نحن نوظف: محلل CDC L1 SOC (المستوى 1)
تبحث نورنت عن محلل CDC L1 SOC للانضمام إلى مركز الدفاع السيبراني لدينا والعمل كخط دفاع أول ضد التهديدات السيبرانية.
يركز هذا الدور على المراقبة الأمنية الفورية، وفرز التنبيهات، والتحقيق الأولي، وإجراءات الاستجابة الأولى، والتصعيد في الوقت المناسب للحوادث الأمنية المحتملة.
ال his المسؤوليات الرئيسية
- مراقبة التنبيهات الأمنية عبر أنظمة SIEM، وXDR، وEDR، والجدران النارية، وIDS/IPS، وWAF، وأمن البريد الإلكتروني، وغيرها من المنصات الأمنية.
- إجراء الفرز الأولي للتنبيهات، والتحقق من الأحداث، وتحديد الإيجابيات الكاذبة، وتحديد مستوى الخطورة المناسب.
- إجراء تحقيق أساسي وإثراء مؤشرات الاختراق (IOC) باستخدام مصادر استخبارات التهديدات.
- تنفيذ إجراءات الاستجابة الأولى المصرح بها، بما في ذلك عزل الأجهزة الطرفية، وإنهاء الجلسات، والحظر المؤقت.
- تصعيد الحوادث المؤكدة أو المشبوهة إلى فرق المستوى 2 / استجابة الحوادث بناءً على الإجراءات المعتمدة.
- توثيق خطوات التحقيق والنتائج والإجراءات بدقة في نظام التذاكر.
- اتباع أدلة التشغيل (Runbooks) وكشوفات اللعب (Playbooks) وإجراءات التصعيد الخاصة بـ SOC.
- الحفاظ على تقارير تسليم ورديات العمل دقيقة تغطي الحوادث الجارية والعناصر الخاضعة للمراقبة والتحديثات التشغيلية.
- المشاركة في المحاكاة الأمنية، والتدريب، وأنشطة التحسين المستمر.
المتطلبات
- درجة البكالوريوس في الأمن السيبراني، أو علوم الحاسب، أو أمن المعلومات، أو أي مجال ذي صلة.
- خبرة عملية في التعامل مع منصات SIEM، مثل XSIAM أو Splunk أو QRadar.
- خبرة أساسية في التعامل مع الحوادث، وفرز محاولات التصيد الاحتيالي، وإثراء مؤشرات الاختراق (IOC).
- فهم عمليات مركز عمليات الأمن (SOC) والمراقبة القائمة على نظام الورديات.
- مهارات تحليلية وحل مشكلات قوية.
- اهتمام ممتاز بالتفاصيل والانضباط في التوثيق.
- القدرة على العمل بفعالية في بيئة عمل بنظام الورديات على مدار الساعة (24×7).
- مواطن سعودي
التقنيات المفضلة
أنظمة SIEM: XSIAM, Splunk, QRadar
أنظمة EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne
أمن البريد الإلكتروني: Proofpoint, Mimecast, Microsoft 365 Defender
أنظمة التذاكر: ServiceNow, JIRA, Remedy
إذا كان لديك اهتمام قوي بـ الأمن السيبراني، واكتشاف التهديدات، وعمليات مركز عمليات الأمن (SOC) وتبحث عن تطوير مسارك المهني داخل مركز للدفاع السيبراني، فنحن نرحب بالتواصل معك.
We’re Hiring: CDC L1 SOC Analyst (Tier 1)
NourNet is looking for a CDC L1 SOC Analyst to join our Cyber Defense Center and serve as the first line of defense against cyber threats.
The role focuses on real-time security monitoring, alert triage, initial investigation, first-response actions, and timely escalation of potential security incidents.
Key Responsibilities
- Monitor security alerts across SIEM, XDR, EDR, Firewall, IDS/IPS, WAF, Email Security, and other security platforms.
- Perform initial alert triage, validate events, identify false positives, and assign appropriate severity.
- Conduct basic investigation and IOC enrichment using threat intelligence sources.
- Perform authorized first-response actions, including endpoint isolation, session termination, and temporary blocking.
- Escalate confirmed or suspicious incidents to Tier 2 / Incident Response teams based on established procedures.
- Document investigation steps, findings, and actions accurately in the ticketing system.
- Follow SOC runbooks, playbooks, and escalation procedures.
- Maintain accurate shift handover reports covering ongoing incidents, watch items, and operational updates.
- Participate in security simulations, training, and continuous improvement activities.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
- Hands-on exposure to SIEM platforms, such as XSIAM, Splunk, or QRadar.
- Basic experience in incident handling, phishing triage, and IOC enrichment.
- Understanding of SOC operations and shift-based monitoring.
- Strong analytical and problem-solving skills.
- Excellent attention to detail and documentation discipline.
- Ability to work effectively in a 24×7 shift environment.
- Saudi Citizen
Preferred Technologies
SIEM: XSIAM, Splunk, QRadar
EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne
Email Security: Proofpoint, Mimecast, Microsoft 365 Defender
Ticketing: ServiceNow, JIRA, Remedy
If you have a strong interest in cybersecurity, threat detection, and SOC operations and are looking to grow your career within a Cyber Defense Center, we’d like to hear from you.