- Job Type
- Contract
- Location
- Riyadh, Saudi Arabia
- Job Reference No.
- CR/030749
Key Responsibilities
- Lead end-to-end Cortex XSIAM deployment and implementation projects for enterprise customers.
- Conduct discovery workshops to understand existing security operations, SIEM architecture, data sources, and operational requirements.
- Design and implement XSIAM data ingestion, use cases, detection logic, and operational workflows.
- Migrate customers from legacy SIEM platforms, including Splunk, IBM QRadar, ArcSight, and other SIEM technologies.
- Configure log collection, parsing, correlation rules, threat detection content, dashboards, and reporting.
- Develop automation and response workflows using XSIAM's orchestration capabilities.
- Integrate XSIAM with security tools including EDR, firewalls, IAM solutions, vulnerability management platforms, and cloud security services.
- Support SOC transformation initiatives focused on improving detection, investigation, and response capabilities.
- Deliver knowledge transfer sessions and operational handovers to SOC and security engineering teams.
- Create technical documentation, migration plans, architecture designs, and implementation runbooks.
- Provide troubleshooting and post-deployment optimisation support.
Required Experience
- Minimum 7 years of experience in IT, Cyber Security, or Security Operations.
- Minimum 3 years in a customer-facing Professional Services, Consulting, or Service Delivery role supporting enterprise organisations.
- Strong hands-on experience with SIEM technologies, including one or more of:
Splunk
- IBM QRadar
- Microsoft Sentinel
- ArcSight
- LogRhythm
- Securonix
- Experience designing and implementing SIEM use cases, correlation rules, and detection engineering content.
- Understanding of SOC operations, incident response processes, threat hunting, and security monitoring.
- Experience managing large-scale log ingestion and security data pipelines.
- Strong stakeholder engagement and customer-facing communication skills.