Job Title: Security Analyst – Infrastructure Management (L1 Cybersecurity Analyst) Location: Riyadh, Saudi Arabia Experience: 1–3 Years
We are seeking a Security Analyst – Infrastructure Management (L1) to provide 24x7 first-line operational support for enterprise security infrastructure. The role is responsible for continuous monitoring of security platforms, validating security events, performing initial troubleshooting, managing incidents, and escalating issues to L2 or OEM support teams in accordance with established SLAs and operational procedures.
Key Responsibilities Monitor security tools, dashboards, alarms, and events to ensure continuous availability of security infrastructure. Perform alarm triage, event validation, and first-level analysis of security incidents. Log, update, assign, and track incidents using the organization's ticketing system. Follow approved SOPs, runbooks, and operational procedures for incident handling and escalation. Perform basic health checks on firewalls, VPNs, and other security devices. Verify device availability, interface/link status, VPN sessions, and basic security policy impacts. Conduct initial troubleshooting and escalate unresolved or high-priority incidents to L2, OEM vendors, or relevant support teams. Support approved operational changes in accordance with change management processes. Maintain accurate incident records, operational logs, and shift handover documentation. Prepare and update reports related to SLA compliance, incident status, and infrastructure availability. Coordinate with SOC, NOC, Helpdesk, Customer Operations, and third-party vendors to ensure timely incident resolution. Escalate critical incidents promptly and ensure all activities comply with defined SLAs and operational standards.
Required Skills & Experience1–3 years of experience in SOC, NOC, Security Operations, or Network Security Support. Basic understanding of enterprise security infrastructure and network security concepts. Familiarity with firewalls, VPN technologies, network connectivity, and security monitoring. Experience using monitoring, logging, and incident/ticket management tools. Knowledge of incident management, escalation procedures, and operational support processes. Strong analytical and troubleshooting skills with attention to detail. Good verbal and written communication skills. Ability to work in a 24x7 rotational shift environment.
Preferred Technical Skills Firewall technologies (Palo Alto, Fortinet, Cisco Firepower, Check Point) VPN Technologies (IPSec, SSL VPN) Basic knowledge of SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Arc Sight) Network fundamentals (TCP/IP, DNS, DHCP, Routing, Switching) Windows and Linux administration fundamentals ITSM/Ticketing tools (Service Now, Manage Engine, Jira, Remedy)
Preferred Certifications Comp TIA Security+CCNAFortinet Certified Associate (FCA) or equivalent Microsoft SC-900ITIL Foundation Any entry-level cybersecurity certification is an advantage.