Information Security Engineer (SOC L2)

Tabby
Riyadh
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 2-3 yearsSkills: ["Communication","Stakeholder management","Mentoring","Incident reporting"]

Monitor and analyze security logs and alerts across firewalls, IDS/IPS, endpoints, servers, and cloud platforms. Correlate events to detect advanced threats, tune detection logic to reduce false positives, and provide real-time SOC visibility. Own incident response from detection through recovery, perform root-cause/forensic investigations, and document post-mortems. Build and tune detection rules and threat-hunting queries, using CTI platforms and feeds, while collaborating with cross-functional teams and mentoring juniors.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tabby
Tabby
51 minutes ago

Information Security Engineer (SOC L2)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 51 minutes agoStatus: Live

Job Summary

Monitor and analyze security logs and alerts across firewalls, IDS/IPS, endpoints, servers, and cloud platforms. Correlate events to detect advanced threats, tune detection logic to reduce false positives, and provide real-time SOC visibility. Own incident response from detection through recovery, perform root-cause/forensic investigations, and document post-mortems. Build and tune detection rules and threat-hunting queries, using CTI platforms and feeds, while collaborating with cross-functional teams and mentoring juniors.
Location: Riyadh
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Monitor and analyze logs and alerts from multiple security sources (firewalls, IDS/IPS, endpoints, servers, cloud platforms).
  • •Correlate events to identify advanced threats and unusual behavior; fine-tune alert thresholds and detection logic.
  • •Lead incident response end-to-end: detection, containment, eradication, recovery, and lessons learned.
  • •Perform root-cause analysis and forensic investigations using endpoint and network artifacts; produce detailed documentation and post-mortems.
  • •Develop and tune detection rules, threat-hunting queries, and threat intelligence use cases; maintain CTI platform integrations for active CTI-driven detections.

Key Requirements

  • •2–3 years in a SOC or cybersecurity operations role in a fast-paced environment.
  • •Strong incident handling and alert triage skills, including log analysis and threat modeling.
  • •Understanding of online technologies, REST APIs, microservices, and modern application architectures.
  • •Operational familiarity with DLP, AV, and anti-malware systems, plus phishing detection and user behavior analytics.
  • •Experience with SIEM, SOAR, EDR/XDR, and threat intelligence platforms; scripting (e.g., Python) is a plus.
Experience:2-3 yearsFintechSOCCybersecurity operationsEnterprise
Skills:CommunicationStakeholder managementMentoringIncident reporting
Certifications:Security+CySA+ECIRECTHPv2GCIAGMON
Tech Stack:SIEMSOAREDR/XDRThreat Intelligence platformsCTI PlatformCTI feedsIDS/IPSFirewallsEndpointsServersCloud environmentsCloud-native loggingCloud-native monitoringREST APIsMicroservicesPythonDLPAVAnti-malwarePhishing detection

Company Brief

Tabby
Tabby is a MENA buy‑now‑pay‑later and fintech platform that enables customers to split purchases into installments, offers in‑store and online payment products, a consumer app, and merchant services across Saudi Arabia, UAE, Kuwait and the wider region.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Riyadh, Saudi Arabia
Founded: 2019
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor