On-site Full Time
VaporVM -
Saudi , Jeddah
--
VaporVM

Job Details

System Operator – Internet Firewall & External Applications
We are looking for a System Operator – Internet Firewall & External Applications to support the operation, monitoring, and administration of cybersecurity systems within Health Affairs. The role will focus on security monitoring, incident handling, investigation, escalation, compliance, and maintaining the effectiveness of security infrastructure.
Key Responsibilities Operate and support cybersecurity systems, including Firewall, WAF, SIEM, Antivirus (AV), EDR, Proxy, IDS/IPS, and related security technologies. Continuously monitor security alerts, events, and incidents across the environment. Identify, classify, prioritize, and investigate security events collected from:Firewalls and network devices Proxies and IDS/IPS systems Antivirus and EDR solutions Databases, servers, and endpoints Classify incidents according to their type, impact, and severity. Take appropriate action based on incident severity, including:Notifying relevant system administrators. Following established incident response procedures. Escalating incidents in accordance with defined escalation processes. Accurately documenting all incidents and actions taken. Investigate cybersecurity incidents, track cyberattacks, and gather relevant information about potential attackers and attack methods. Analyze cyber events and incidents reported by the National Cybersecurity Authority and coordinate appropriate actions. Create, review, and update SIEM/security monitoring use cases for new systems and applications. Resolve and manage cybersecurity-related service requests and user issues. Coordinate with other departments and technical teams during security incident investigations and resolution. Monitor compliance with applicable MNG-HA technical security standards and support remediation of identified gaps. Maintain and operate the latest approved versions of cybersecurity systems and security technologies within Health Affairs. Prepare and submit monthly cybersecurity reports summarizing major incidents, investigations, actions taken, and key observations. Support continuous improvement of security monitoring, incident response, and cybersecurity operational processes.
Required Skills & Experience Experience in Cybersecurity Operations, SOC, Security Monitoring, or Security Engineering. Hands-on experience with security technologies such as Firewalls, WAF, SIEM, EDR, Antivirus, Proxy, and IDS/IPS. Strong understanding of security event monitoring, incident classification, investigation, escalation, and response. Experience analyzing logs and security events from network devices, servers, endpoints, databases, and security tools. Knowledge of incident response processes and cybersecurity best practices. Ability to develop and maintain security monitoring/SIEM use cases. Strong analytical, troubleshooting, documentation, and communication skills. Experience working in a 24x7 SOC or security operations environment is an advantage. Relevant cybersecurity certifications such as Security+, CySA+, CEH, GCIH, or equivalent are preferred.

Similar Jobs

About VaporVM
Saudi, Jeddah
Information Technology and Services