and maintain chain-of-custody documentation.

• Analyze artifacts such as registry, event logs, browser history, persistence mechanisms, and lateral movement traces.

• Prepare forensic reports suitable for executive and legal review.

3. Endpoint & EDR Deep Analysis

• Perform deep investigations using enterprise EDR platforms such as

Microsoft Defender for Endpoint,

CrowdStrike Falcon, or equivalent.

• Conduct advanced threat hunting and behavioral analysis.

• Reverse-engineer suspicious scripts or malware (basic to intermediate level).

4. SIEM & Log Correlation Expertise

• Conduct advanced log analysis across SIEM platforms such as

Splunk Enterprise Security,

Microsoft Sentinel, or equivalent.

• Develop and optimize advanced detection queries (SPL / KQL).

• Correlate endpoint, network, identity, and cloud telemetry for full attack chain reconstruction.

• Map incidents to MITRE ATT&CK framework techniques.

5. Network & Cloud Forensics

• Analyze PCAP, NetFlow, DNS, proxy, and firewall logs.

• Investigate suspicious lateral movement and command-and-control traffic.

• Perform forensic investigations within Microsoft 365, Azure, and AWS environments.

• Assess identity compromise scenarios (AD, Azure AD, privileged access abuse).

6. Threat Intelligence & Proactive Defense

• Integrate threat intelligence feeds into DFIR investigations.

• Conduct proactive threat hunting campaigns.

• Participate in red team / purple team exercises.

• Identify detection gaps and recommend defensive improvements.

7. Governance & Compliance Support

• Ensure forensic readiness aligned with NCA ECC, SAMA CSF, ISO 27001, and other regulatory frameworks.

• Maintain forensic documentation aligned with legal admissibility standards.

• Contribute to incident response policy and playbook development.

8. On-Call & Crisis Response

• Participate in 24x7 on-call rotation for major incidents.

• Provide immediate response and executive-level briefing during critical cybersecurity events.

Requirements

Candidates must demonstrate proven, hands-on DFIR experience in:

• Minimum 7–10 years of experience in cybersecurity operations.

• At least 3–5 years in L3 / DFIR role handling major enterprise incidents.

• Practical experience with forensic tools such as:

o EnCase

o FTK

o X-Ways

o Volatility

o Autopsy

• Memory forensics and live response techniques.

• Ransomware investigation and recovery coordination.

• Advanced Windows & Linux artifact analysis.

• Network protocol deep understanding (TCP/IP, DNS, HTTP/S, SMB, LDAP, Kerberos).

• Cloud security investigations (Azure / AWS / M365).

• Evidence handling and chain-of-custody documentation.

• Experience working in regulated sectors (Banking, Government, Critical Infrastructure preferred).

Requirements

  • •Lead end-to-end handling of high-severity cybersecurity incidents
  • •Serve as primary escalation point for SOC L2 investigations
  • •Perform forensic acquisition and analysis of endpoints, servers, and cloud workloads
  • •Conduct disk, memory, and network forensics using industry-standard tools
  • •Preserve and maintain chain-of-custody documentation
  • •Perform deep investigations using enterprise EDR platforms
  • •Conduct advanced log analysis across SIEM platforms
  • •Assess identity compromise scenarios

Nice to Have

  • •Manage complex breach scenarios
  • •Provide strategic guidance to SOC L1 and L2 teams
  • •Coordinate with IT, Legal, Risk, Compliance, and executive leadership
  • •Conduct post-incident reviews and lessons-learned workshops
  • •Reverse-engineer suspicious scripts or malware
  • •Map incidents to MITRE ATT&CK framework techniques
  • •Perform forensic investigations within Microsoft 365, Azure, and AWS environments
  • •Integrate threat intelligence feeds into DFIR investigations

Responsibilities

  • •Lead handling of high-severity cybersecurity incidents
  • •Serve as primary escalation point for SOC L2 investigations
  • •Perform forensic acquisition and analysis
  • •Conduct disk, memory, and network forensics
  • •Analyze artifacts (registry, event logs, etc.)
  • •Perform deep investigations using EDR
  • •Conduct advanced SIEM log analysis
  • •Investigate suspicious lateral movement and command-and-control traffic

Related Jobs

Mindrift logo
Senior Python Systems Developer - Functional Testing Project
Mindrift · 🇸🇦 Saudi Arabia
Mindrift logo
Freelance Data Science Engineer (Python & SQL)
Mindrift · 🇸🇦 Saudi Arabia
Back to all jobs
Quick CV Check
  • Get your ATS score for DeepSource Technologies in 30 seconds
  • Get AI-rewritten bullet points
  • Download Gulf-ready CV
Get My Score

60 seconds. $3.99 one-time.

Benefits Package
🏠Housing
✈️Flights
🏥Medical
🎓Education
🚗Transport
💰Gratuity
🎯Bonus
📦Relocation
GCC Info
🌙 Saudi National
Company
DeepSource Technologies logo
DeepSource Technologies
employees

Visit WebsiteView all jobs
Share
WhatsAppLinkedInX
menajobs

AI-powered GCC job board with resume optimization tools.

Serving:

UAESaudi ArabiaQatarKuwaitBahrainOman

Product

  • Resume Tools
  • Features
  • Pricing
  • FAQ

Resources

  • Resume Examples
  • CV Format Guides
  • Skills Guides
  • Salary Guides
  • ATS Keywords
  • Job Descriptions
  • Career Paths
  • Interview Questions
  • Achievement Examples
  • Resume Mistakes
  • Cover Letters
  • Resume Summaries
  • Resume Templates
  • ATS Resume Guide
  • Fresher Resumes
  • Career Change
  • Industry Guides

Country Guides

  • Jobs by Country
  • Visa Guides
  • Cost of Living
  • Expat Guides
  • Work Culture

Free Tools

  • ATS Checker
  • Offer Evaluator
  • Salary Guides
  • All Tools

Company

  • About
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Shipping & Delivery
  • Sitemap

Browse by Location

  • Jobs in UAE
  • Jobs in Saudi Arabia
  • Jobs in Qatar
  • Jobs in Dubai
  • Jobs in Riyadh
  • Jobs in Abu Dhabi

Browse by Category

  • Technology Jobs
  • Healthcare Jobs
  • Finance Jobs
  • Construction Jobs
  • Oil & Gas Jobs
  • Marketing Jobs

Popular Searches

  • Tech Jobs in Dubai
  • Healthcare in Saudi Arabia
  • Engineering in UAE
  • Finance in Qatar
  • IT Jobs in Riyadh
  • Oil & Gas in Abu Dhabi

© 2026 MenaJobs. All rights reserved.

LoginGet Started — Free